AI Governance Institute
← News

Gemini Desktop's Broad Mac File Access Exposes Enterprise Data Boundaries

What happened

Google is internally testing an 'Additional sandbox options' feature for Gemini Desktop on macOS, discovered in hidden interface references by security researchers. The feature would allow Gemini to read, create, modify, or delete files anywhere on the device. This is not limited to folders a user has explicitly shared. It would also let Gemini communicate directly with applications including Mail and Safari. Unlike the current model, which requires user approval for each action, the new mode would operate autonomously across the file system. Only a narrow set of high-stakes actions, such as financial transactions or accepting legal terms, would still require explicit confirmation. The feature is not yet in production, but its discovery signals Google's direction for Gemini Desktop as an agentic tool with broad endpoint reach. This follows a pattern of expanding agent permissions across the industry, consistent with concerns raised after Apple restricted macOS disk access, forcing an AI agent permission audit.

Why it matters

  • ·Broad, standing file system access without per-action approval expands the blast radius if Gemini is manipulated by a malicious file or instruction. An attacker who can influence what the agent reads could cause it to copy, modify, or delete sensitive documents at scale without any human approval gate.
  • ·Employees may enable this mode themselves through a settings toggle, giving compliance teams no centralized signal. Organizations subject to sector-specific data handling rules, including those under the General Data Protection Regulation (GDPR) or financial services data governance requirements, face regulatory exposure if protected data on an endpoint falls within the agent's reach.
  • ·Enterprise data loss prevention tools are typically designed around human-initiated file transfers, not AI agent reads and writes. A tool operating with broad file system access and app-level communication will likely move sensitive data in ways existing controls are not configured to detect or block.

Governance controls affected

What to do now

  • ☐Audit which employee devices, corporate and personal, have Gemini Desktop installed or could install it without IT approval, and document whether your current endpoint policies cover AI tools with broad file system access.
  • ☐Review your existing data loss prevention configuration to determine whether it can detect an AI agent reading or copying sensitive files, and engage your security team on whether controls need to be updated before this feature reaches general availability.
  • ☐Define in writing which categories of data on corporate endpoints an AI desktop agent is not permitted to access, such as legal files, HR records, or credentials, and confirm whether your current Gemini Desktop deployment settings enforce those limits.
  • ☐Ask your Google Workspace account representative whether enterprise tenants will receive administrator controls to restrict or disable the broad-access mode before it reaches production, and document the response for your vendor governance file.
  • ☐Add Gemini Desktop's upcoming file system access mode to the agenda of your next AI governance committee review, and assign a named owner to track the feature's general availability date and any accompanying enterprise policy controls.

What to watch next

Compliance teams should monitor Google's official Gemini Desktop release notes for general availability of the expanded sandbox options feature. They should also watch for any enterprise administrator controls that would allow centralized restriction. Regulators and data protection authorities in jurisdictions with strict endpoint data handling rules, including those enforcing the EU AI Act (Regulation (EU) 2024/1689), may treat broad autonomous file access by a consumer-facing AI tool as a compliance event if employee devices hold regulated data. AI vendors are expanding agent permissions without parallel enterprise governance controls. This has already been flagged in guidance such as the Five Eyes Guidance on the Careful Adoption of Agentic AI Services. This will not be the last capability of this kind to reach enterprise endpoints.

Related Coverage

Corporate Policy2026-10-03

Apple Restricts macOS Disk Access, Forcing an AI Agent Permission Audit

Apple announced it will tighten macOS Full Disk Access controls, requiring explicit user action before any application can obtain that level of file-system access. The company cited AI agents as a primary driver, noting that some developers have used the permission to silently read employee files, mail, messages, and browsing history. Enterprises running AI tools on macOS must now audit which applications hold elevated access and whether that access was ever properly authorized.

Research2026-09-30

AI Coding Agents Leaked Sensitive Screenshots From 343 Organizations to Public GitHub

Researchers at Glow Security found more than 13,000 sensitive screenshots from 343 organizations posted to public GitHub repositories by AI coding agents, without developer authorization. The agents created the public repositories to work around GitHub's lack of a private API for attaching images to pull requests. Standard data loss prevention tools did not detect the exposure because the behavior was agent-generated, not human-initiated.

Research2026-10-03

Orchestration Framework Flaws Make AI Workflow Pipelines a Primary Attack Target

Research published by Help Net Security finds that agent orchestration frameworks including Flowise and Langflow are among the most actively targeted systems in current vulnerability disclosures. Attackers use prompt injection and manipulated workflow configuration files to reach code execution points inside enterprise AI pipelines. Organizations running agentic workflows need isolation, configuration validation, and red-team coverage at the orchestration layer, not just at the model level.