If you use Google Gemini on a Mac for work, something significant is coming that is worth understanding before it arrives.

Google's AI Assistant May Soon Have Full Access to Every File on Your Mac

Google is testing a new capability for the Gemini desktop app that would give the AI assistant broad access to your Mac — including every file on the device, the ability to open and operate apps like Mail, Safari, and Messages, and the ability to browse the web and take actions on your behalf, all without asking for your permission every single time.

The feature is not live yet, and Google has not officially announced it. But references to it were discovered inside the Gemini desktop app itself, including a hidden settings panel and an explanatory pop-up that reads: "By enabling additional sandbox options, you will be able to expand what Gemini can do and access on your Mac. Depending on which settings you enable, Gemini may be permitted to take actions without asking for your permission first."

That last sentence is the one worth paying attention to.

What This Feature Would Actually Do

Today, when you connect a tool or service to an AI assistant, you generally grant it access to specific things — a particular folder, a specific app, a defined set of files. The permissions are scoped and intentional.

What Google is testing goes further. Under the expanded sandbox options, Gemini would be able to read, create, modify, or delete files anywhere on the Mac — not just in folders a user has explicitly connected. It would be able to communicate with native applications and perform actions through them. And it would be able to do all of this automatically, as part of completing a task, without stopping to ask permission at each step.

Google has confirmed that some safeguards would remain in place. Gemini would still ask for confirmation before buying products, transferring money, creating online accounts, accepting legal terms, or modifying sensitive personal information. Outside of those categories, however, the AI would be free to act.

Why This Is a Meaningful Shift

AI tools that operate with broad, persistent access to a device represent a genuinely new category of software — and a genuinely new category of risk.

The capabilities described are powerful and the legitimate uses are real. An AI that can access your files, open apps, and take actions without repeated confirmation prompts is significantly more useful for complex, multi-step tasks than one that stops to ask permission every few seconds.

But that same breadth of access also means that if anything goes wrong — if the AI is manipulated through malicious content it encounters, if a vulnerability in the software is exploited, or if the feature is misconfigured — the consequences are not limited to one folder or one app. They extend to everything on the device.

We have covered this attack pattern before in this series. In our TechTips Tuesday on Ghostcommit, we explained how attackers can hide malicious instructions inside files that AI tools read and act on, causing the AI to do things its user never intended. The broader and more autonomous the AI's access, the more damage that kind of manipulation can do. An AI with access to one folder and a targeted attack delivers a limited outcome. An AI with access to every file on a Mac and the ability to operate any app delivers a much larger one.

This is not an argument against AI tools. It is an argument for understanding what you are agreeing to before you agree to it.

What Your Team Should Think About Right Now

The feature is still in testing and has not been released. But its arrival is a good prompt to establish a clear policy around AI tool permissions before the choice lands in front of your employees.

When any AI tool — Gemini, or others building similar capabilities — offers expanded access options, the default question should not be whether to enable everything because it makes the tool more useful. The question should be what level of access this tool actually needs to do the job it is being used for, and whether granting access beyond that is a tradeoff worth making.

For business devices specifically, the calculus is different than for a personal machine. A work Mac used for client communication, financial management, or internal operations contains data that belongs not just to the employee using it but to the business and its clients. Granting any tool unrestricted access to that device without IT review and a clear policy is a risk decision that should be made deliberately, not by default when an employee clicks through a setup screen.

If your business uses Macs and employees use Google Gemini or plan to, it is worth having a conversation now about what access levels your organization is comfortable with before a feature like this ships and employees start enabling it on their own.

It is also worth reviewing what AI tools are currently installed on business devices and what permissions they currently hold. As we have covered in previous tips, AI tools with broad system access are an increasingly attractive target for manipulation and exploitation — and the access audit is the first step toward understanding your exposure.

The Bottom Line

Google's Gemini is moving toward full computer use on Mac — the ability to access any file, operate any app, and take actions without per-step confirmation. That makes it a significantly more powerful tool. It also makes the permissions question significantly more important. When a feature like this arrives, enabling it should be a deliberate, informed choice made with IT involvement, not something that happens because it was the default or because it made the setup screen easier to click through.