As reported by BleepingComputer, Google is quietly testing a new "Additional sandbox options" setting within the Gemini Desktop app for macOS that would grant its AI assistant sweeping access to the host system — including the ability to read, create, modify, or delete files anywhere on the device, interact with native apps like Mail and Safari, and perform actions without per-step user confirmation.

AI Security Alert: Each such transition multiplies the risk calculus for security teams.

From a defender's perspective, this development is significant not because it is novel — Anthropic's Claude and Microsoft's Copilot have already staked out similar territory — but because it marks another major consumer AI platform moving from chat-only to agentic execution on the endpoint. Each such transition multiplies the risk calculus for security teams.

Why This Changes the Threat Model

Today's AI desktop assistants operate in a conversational sandbox. Tomorrow's will function as semi-autonomous agents with file system traversal, application control, and web interaction capabilities. This fundamentally alters the threat surface in several ways:
Why This Changes the Threat Model
Prompt injection escalation: A malicious document, email, or web page could contain hidden instructions that trick Gemini into executing file operations, exfiltrating data, or interacting with apps in unintended ways. When the AI has read-write-everywhere access, a single poisoned prompt becomes a full endpoint compromise vector.
Consent fatigue: Google says Gemini will still confirm before sensitive actions like financial transfers or account creation. But if users are prompted dozens of times daily for routine file operations, they will develop click-through fatigue — the same problem that plagued UAC on Windows. Attackers exploit this pattern.
Credential and session hijacking: If Gemini can interact with Safari, Mail, and Messages, it inherently has access to active sessions, cached credentials, and authentication tokens within those apps. A compromise of the AI agent is a compromise of the user's authenticated identity surface.
Supply chain adjacency: Gemini's expanded access creates a new privileged pathway. If Google's cloud infrastructure, model serving layer, or the Gemini Desktop app itself were compromised, attackers would gain a ready-made remote access tool with file system and application control on millions of macOS endpoints — no malware deployment required.

Who Is Most Affected

Enterprise security teams should be particularly concerned. While this feature is consumer-facing today, Google Workspace integration is inevitable. Once Gemini Desktop with expanded sandbox access appears on corporate Macs — whether sanctioned or installed by employees without IT approval — it creates an unmonitored execution channel that bypasses traditional DLP, EDR, and endpoint hardening controls. The fact that the setting lives behind a hidden toggle in the desktop app makes shadow IT adoption a real risk before security teams even know the feature exists.

Apple's reported consideration of restricting AI agent access to personal files is encouraging, but it creates a tension: macOS may become a battleground between platform-level security controls and third-party AI vendors demanding broader system access. Defenders should watch Apple's WWDC 2027 roadmap closely for any endpoint security architecture changes that address agent-level permissions.

Shield53 Recommendations

What You Should Do

  • Inventory and block preemptively: Add Gemini Desktop to your endpoint management inventory now. Use MDM (Jamf, Kandji, Mosyle) to block or restrict installation of the Gemini Desktop app on managed Macs until your team has evaluated the sandbox expansion feature and approved it for use.
  • Define an AI agent governance policy: Before this ships broadly, establish organizational policy on which AI agents can run on endpoints, what access levels are permitted, and who approves new agent capabilities. Include this in your acceptable use policy refresh for 2027.
  • Extend DLP and EDR monitoring: Work with your EDR vendor (CrowdStrike, SentinelOne, Microsoft Defender) to ensure they can detect and alert on AI agent file system activity. Traditional process-based detection may not flag Gemini-initiated file modifications correctly if they occur through legitimate OS APIs.
  • Test prompt injection resilience: If you allow AI agents on endpoints, run red team exercises that attempt prompt injection through documents, emails, and web content. Document how the agent responds and whether it can be coerced into unauthorized file operations.
  • Monitor Apple's API changes: Track Apple developer documentation for any new entitlement or privacy framework changes that gate AI agent access to file system, automation, and inter-app communication APIs. This will determine what's technically possible — and what your security baseline must account for.
  • Educate end users now: Brief employees that AI desktop assistants are evolving from chat tools to execution agents. Reinforce that they should never grant expanded system access to any AI tool without explicit IT approval, and explain the prompt injection risk in plain language.
The shift from conversational AI to agentic AI on the endpoint is the most consequential endpoint security change since the rise of remote work. Treat every new agent capability as a new privilege — because that's exactly what it is.

The broader implication is clear: the era of AI agents with deep system access is arriving faster than enterprise governance can adapt. Security teams that wait until these features ship broadly will find themselves playing catch-up against both shadow IT adoption and adversary exploitation of the expanded attack surface. The time to prepare is now — before Gemini's sandbox walls come down.