ChatGPT Voice Now Uses the Same Plugins as Text Chat
The change is confirmed by OpenAI's release notes and by independent reporting. Unite.AI reports that OpenAI added plugin support to the Live voice experience in ChatGPT across web, iOS, and Android and brought Voice into ChatGPT Work on web and mobile. OpenAI's notes add that users can follow written responses in the chat during a Voice conversation. They also say that when a Voice call in Work ends, an unfinished task can continue in text.
9to5Mac grouped the release into three upgrades. First, ChatGPT Voice can now be powered by OpenAI's three GPT-6 models. Second, plugins now work with ChatGPT Voice. This includes integration like email, calendar, and Slack. Third, Voice now works with ChatGPT Work on web and mobile. TechCrunch described the mobile side in concrete terms: Plus and Pro users will be able to use the Work tab on their phone to create a document, draft an email, or summarize Slack messages.
Plan boundaries matter here. OpenAI's notes say Free and Go users can use Voice in Chat with whatever plugins their plan supports. Voice in Work requires access to both Voice and Work. TechCrunch agrees that Free and Go users, meanwhile, will get to work with plugins and connected apps, and Tbreak reports that ChatGPT Work is rolling out on web and mobile for eligible paid plans.
The release has limits. OpenAI's Voice documentation, as Unite.AI summarizes it, says Live does not support video or screen sharing, and it cannot currently find or add files from a user's ChatGPT Library. That contradicts comparison tables circulating with this news, which credit the connector-enabled ChatGPT Voice with camera and screen sharing. On the evidence of OpenAI's own documentation, the Live plugin experience doesn't have those features today.
Voice Was the Last Surface to Get Plugins in ChatGPT
This release is the latest step in a sequence, and several details reported alongside it actually shipped earlier. Unite.AI traces the history through OpenAI's changelog. On July 8, 2026, OpenAI introduced GPT-Live-1 in ChatGPT Voice for paid users and GPT-Live-1 mini for Free users, and ChatGPT Work followed a day later. According to iThinkDifferent, OpenAI brought ChatGPT Voice back to the desktop app on July 23, 2026, and it can start, check, and steer tasks running in Chat, Work, and Codex by voice. OpenAI's Enterprise notes place that desktop Work and Codex voice mode on macOS and Windows. For Windows users, the September release extends to phones and browsers a voice workflow the Windows desktop app already had.
Multiple-account support is also older than some coverage suggests. Several stories bundled the ability to link several Gmail, Google Calendar and Google Contacts accounts into the September 23 news. OpenAI's release notes date that feature to August 28, available globally on supported Plus, Pro, Business and Enterprise plans across web, desktop, iOS and Android. On September 17, multi-account support expanded beyond the Google plugins to all ChatGPT plans. Voice now inherits those connections. It did not introduce them.
Model and pricing changes arrived on September 9. OpenAI's notes say Voice can use GPT-5.6 or GPT-6 Astra when it needs to search or reason through harder questions. They also set daily GPT-Live limits:
| Plan | Daily GPT-Live allowance (from Sept 9 notes) |
|---|---|
| Go | Up to 3 hours with GPT-Live-1 mini |
| Plus | Up to 3 hours with GPT-Live-1 |
| Pro ($100/month) | Up to 15 hours with GPT-Live-1 |
| Pro ($200/month) | Unlimited GPT-Live-1 |
| Enterprise, usage billing in USD | $0.05 per minute |
| Enterprise/Edu on credits | 1.25 credits per minute, down from 5 |
For Business Premium, Tbreak reports that Voice usage is listed at 1.25 credits per minute for GPT-Live-1.
Voice Carries No New Permissions
For administrators, the key sentence is in OpenAI's Enterprise and Edu release notes. Workspace controls continue to apply. Plugins keep their existing app access, data permissions and action restrictions. And "enabling Voice does not enable Work or a blocked plugin." The consumer notes say the same thing in shorter form: existing app connections, permissions and usage limits apply.
In practice, a workspace that has blocked the Gmail or Slack plugin doesn't get it back through Voice. A member without Work access can't reach Work by speaking. Kingy AI's walkthrough makes a similar point from the user's side: installing a plugin and switching to Work are separate steps; neither grants access to an external account by itself.
That also answers the question most coverage left open: can ChatGPT Voice send an email or post to Slack on its own? OpenAI's Enterprise notes say that when an action needs approval, the user reviews it on screen. OpenAI's September 14 entry gives more detail on the consumer permission model. ChatGPT has a global plugins permission setting whose default is "Allow low-risk actions." Under that default, ChatGPT can use connected data without asking each time, but it asks before sensitive actions such as emailing content to another person. Another plugin shows the same pattern. OpenAI's notes say the Apple Messages plugin asks by default for approval of the message and recipients before sending.
So a spoken request doesn't by default skip the confirmation step that a typed request would trigger. The approval appears on the screen, though, and a user talking to a phone in a pocket may not be looking at it. Whether a given action counts as "low-risk" depends on OpenAI's classification and the user's own setting, not on anything specific to Voice.
Some widely repeated claims don't appear in the September 23 release notes. These include a separate Slack connector alongside a ChatGPT app inside Slack, and a specific admin toggle for Slack connector actions in ChatGPT Business. OpenAI's notes on Slack go only as far as plugins generally. Treat those specific prerequisites as unconfirmed until you see them in your own admin console.
