New Google Gemini setting could give AI tool broad access to users' Macs
A new permission would allow an AI agent to access files and carry out actions without specific permission every time
Google is expected to introduce full access permissions for Gemini that would allow it to access any file on a macOS device, open apps, browse the web, and perform actions without asking for permission every time.
As spotted by AI news tracker TestingCatalog, the permission has been included in a new "Additional sandbox options" setting.
It allows Gemini to read, create, modify, or delete files residing anywhere on a Mac, including files outside connected folders and even files belonging to other people stored on the device.
Data could be sent and received over the network without approval for each connection, including accessing websites, APIs, and services that the user is logged into.
Notably, it could also communicate with other Mac applications such as Mail, Safari, or Messages, and carry out actions through them without specific permission.
"Gemini will still ask user permission before purchasing products, creating accounts, accepting legal terms, or modifying sensitive information about you," the report reads.
Deeper AI integration
The news highlights the lengths to which vendors will go to gain access to high-quality, up-to-date and unique AI training data, according to Ilia Kolochenko, founder of ImmuniWeb.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
"Today, 99% of websites, online archives and web libraries have erected technical barriers to ban AI data scrapers, leaving AI vendors without access to free data,” he said.
“We will almost certainly see all major AI companies following Google and collecting their AI training data via various 'creative' techniques.”
Kolochenko added that access to training data is an “existential question for all Ai vendors,” but most will “probably accept the risk”.
The situation is even riskier for smaller vendors, he noted, many of whom are limited by funds and other resources to procure training data for in-house AI models.
"They form the so-called AI training pools, where hundreds of smaller players submit some data and, in exchange, can use all other data from the pool," he said. "Eventually, once you share your data with a small AI startup, it may end up in thousands of wrong hands around the globe."
Apple's AI security focus
The news comes as Apple tightens up Mac security for AI agents, announcing plans to introduce additional controls that will require Mac users to take "very explicit" action to enable Full Disk Access.
"Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems —including files, mail, messages, and even browsing history —without users’ full knowledge and understanding," said the firm.
"Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action."
The new Gemini feature hasn't yet been enabled, and it's not clear when Google might plan to do so.
ITPro approached Google for comment, but did not receive a response by time of publication.
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Finance teams are wasting a quarter of their week checking AI slopNews AI adoption is high in financial processes, but accuracy and accountability remain challenges
-
ISACA CEO says AI compliance will be like 'SOX on steroids'News Businesses will need to do far more work in far less time to meet stringent regulations
-
‘This pause is due to a significant rise in automated submissions, the vast majority of which are not valid’: Google pauses open source bug bounty scheme over AI slop submissionsNews The Google open source scheme is the latest bug bounty to fall victim to AI-generated submissions
-
Apple targets developer AI performance gains with new M6 Mac Mini and M5 Ultra Mac Studio devicesNews The new devices, powered by the M6 and M5 Ultra chips, offer huge local AI performance capabilities
-
Apple is speeding up software patching due to AI security concerns – here’s what you need to knowNews Apple is speeding up its software patching processes amid rising concerns that AI is helping hackers to spot and exploit flaws at a far quicker pace.
-
Apple’s Siri overhaul is a ‘watershed moment’ in its long-awaited AI push – but it still has to win over skepticsNews The revamped Siri AI could put to rest questions over its lackluster approach to AI, providing it nails the roll-out
-
Developers warned to avoid 'early-access' Google Gemini toolsNews Attackers are tempting would-be users into downloading reverse shell malware
-
Apple Business: Everything you need to know about the all-new enterprise platformNews The new platform will replace the previous business suites Apple offered, with more focus on helping businesses grow through Apple Maps
-
Big tech is clamping down on open source ‘AI slop’ reportsNews Firms including Microsoft, OpenAI, and Google have pledged funding to bolster open source security and cut down on slop reports
-
Automated code reviews are coming to Google's Gemini CLI Conductor extension – here's what users need to knowNews A new feature in the Gemini CLI extension looks to improve code quality through verification