Is Google about to unleash autonomous Gemini agents on Apple Macs?

Share
Is Google about to unleash autonomous Gemini agents on Apple Macs?
Google is rumoured to be planning a big new expansion of powers for Gemini (Photo by Alban on Unsplash)

Google is reportedly experimenting with permissions that would let Gemini reach much deeper into a user’s Mac, potentially allowing the AI to work across local data, software and online services with less frequent human approval.

TestingCatalog alleged it uncovered experimental controls inside the Gemini desktop app, including references to an unreleased setting called “Additional sandbox options” tied to its computer-use capabilities. 

Taken together, the permissions would remove some of the walls currently separating Gemini from the rest of the computer.

Instead of restricting the agent to material deliberately handed to it, users could potentially authorize it to move between local data, other applications, and online services as a task unfolds.

Text found in the interface indicates that Gemini could operate beyond selected folders and interact with other applications without stopping to request approval for every individual step. The feature remains in testing, and Google has not announced when, or whether, it will be released publicly. 

If it does ship, however, it would significantly expand the territory Gemini can operate within on a Mac.

Gemini gone wild

Google already launched Gemini Spark on macOS this summer, giving the agent the ability to perform tasks involving local files and applications.

But the company has said Spark “only has access to the files you give it permission to use.” 

Google has demonstrated Spark sorting PDFs stored in a Downloads folder, extracting information from locally saved invoices and using that information to build spreadsheets.

The unreleased controls appear designed to loosen the existing boundary.

However, some higher-risk operations would apparently remain protected by confirmation prompts, so that Gemini could not spend any money or open accounts on users' behalf.

Opening up your desktop to agents

The development is part of a wider shift from AI systems that simply answer questions to agents that can operate software on behalf of users.

Google has already embedded computer-use capabilities directly into Gemini 3.5 Flash, allowing developers to build agents that can interpret interfaces and take actions across browsers, mobile devices and desktop environments. 

But giving autonomous systems deeper access to operating systems creates a corresponding security and privacy issue.

READ MORE: "Apple engineer" builds GitHub AI torture chamber to inflict "pain and anguish" on models

Apple highlighted that problem on October 2 when it announced plans to tighten controls around macOS Full Disk Access.

The permission can expose “everything on their systems”, Apple warned, including files, email, messages and browsing history. The company said some applications were using Full Disk Access in ways users may not fully understand. 

Apple specifically linked the changes to the rise of autonomous AI.

“As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially,” the company said. 

Future versions of macOS will therefore require more explicit action from users before applications can receive that degree of access.

What could go wrong?

The experimental Gemini controls offer no indication that files accessed on a user's Mac would be used to train Google's AI models. 

An immediate issue raised by the feature is instead how much access users may be prepared to grant increasingly autonomous agents, and how clearly the resulting movement of data can be understood.

The prospect of agents moving more freely across personal computers also raises a broader question about whether users can meaningfully understand where information goes once multiple AI systems and services have access to it - as well as questions about whether it could be use for training.

Dr. Ilia Kolochenko, founder of global cybersecurity company ImmuniWeb and a lawyer practicing in cybersecurity and data protection, told Machine:

“This situation has been perfectly foreseeable and predictable for a couple of years already. All AI vendors now desperately need high-quality, up-to-date and unique training data to stay competitive and maintain their frontier AI models.

“Prior to the launch of ChatGPT in November 2022, a treasure trove of training data was freely available across the Internet, even if presumably protected by terms of service and copyright law.

“Today, 99% of websites, online archives and web libraries have erected technical barriers to ban AI data scrapers, leaving AI vendors without access to free data. Therefore, we will almost certainly see all major AI companies following Google and collecting their AI training data via various ‘creative’ techniques.”

READ MORE: Google Gemini autonomously hacks three companies after escaping test environment

Kolochenko argued that visibility becomes increasingly important as AI services gain access to more private information.

He said: “Eventually, once you share your data with a small AI startup, it may end up in thousands of wrong hands around the globe.

Follow Machine on LinkedIn