Prompt Injection Risk Grows With ChatGPT Work's Standing Access
The security concern is real, but it needs to be located precisely. The Cloud Security Alliance's 2026 research note describes indirect prompt injection: an attacker plants instructions in third-party content such as emails, calendar invites, PDFs or web pages, and an AI agent later reads that content and follows them. The risk rises when a system can't tell content it is analyzing from instructions it should follow, and it rises again when the agent can take actions rather than only summarize. An assistant that reads your inbox aloud reads attacker-controlled text as part of its job.
Voice doesn't change that exposure in kind. The plugins and their data access are the same whether you type or talk. What voice may change is supervision. Written responses appear in the chat and approvals appear on screen, but someone speaking hands-free is less likely to be watching. That is an inference, not a documented weakness. Neither OpenAI nor the CSA has reported an exploit against the September 23 feature.
Some coverage merged the voice release with a different feature that does involve continuous access: webhook-triggered scheduled tasks in ChatGPT Work, which OpenAI released on August 25. These tasks can run when a new Gmail message arrives, when a Slack channel gets a message, or when a GitHub pull request changes. That is standing, event-driven reading of incoming content, which is exactly the input path indirect prompt injection relies on. OpenAI's scoping is fairly conservative:
- Plus and Pro users can create webhook-triggered tasks in Work on web, iOS and Android. Free and Go users cannot.
- In Enterprise, Edu and ChatGPT for Healthcare, an admin must first turn on "Allow event-triggered scheduled tasks" under Permissions & roles > Work, and that permission is off by default.
- Each monitored Slack channel requires @ChatGPT to be added to it.
- Actions that need approval pause until the user reviews them.
- In ChatGPT for Healthcare, these tasks aren't covered under a Business Associate Agreement and must not handle protected health information.
Voice in Work can start and steer Work tasks. So these two features now sit closer together than they did in August, even though the September release didn't change how webhooks work.
Copilot in Teams Is Governed Through Microsoft 365 Policy
Coverage of this release often sets ChatGPT against Microsoft Copilot, Gemini Live, Alexa+ and Siri in a feature table. Those tables compare products built very differently, and none rests on head-to-head testing. As one analysis at Tech Insider put it, none of the available reporting offers a head-to-head benchmark of latency, accuracy, or reliability across the three assistants it compared. The documented differences lie in governance.
Microsoft's documentation shows Copilot built into Teams calling. A licensed participant can get real-time insights and summaries during a call. Administrators control access through Teams calling policies, including turning Copilot off or requiring a saved transcript. Copilot works with or without transcription, but if transcription never started, no transcript is available after the call. Microsoft Learn also documents a preview integration between custom Copilot Studio voice agents and Teams Phone. Microsoft labels it subject to change and not for production use.
ChatGPT governs these features in its own admin console, a separate control plane with its own roles, SCIM provisioning and audit logs. Recent release notes show that console filling out: group managers, a model-access test tool, audit logs for Codex policies, and tenant-wide SCIM that now covers the API Platform. For a Microsoft 365 shop, adopting ChatGPT Voice with plugins means running a second policy system next to Entra and Teams policies. It doesn't replace them.
The two systems meet in ChatGPT for Word. OpenAI's Enterprise notes say workspace admins can turn Word access on or off in the ChatGPT admin console, that Microsoft 365 admins must also allow the ChatGPT add-in, and that Word access will be enabled by default starting October 1, 2026. Both sets of admins have a part in that decision. OpenAI has also added SharePoint to ChatGPT Library alongside Box and Dropbox, with existing file permissions and workspace controls applying. So Microsoft content is reachable from ChatGPT even though, as noted above, Live voice can't yet pull files from Library.
What IT Admins and Individual Users Should Do Before Using ChatGPT Voice With Connected Apps
Work through this as a plugin-permission review, because that is what it is. Voice adds no access of its own. It makes the access you've already granted easier to use by speaking. If your plugin allow-list, action settings and Work access are set the way you want, Voice doesn't need a separate policy. If you've never reviewed them, this release is a good reason to start.
Enterprise and Edu admins should check which plugins are allowed or blocked per role and who has Work access. They should also confirm whether "Allow event-triggered scheduled tasks" is still off, and decide on the ChatGPT for Word default before October 1. Individual Plus and Pro users should open Settings → Plugins and decide whether "Allow low-risk actions" is acceptable across every connected account. This matters most now that personal and work accounts can sit in the same conversation.
- Enabling Voice does not turn on Work or unblock a plugin, according to OpenAI's Enterprise notes, so your existing plugin allow-list is the control that matters.
- Actions that need approval show up for review on screen, so train voice users to check the screen before approving anything that sends, posts or shares.
- Webhook-triggered tasks that watch Gmail, Slack or GitHub are off by default in Enterprise, Edu and Healthcare workspaces, and they are the right place to focus prompt-injection concerns.
- Multiple Google accounts have been supported since August 28, so review whether personal accounts are linked alongside work accounts on the same ChatGPT login.
- Microsoft 365 admins should decide on the ChatGPT for Word add-in before access turns on by default on October 1, 2026.
- Live voice doesn't currently support screen sharing or Library files, so don't plan workflows around those features.
OpenAI's voice push is really an extension of its permission model: the plugin controls that govern typed ChatGPT now govern spoken ChatGPT too, and the company has written that into its Enterprise notes. The next dates on the calendar are administrative. ChatGPT for Word turns on by default for Enterprise on October 1, and custom GPTs in affected Enterprise workspaces retire on December 11 as OpenAI moves them to plugins. Each date moves more work onto the plugin layer that voice now uses, so organizations that audit that layer now will face fewer surprises when those dates arrive.