LIVE FEED
FIRST LOOK ATLAS OWASP MEDIUM Moderate risk · Monitor closely RELEVANCE ▲ 6.2

Google Gemini Adds Full Mac File and App Access for Desktop Agents

FIRST LOOK MEDIUM ↗ MODERATE
  • What shipped: Google is testing full macOS file, app, and web access for Gemini Desktop with reduced per-action confirmation prompts.
  • Who benefits: Enterprise security and IT teams managing macOS endpoints need to establish AI agent governance policies before this capability reaches general availability.
  • Next steps: Inventory macOS endpoints that will be eligible for Gemini Desktop and document what file system paths and apps they expose · Draft an AI agent access policy that defines acceptable autonomous action scopes before the feature reaches GA · Engage endpoint detection teams to assess whether existing EDR telemetry captures AI-initiated file and app actions as distinct event sources
Google Gemini Adds Full Mac File and App Access for Desktop Agents

Defender Impact

Google’s expanded desktop agent capability for Gemini formalises what has been an emerging but poorly-scoped threat surface: AI systems performing autonomous file, application, and web actions on managed endpoints. For defenders, the significance is not the feature itself but what it demands — a structured agentic access governance model that most organisations do not yet have in place.

Capability Overview

According to references surfaced in the Gemini Desktop app by TestingCatalog, Google is testing an “Additional sandbox options” setting that, when enabled, would allow Gemini to read, create, modify, and delete files anywhere on a macOS device — not just in folders explicitly connected to Gemini. The agent would also be able to communicate with and act through native macOS applications including Mail, Safari, and Messages.

Critically, the feature includes a tiered consent model: Gemini would not require per-action confirmation for routine tasks, but would still prompt the user before high-sensitivity actions such as financial transactions, accepting legal terms, creating accounts, or modifying personal information. Google describes this as a “Claude-like experience” — an explicit reference to Anthropic’s computer-use permission model — suggesting the industry is converging on a tiered autonomy framework for desktop agents.

The feature is not yet live and Google has not made a formal announcement. Apple is also reportedly evaluating platform-level restrictions on AI agent access to personal files, which means the final capability shape may be constrained by OS-level policy before it reaches enterprise users.

Defensive Advances

Tiered permission architecture as a reference model. Google’s explicit separation of routine autonomous actions from high-sensitivity guarded actions gives defenders a concrete reference architecture when designing internal AI agent governance policies. The enumerated sensitive categories — financial actions, legal acceptance, account creation — provide a baseline that security teams can extend for their own risk profiles.

Visibility forcing function. The announcement of broad file system and app access forces organisations to formally ask questions they may have deferred: What AI agents are running on our endpoints? What can they access? How do we attribute AI-initiated actions in our telemetry? This is a maturity-accelerating development even before the feature ships.

Industry convergence signal. The convergence between Google’s tiered consent model and Anthropic’s computer-use approach suggests defenders can begin building governance frameworks against a stabilising interaction pattern, rather than chasing divergent vendor implementations.

Residual Gaps

Enterprise policy controls are undefined. The current references describe a consumer-facing toggle. It is unknown whether enterprise MDM or Google Workspace admin controls will allow IT teams to restrict or audit Gemini’s expanded access at scale. Without fleet-level policy enforcement, individual endpoint configuration becomes unmanageable.

EDR and DLP attribution gap. Most endpoint detection and data loss prevention tools attribute file and network actions to user accounts or specific application processes. AI agents acting on behalf of users may not be captured as a distinct action source, creating blind spots in telemetry and audit logs.

Apple platform uncertainty. Apple’s reported consideration of platform-level AI access restrictions introduces implementation uncertainty. Defenders cannot finalise integration guidance until the interaction between Apple’s macOS controls and Gemini’s access model is resolved.

No public audit trail specification. It is unclear whether Gemini will provide tamper-evident logs of actions taken autonomously, which is a prerequisite for any regulated environment deploying agentic AI on managed endpoints.

Framework Mapping

This capability most directly maps to LLM08 (Excessive Agency) — the OWASP category covering AI systems that take consequential actions beyond their intended scope. The tiered consent model is a partial control against this. AML.T0086 (Exfiltration via AI Agent Tool Invocation) and AML.T0051 (LLM Prompt Injection) are relevant because broad file system access combined with web browsing creates a surface where malicious content in files or web pages could redirect agent behaviour. AML.T0080 (AI Agent Context Poisoning) applies where adversarial content in Mail or Messages could manipulate Gemini’s action context.

Deployment Considerations

Organisations should treat this pre-release announcement as a planning trigger rather than a reaction point. The time between now and general availability is the appropriate window to: define what file system paths and applications are acceptable for AI agent access on managed endpoints; assess whether existing EDR platforms can distinguish AI-initiated actions from user-initiated actions; and engage Google Workspace or device management teams on what enterprise policy controls will be available at launch.

Organisations in regulated sectors should also begin documenting what audit log requirements they will impose on any agentic AI capability before procurement or rollout decisions are made.

Defender Checklist

  • Map which macOS endpoints in your fleet would be in scope for Gemini Desktop and assess their data sensitivity
  • Draft a tiered AI agent access policy defining which autonomous actions are acceptable without user confirmation
  • Confirm with your EDR vendor whether AI agent file and app actions appear as distinct, attributable events in telemetry
  • Engage DLP tooling teams to assess whether AI-mediated file reads and app interactions are inspected or logged
  • Monitor Google Workspace admin release notes for enterprise policy controls accompanying this feature
  • Review Apple platform security guidance on AI agent access restrictions as it develops
  • Establish a log retention and audit trail requirement for agentic AI actions before any rollout

References

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.