One Toggle From Total Access: Gemini Desktop's Hidden 'Full Access' Tier Would Hand Google's AI Your Mac
Strings spotted inside Google's desktop app reveal a 'Full Access' computer-use tier letting Gemini read, write, or delete any file and act inside Mail, Safari, and Messages — landing just as Apple moves to wall off AI agents.
Google’s AI assistant appears poised to take the most aggressive step yet by a major vendor into “computer use” on consumers’ personal machines — and the evidence is sitting in plain sight inside the Gemini Desktop app itself.
A hidden setting labeled “Additional sandbox options” has surfaced in recent builds of the Gemini Desktop application, according to TestingCatalog, the independent tracking outlet that spotted the strings. When enabled, it unlocks a tier the interface calls “Full Access”: permission for Gemini to access any file on the machine, run any application, and take actions without asking for the user’s approval at each step.
What the strings actually say
The discovered interface text is explicit about the scope of what is being granted. “By enabling additional sandbox options, you will be able to expand what Gemini can do and access on your Mac,” Google’s pop-up explains. The critical line follows immediately: “Depending on which settings you enable, Gemini may be permitted to take actions without asking for your permission first.”
In practice, BleepingComputer reports, that translates to capabilities that go far beyond what desktop AI assistants have offered until now:
- Read, create, modify, or delete files anywhere on the machine — not merely inside folders the user has explicitly connected to Gemini
- Communicate with native apps such as Mail, Safari, and Messages, and perform actions through them
- Make network calls and act across other applications without per-step approval
Google has not confirmed the feature, and it is not live for users. But the direction is unambiguous: Gemini Desktop is being prepared to operate the computer itself, working across files, websites, and native apps instead of being confined to a chat window.
Guardrails remain — on paper
The setting is not a blank check. According to the disclosed interface, Gemini would still require explicit confirmation before a defined class of sensitive actions: buying products or transferring money, creating online accounts, accepting legal terms on the user’s behalf, or modifying sensitive personal information.
The pattern mirrors the permission model Anthropic built for Claude’s computer use — the user grants broad machine access once, and the agent operates within it, pausing at a hardcoded list of high-stakes gates. It is the same bargain every agentic system is now converging on: convenience measured in hundreds of skipped confirmation dialogs, risk concentrated in the moments the model misjudges what counts as “sensitive.”
The collision with Apple
The timing could hardly be more pointed. Two days before these strings surfaced, Apple announced it is tightening macOS Full Disk Access controls precisely because of risks from AI agents. Apple’s statement cited incidents including a flaw in the ChatGPT Mac app and allegations around Meta’s Muse agent reading private messages — and warned that risks “will grow substantially as AI agents become more capable and more autonomous.”
The two companies are now moving in opposite directions on the same platform. Apple wants to make it harder for any agent — including Google’s — to obtain sweeping access to a Mac’s filesystem and personal data, requiring more explicit and informed user consent. Google is building a tier whose entire purpose is to obtain exactly that access, at scale, with a single toggle.
Who wins that tug-of-war matters well beyond these two firms. If Apple hardens the platform faster than agents can adapt, macOS becomes the awkward platform for agentic AI. If Google’s approach prevails, the operating system’s permission model becomes a formality negotiated between vendors rather than a boundary drawn by users.
From chat window to operating layer
The Full Access tier fits squarely into Google’s broader computer-use roadmap. The company shipped its first Gemini Computer Use model in October 2025, optimized for controlling interfaces by taking screenshots and deciding where to click, type, and scroll. Gemini 4 Argon, the frontier model released this week, was specifically tuned for computer-use benchmarks. And TestingCatalog previously spotted a separate “Tasks mode” in desktop testing that adds persistent background work to the app.
Each piece points the same way: Gemini is being repositioned from a conversational interface into an operating layer that spans the whole device. The sandbox options are the missing permission plumbing that such a layer requires.
The engineering logic is sound — an agent that must ask permission for every file touch is nearly useless for real work. But the security logic cuts the other way: an agent with pre-authorized write access to every file and three communication apps is also the most powerful malware delivery platform ever imagined, should its instructions ever be subverted. Prompt-injection attacks — where malicious content harvested from the web instructs an agent to act on the attacker’s behalf — become materially more dangerous when the agent no longer pauses to ask.
What is still unknown
Neither the rollout timing nor the model that would power the tier is clear. Google has not responded publicly to the findings, and hidden settings in app builds routinely ship months after they first appear — or never ship at all.
But the competitive pressure is real. OpenAI is pushing always-on agents, Anthropic’s Claude already offers supervised computer control, and every vendor’s agent benchmarks now assume deep machine access. Whoever ships trustworthy full-machine autonomy first gains a defensible consumer lock-in. The strings in Gemini Desktop are best read as Google declining to let that race happen without it.
For users, the practical advice is simple: when the toggle arrives, treat it as the security-equivalent of handing over your keyboard. Backups, disk encryption, and a healthy skepticism about what an agent browsing “any file” might send where are the new baseline for anyone opting in.
Sources
- [1] https://www.bleepingcomputer.com/news/google/google-gemini-could-soon-get-full-access-to-your-macs-files-apps-and-the-web/
- [2] https://x.com/testingcatalog/status/2106041553806336167
- [3] https://www.theverge.com/tech/1004295/apple-limit-mac-disk-access-ai-agents
- [4] https://9to5mac.com/2026/10/02/apple-says-its-tightening-macos-privacy-controls-amid-the-rise-of-ai-agents/
- [5] https://blog.google/innovation-and-ai/models-and-research/google-deepmind/gemini-computer-use-model/