Press Esc to close

Gemini desktop is getting a full-access mode for your entire Mac

The official Gemini desktop app icon, a rounded white tile with the multicolor Gemini spark and a black mouse pointer, on a soft blue gradient background

Image: Google

Google's Gemini app for Mac is getting ready to take a much bigger set of keys. A hidden "Additional sandbox options" setting, spotted by TestingCatalog, would let Gemini's computer use agent work outside the folders you give it, go online and operate other apps without stopping to ask at every step.

According to the setting's text, which TestingCatalog shared, Gemini "may be permitted to take actions without asking for your permission first." That includes reading, creating, changing or deleting files "anywhere on your Mac," even outside connected folders and including "files belonging to other people stored on your device." It also covers sending and receiving data online without approving each connection, and taking actions through apps like Mail, Safari and Messages.

There's still a floor. The screen says Gemini is designed to ask before buying products or transferring funds, creating an online account, accepting legal terms or changing sensitive information about you. Users would have to switch it on with an "Enable additional options" button.

Google hasn't announced any of this, but the feature is clearly taking shape. TestingCatalog first spotted computer use traces in the app's settings, then reported that trusted testers were getting a Tasks mode with settings for allowed and blocked apps. There's no public release date yet.

What Gemini on Mac can do today

The official version is far more fenced in. The free Gemini desktop app runs on Mac and Windows. On Mac, Google's Gemini Spark agent can sort, rename and edit your files, but Google's help page says it "can only view files or directories that you specifically add" to its Connected folders. It's designed to ask before permanently deleting or sharing files, and its temporary backups last up to 24 hours.

Spark also needs a Google AI Pro or Ultra plan and isn't offered in the EEA, the UK, Switzerland or Nigeria. So the new mode would be a big jump, from a few folders you pick to, potentially, your whole Mac.

How it compares, and why it's risky

Rivals mostly approve access one app at a time. Anthropic's Claude computer use, in beta for Pro and Max subscribers, asks before touching each application and blocks trading and crypto apps by default. OpenAI's ChatGPT Computer Use also asks before using an app, with an "Always allow" option. Microsoft's experimental Copilot Actions on Windows runs in a separate agent workspace with its own account, and folder access can be set to "Ask every time."

Our take: as described, Google's version draws its line around types of actions rather than specific apps. That's handier for long tasks, but it relies heavily on Gemini correctly judging what counts as sensitive.

Google's own Spark help page warns that prompt injection, hidden instructions in a website, email or document, could trick an agent into sending your Gmail messages to an outside service. An agent that can go online without approving each connection makes that harder to catch. The note about other people's files also matters on a shared family Mac.

The timing is interesting. Google just unveiled Gemini 4 Argon, which it calls its "most resilient model yet" against indirect prompt injections. TestingCatalog thinks computer use will likely run on Gemini 4. Google hasn't confirmed that, and Argon is limited to trusted testers for now.

If this mode arrives as described, treat it like handing someone your unlocked laptop. Connected folders will still be the safer default for most people.

Comments