OpenAI's message on September 23, 2026 started with a line that admits the product was behind: "We heard you loud and clear." The fix is three upgrades to ChatGPT Voice: plugins, the GPT-6 model family, and a seat inside ChatGPT Work.
The announcement says Voice can now "use plugins like your email, calendar, and Slack," be "powered by GPT-6 Astra, Sol, and Luna," and be "used in ChatGPT Work on web and mobile, so you can create docs, decks, sites, and spreadsheets or tackle complex tasks in the browser, just by talking." It is "rolling out globally today in the latest version of the app," and drew about 1.5 million views.
This guide explains what changed, how it fits with earlier voice work, what to check before enabling it, and what the first user replies say about rollout gaps. Background reading: ChatGPT Voice on desktop with GPT Live and the GPT-Live launch.
TL;DR
| Question | Answer |
|---|---|
| What is new? | Plugins in Voice, GPT-6 Astra/Sol/Luna support, Voice inside ChatGPT Work |
| Which plugins? | Examples given: email, calendar, Slack |
| Which models? | GPT-6 Astra (most capable), Sol (medium), Luna (small), subject to plan/workspace |
| Where? | Web and mobile; latest app version |
| Rollout? | Global, but some Work and model features are gated |
| Can it create files? | In ChatGPT Work: docs, decks, sites, spreadsheets by talking |
| Permissions? | Still apply; connecting an app does not open the whole account by default |
| Missing? | Live video with voice, per a user request |
Change 1: plugins in Voice
Until now, voice conversations were mostly self-contained: you could talk, get answers, and maybe search. Plugins change that. Voice can now reach the same kinds of connected apps that typed chat uses: your email, your calendar, your Slack.
That turns voice from a Q&A toy into an interface for actions: "What is on my calendar tomorrow, and move my 3 pm to Thursday," or "Summarize unread messages in the #launch channel." The permissions model matters here. Reporting on the announcement stresses that permissions still apply, so a plugin does not automatically expose everything in your account.
For builders, this echoes OpenAI's plugin standardization; see agent plugins as an OpenAI standard across AWS, Cursor, GitHub and VS Code.
Change 2: GPT-6 Astra, Sol and Luna in Voice
Voice can now be powered by the GPT-6 family. Astra is the most capable model and has been out for a few weeks; Sol and Luna are the medium and small models, upgraded to GPT-6 the day before. Model availability is subject to plan and workspace settings.
Why it matters: earlier voice modes used specialized realtime models. Letting the flagship family drive conversation means better reasoning during calls, but also higher cost and quota sensitivity. See our coverage of GPT-6 Astra launch, benchmarks and pricing, Sol and Luna, and the usage limit changes that affect how often you can use the strongest model.
Practical note: if you rely on Voice for long sessions, Luna or Sol may be the pragmatic choice; save Astra for complex reasoning. Check what your model picker shows, because plan tiers differ.
Change 3: Voice inside ChatGPT Work
ChatGPT Work is OpenAI's cloud-connected agent workspace. With this update you can use Voice inside Work on web and mobile to "create docs, decks, sites, and spreadsheets or tackle complex tasks in the browser, just by talking."
That is the biggest conceptual shift. Voice is no longer only a conversation surface; it becomes a control surface for an agent that produces artifacts. For background, read ChatGPT Work vs Codex, ChatGPT Work's thread orchestration on mobile and Work's cloud browser with signed-in websites.
A voice-first workflow looks like:
- "Start a new deck about Q3 results using last month's spreadsheet."
- Voice hands the task to Work, which uses connected files.
- You correct verbally: "Make slide three simpler."
- Work produces the file; you review on screen.
What early replies reveal
The first responses are a useful reality check.
- "I needed this last month." Positive interest from power users.
- "Ah yes, an email plugin exactly what customers have been petitioning for." A sarcastic reply suggests some users wanted different priorities, such as reliability or video.
- "I don't see it in Work yet. When does it go live?" Rollout gaps are real; the announcement says rolling out today, and features are plan and workspace gated.
- Mobile confusion: one user could see Work chat and scheduled tasks on mobile but not Voice in Work, suggesting staged rollout by surface.
- "Bring back live video with voice chat." A request for video, which OpenAI did not announce.
If you do not see the update: update the app, restart, check workspace admin settings for plugins and Work, and confirm your plan includes the model you expect.
