New Google Gemini setting could give AI tool broad access to users' Macs

A new permission would allow an AI agent to access files and carry out actions without specific permission every time

Google Gemini logo and branding pictured on a smartphone, with bar graph visuals blurred in background.
(Image credit: Getty Images)

Google is expected to introduce full access permissions for Gemini that would allow it to access any file on a macOS device, open apps, browse the web, and perform actions without asking for permission every time.

As spotted by AI news tracker TestingCatalog, the permission has been included in a new "Additional sandbox options" setting.

It allows Gemini to read, create, modify, or delete files residing anywhere on a Mac, including files outside connected folders and even files belonging to other people stored on the device.

Data could be sent and received over the network without approval for each connection, including accessing websites, APIs, and services that the user is logged into.

Latest Videos FromIT Pro

Notably, it could also communicate with other Mac applications such as Mail, Safari, or Messages, and carry out actions through them without specific permission.

"Gemini will still ask user permission before purchasing products, creating accounts, accepting legal terms, or modifying sensitive information about you," the report reads.

Deeper AI integration

The news highlights the lengths to which vendors will go to gain access to high-quality, up-to-date and unique AI training data, according to Ilia Kolochenko, founder of ImmuniWeb.

"Today, 99% of websites, online archives and web libraries have erected technical barriers to ban AI data scrapers, leaving AI vendors without access to free data,” he said.

“We will almost certainly see all major AI companies following Google and collecting their AI training data via various 'creative' techniques.”

Kolochenko added that access to training data is an “existential question for all Ai vendors,” but most will “probably accept the risk”.

The situation is even riskier for smaller vendors, he noted, many of whom are limited by funds and other resources to procure training data for in-house AI models.

"They form the so-called AI training pools, where hundreds of smaller players submit some data and, in exchange, can use all other data from the pool," he said. "Eventually, once you share your data with a small AI startup, it may end up in thousands of wrong hands around the globe."

Apple's AI security focus

The news comes as Apple tightens up Mac security for AI agents, announcing plans to introduce additional controls that will require Mac users to take "very explicit" action to enable Full Disk Access.

"Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems —including files, mail, messages, and even browsing history —without users’ full knowledge and understanding," said the firm.

"Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action."

The new Gemini feature hasn't yet been enabled, and it's not clear when Google might plan to do so.

ITPro approached Google for comment, but did not receive a response by time of publication.

FOLLOW US ON SOCIAL MEDIA

Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.

You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.

TOPICS
Emma Woollacott

Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.