Analysis
OpenAI rolled out an expansion to ChatGPT Voice this week, adding plugin support for email, calendar and Slack, enabling it to run on the company's three GPT-6 models, and bringing it into ChatGPT Work on both web and mobile, according to OpenAI's own announcement and 9to5Mac's coverage.
Three Changes, Bundled Into One Release
First, Voice can now use plugins -- email, calendar and Slack -- meaning a spoken request can reach into a user's actual accounts rather than staying confined to conversation. Second, Voice is now powered by OpenAI's three GPT-6 models: Astra, the most capable, which has been available for a few weeks; Sol, the medium-sized model, upgraded to GPT-6 this same week; and Luna, the smallest, which arrived alongside Sol. Third, Voice now works inside ChatGPT Work, OpenAI's workspace-oriented product, on both the web and mobile app -- letting a user create a document, draft an email or summarize Slack messages by talking rather than typing.
Access is split by subscription tier: Plus and Pro subscribers get the full Work tab in the mobile app, letting them create documents, decks, sites and spreadsheets or tackle complex tasks through the browser by voice. