BleepingComputer reported on 3 October 2026 that Google is testing a setting called "Additional sandbox options" in its Gemini Desktop app for macOS. The setting would let the assistant read, create, modify or delete files anywhere on a Mac and act through apps such as Mail, Safari and Messages [1]. The report states that Google has not officially confirmed the feature [1].
Background
A desktop AI assistant that only answers questions needs little access to the computer. An assistant that carries out tasks needs permission to open files, press buttons in other apps and browse the web. Every extra permission widens what a mistaken instruction, or a hostile instruction hidden in a document or web page, could do on that Mac.
Findings
According to BleepingComputer, the setting was spotted by the account TestingCatalog on X while examining the Gemini Desktop app's source code [1]. The report quotes the interface text: "By enabling additional sandbox options, you will be able to expand what Gemini can do and access on your Mac" [1].
The report lists the permissions the setting would add: reading, creating, modifying or deleting files anywhere on the Mac, access to files outside folders the user has explicitly connected, and communication with apps such as Mail, Safari and Messages, with actions performed through them [1]. It also quotes a warning in the interface: "Depending on which settings you enable, Gemini may be permitted to take actions without asking for your permission first" [1].
BleepingComputer states that Gemini would still ask for confirmation before purchasing products, transferring money, creating accounts, accepting legal terms or modifying sensitive personal information [1]. The report gives no release date and no version number [1].
Implications for Mac users
If the setting ships as described, a user who switches it on would be granting an assistant broad authority over personal files and over apps that hold mail and messages. The warning text the report quotes indicates that some actions could run without a prompt [1]. The report does not say whether the setting is off by default, and it does not say how the sandbox is enforced.
The report is a description of unreleased code and interface strings. It does not show the feature working, and a test setting can change or be dropped before release [1].
Recommendations
- Before enabling any option that widens an AI assistant’s access, read the permission text and decide which folders and apps are in scope.
- Keep personal and work files that the assistant does not need outside folders it can reach.
- Review the Privacy & Security pane in System Settings for the assistant’s entries, such as Files and Folders, Automation and Accessibility, and remove those that are not needed.
- Prefer settings that require a confirmation for each action, and treat a "no confirmation" option as a deliberate risk decision.
- Check which hosts the assistant contacts, and note any destination that does not match its documented function.
Relevance to FireAI
FireAI is a firewall for one Mac. It identifies an app by its code signature and applies per-app rules to each connection that app opens, and the Activity page lists the apps that went online, newest first. The Agent profile recognises 19 AI agents, among them Gemini CLI, learns the destinations each normally contacts and flags a first-ever destination or an upload spike, using only host names and byte counts.
FireAI does not control which files an app may read, and it does not manage macOS permissions such as Files and Folders or Automation. It does not read files, mail or messages, and it cannot tell what an assistant did inside Mail or Safari. It does not read the inside of an encrypted connection. The Agent profile documentation lists Gemini CLI; it does not list the Gemini Desktop app, and this item does not claim that FireAI recognises it.
Limitations
This item relies on one report, which in turn relies on a post by a third party and on interface text; the item did not install or test Gemini Desktop [1]. Google's own documentation and statement were not available, and the report does not establish when, or whether, the setting will be released.
Try FireAI, by HisnLabs free for 17 days.