Risks specific to voice plus plugins
Voice changes the risk profile of connected apps.
| Risk | Why voice makes it worse | Mitigation |
|---|---|---|
| Misheard command | No visual confirmation | Require confirmation for send, delete, pay |
| Accidental trigger | Ambient speech | Push-to-talk; disable in public |
| Over-broad scopes | Easy to click "allow all" | Start read-only; add write scopes later |
| Data exposure | Spoken content in shared spaces | Use headphones; avoid sensitive topics aloud |
| Prompt injection | Emails and Slack messages can carry hostile instructions | Treat plugin content as untrusted; see below |
The last one is critical. When Voice reads your email or Slack and then acts, hostile text in a message can try to steer the agent. Our guide to indirect prompt injection explains the attack. Keep human confirmation on any irreversible action.
How this compares with other voice agents
- Meta Muse added voice and real-time video at Connect and is bringing Muse to glasses; see Meta Connect 2026.
- Claude voice mode supports tools and multiple languages; see Claude voice mode.
- OpenAI's API offers voice agents via GPT-Live-1.
- Google shipped Gemini 3.8 Flash TTS for expressive output the same week.
- Fish Audio launched Drama 3 for fine-grained voice direction.
The pattern: every major lab is turning speech into an agent interface, and the differentiator is connected actions plus reliability, not the voice itself.
Try these voice workflows
- Morning brief: "Summarize my calendar and unread email, flag anything that needs a reply today."
- Meeting prep: "Pull the last thread with [client] from Slack and draft three talking points."
- Doc creation in Work: "Create a one-page project brief from these notes." Review visually before sharing.
- Spreadsheet edits: "Add a column for cost per unit and fill it from the price list." Verify formulas.
- Read-only first week: enable plugins with read permissions only; add write scopes after you trust the behavior.
When to use voice, and when to type
Voice is faster for intent and slower for precision. That split should decide which tasks you hand to it.
Use voice for:
- Capturing intent while your hands are busy: commuting, cooking, walking between meetings.
- Rough drafting: "give me a first pass at the announcement email, friendly but short."
- Read-only lookups: schedules, unread counts, message summaries.
- Iterating on a document you can see: "shorter," "more formal," "move the pricing up."
Type (or at least review on screen) for:
- Anything with exact numbers, names, addresses or code.
- Sending, deleting, paying or sharing. A spoken "yes" is easy to give by accident.
- Sensitive content in shared spaces.
- Long, structured prompts where you want to control every constraint.
A useful habit is speak to start, read to finish: dictate the task, then read the result and confirm actions on screen. That keeps the speed of voice without giving up the review step that typed workflows have by default.
A rollout checklist for teams
If you manage a ChatGPT workspace, treat this like any new connected-app surface.
- Inventory plugins. Decide which are allowed in Voice, not just in chat. Email and Slack contain the most sensitive data.
- Set scopes. Prefer read-only for the first two weeks.
- Decide the default model. Astra costs more of your quota than Luna; pick defaults deliberately and tell people why.
- Write a two-line policy for spoken use in public places and on shared devices.
- Log a sample of sessions during the trial and review failure cases: misheard names, wrong calendar events, wrong recipients.
- Train on injection. Show your team that a hostile email can contain instructions the agent may try to follow.
- Re-check after each app update. Voice and Work are changing quickly, and settings can shift.
Individuals can use the same list in miniature: connect one plugin, use it for a week, then add another.
Bottom line
This update closes a long-standing gap: Voice can finally act on your connected tools and run on the newest models, and Work gets a hands-free front door. It also raises the stakes. Voice plus email and Slack is an injection surface, and rollout is uneven. Start with read-only scopes, keep confirmations on, and update the app before judging the feature.
Details reflect OpenAI's September 23, 2026 announcement and press coverage. Feature availability varies by plan, workspace and region.
Related reading
- ChatGPT Voice on desktop with GPT Live and Codex Work
- GPT-Live: OpenAI's ChatGPT Voice model
- GPT-Live-1 API for voice agents
- ChatGPT Work vs Codex: complete guide
- GPT-6 Sol and Luna: launch and pricing
- ChatGPT Voice price cut and gift credits
- What is indirect prompt injection?
- Official: OpenAI announcement on X
