Gemini Desktop's Broad Mac File Access Exposes Enterprise Data Boundaries
What happened
Google is internally testing an 'Additional sandbox options' feature for Gemini Desktop on macOS, discovered in hidden interface references by security researchers. The feature would allow Gemini to read, create, modify, or delete files anywhere on the device. This is not limited to folders a user has explicitly shared. It would also let Gemini communicate directly with applications including Mail and Safari. Unlike the current model, which requires user approval for each action, the new mode would operate autonomously across the file system. Only a narrow set of high-stakes actions, such as financial transactions or accepting legal terms, would still require explicit confirmation. The feature is not yet in production, but its discovery signals Google's direction for Gemini Desktop as an agentic tool with broad endpoint reach. This follows a pattern of expanding agent permissions across the industry, consistent with concerns raised after Apple restricted macOS disk access, forcing an AI agent permission audit.
Why it matters
- ·Broad, standing file system access without per-action approval expands the blast radius if Gemini is manipulated by a malicious file or instruction. An attacker who can influence what the agent reads could cause it to copy, modify, or delete sensitive documents at scale without any human approval gate.
- ·Employees may enable this mode themselves through a settings toggle, giving compliance teams no centralized signal. Organizations subject to sector-specific data handling rules, including those under the General Data Protection Regulation (GDPR) or financial services data governance requirements, face regulatory exposure if protected data on an endpoint falls within the agent's reach.
- ·Enterprise data loss prevention tools are typically designed around human-initiated file transfers, not AI agent reads and writes. A tool operating with broad file system access and app-level communication will likely move sensitive data in ways existing controls are not configured to detect or block.
Governance controls affected
What to do now
- ☐Audit which employee devices, corporate and personal, have Gemini Desktop installed or could install it without IT approval, and document whether your current endpoint policies cover AI tools with broad file system access.
- ☐Review your existing data loss prevention configuration to determine whether it can detect an AI agent reading or copying sensitive files, and engage your security team on whether controls need to be updated before this feature reaches general availability.
- ☐Define in writing which categories of data on corporate endpoints an AI desktop agent is not permitted to access, such as legal files, HR records, or credentials, and confirm whether your current Gemini Desktop deployment settings enforce those limits.
- ☐Ask your Google Workspace account representative whether enterprise tenants will receive administrator controls to restrict or disable the broad-access mode before it reaches production, and document the response for your vendor governance file.
- ☐Add Gemini Desktop's upcoming file system access mode to the agenda of your next AI governance committee review, and assign a named owner to track the feature's general availability date and any accompanying enterprise policy controls.
What to watch next
Compliance teams should monitor Google's official Gemini Desktop release notes for general availability of the expanded sandbox options feature. They should also watch for any enterprise administrator controls that would allow centralized restriction. Regulators and data protection authorities in jurisdictions with strict endpoint data handling rules, including those enforcing the EU AI Act (Regulation (EU) 2024/1689), may treat broad autonomous file access by a consumer-facing AI tool as a compliance event if employee devices hold regulated data. AI vendors are expanding agent permissions without parallel enterprise governance controls. This has already been flagged in guidance such as the Five Eyes Guidance on the Careful Adoption of Agentic AI Services. This will not be the last capability of this kind to reach enterprise endpoints.
Stay ahead of stories like this
Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.
Recent issues
- AI agents this week destroyed backups at machine speed, leaked sensitive data without developer approval, and drew federal scrutiny that may extend liability to every enterprise deploying them.1 Oct
- A vulnerability that bypasses approved-plugin controls, new criminal liability for executives, and a landmark safety-disclosure framework all point to one conclusion: AI systems are outpacing the controls organizations have built around them.23 Sept
Free every Thursday. Unsubscribe anytime.
