Google readies Gemini to control the entire Mac through a hidden sandbox option
On 3 October 2026, BleepingComputer reported that Google is testing desktop control for Gemini, with a hidden “Additional sandbox options” setting that would let the AI read, create, modify or delete files and drive Mail, Safari and Messages. The feature is not live yet, and Apple is weighing whether to make it harder for AI agents to reach personal files on the Mac.
3 October 2026. BleepingComputer reports that Google is testing desktop control for Gemini, with a hidden “Additional sandbox options” setting spotted by TestingCatalog inside the Gemini Desktop app. Files, apps, web. The AI could read, create, modify or delete files beyond the folders you explicitly connected, and act through Mail, Safari and Messages. No date. Google has neither confirmed the feature nor announced a rollout. Why it matters: Gemini is about to step out of the chat window and become a full desktop agent, and the question of what a model can touch without asking every time is becoming the new frontier of endpoint security.
What the sandbox option hides
The discovery hinges on an interface that is still concealed. According to BleepingComputer, references to an “Additional sandbox options” setting appear in Gemini Desktop, and an internal dialog spells out the scope. Once enabled, the setting would let Gemini read, create, modify or even delete files “anywhere on your PC” — including outside the folders you have explicitly connected to the assistant.
The translation is blunt: until now, Gemini operated inside a narrow perimeter, bounded by the folders the user agreed to share. The “extended” option pushes that perimeter out to the entire filesystem. The internal dialog says it plainly: “By enabling additional sandbox options, you will be able to expand what Gemini can do and access on your Mac… Depending on which settings you enable, Gemini may be permitted to take actions without asking for your permission first.”
Guardrails exist, but the line is moving
Google is not handing over unlimited control. The experience described mirrors Claude’s: the user explicitly grants the AI permission to use their computer, and Gemini would still ask for confirmation before certain sensitive actions. The published list covers buying products, transferring money, creating an online account, accepting legal terms on your behalf and modifying sensitive information about you.
But that list is the real story. The guardrails cover transactional and legal acts, not reading or editing files. And that is exactly where the risk shifts: an agent that can open, read and rewrite any document, then send a message through Mail or Messages, has an attack surface far beyond anything a chat assistant could reach. The question is no longer “can the AI buy on my behalf?” but “who controls the list of what it is allowed to do without asking me?”
That asymmetry matters because files are where the damage concentrates. A misplaced purchase is a refundable transaction; a rewritten document, a deleted folder or an exfiltrated attachment is a data event no confirmation dialog can undo. An agent that reads everything but is prompted only before transactions is protecting the wrong asset — the money, not the data.
Apple as a counterweight
The context is not neutral. BleepingComputer notes that Apple is “considering making it difficult for AI agents to access personal files and data on Mac”. The wording is cautious — no formal announcement — but it sketches a power struggle: on one side, Google pushes Gemini toward ever broader control of the machine; on the other, the owner of macOS weighs tightening third-party agents’ access to personal data.
CISOs should read this as a signal, not a squabble. The browser and the operating system are becoming the two control points where trust in agents is actually settled. Whoever owns the sandbox — the OS — keeps the last word, no matter which model asks for more latitude. Google can offer “additional sandbox options”, but macOS ultimately decides what a process may touch.
The browser is the other half of the same fight. Gemini already lives inside Chrome, and a desktop agent that can both drive the browser and touch the filesystem collapses two permissions that were historically kept apart — what a website can reach versus what an installed app can reach. For defenders, the practical consequence is that browser policies and OS sandbox policies can no longer be managed as separate worlds.
The computer-use race
The move sits inside Google’s broader computer use plans: making Gemini work across files, websites and native apps instead of confining it to a chat window. Neither the rollout date for this “Full Access” nor the model that will power it is known, per BleepingComputer. What is already visible, however, is the direction of travel: assistants are being rebuilt as the primary interface to the whole machine, not as a tab inside it.
The stakes go beyond Google. Assistants are shifting from a passive role — answering in a thread — to an active one — acting on the user’s computer. Every player is tuning the same tension: grant enough autonomy to be useful without opening a channel the user no longer controls. The hidden option in Gemini Desktop is a snapshot of that tuning in progress, before it is even public.
The Claude precedent is instructive: Anthropic launched its computer use back in October 2024, with the same starting promise — an agent that sees the screen, clicks and types. Google arrives later, with the advantage of native integration into Gemini Desktop and a Workspace ecosystem already present on many machines. The difference here is not capability but the default perimeter: what the hidden setting reveals is the temptation to widen that perimeter all at once rather than folder by folder.
What it changes for an operator
First, for a CISO, the finding works as an early warning: desktop-agent permission management will have to join existing controls, on par with browser extensions or folder access. Second, the list of “sensitive” actions for which Gemini will still ask is a useful starting point for your own policy — but it does not cover document reading, which remains the weak link. Third, Apple’s move in the opposite direction is a reminder that trust in agents is negotiated at the OS level: MDM-managed fleets will eventually need to impose their own sandbox perimeter, independent of whatever the assistant vendor proposes.
It is also worth reading the timeline soberly. The feature is still hidden, unconfirmed, and has no release date — but settings like this do not appear out of nowhere: when an “extended access” option shows up in a test build, a rollout is being prepared. Writing the policy before the official announcement is cheaper than reacting after it.
Verdict
If you manage a fleet of Macs, treat this rumor as a project to open, not an alert to block: the desktop agent is inevitable, but its perimeter should be set by your policy, not by an app’s defaults. If you are an individual user, the rule is simple — never enable an “extended access” option without knowing precisely what it removes from your control, and read the list of actions the agent will still ask about. If you track the computer-use race, remember the inflection point: the battle is moving from the model to the sandbox, and the OS owner will hold the key. Gemini is preparing the ground; Apple is preparing the limit. For the security teams in between, the work starts now, before either one ships.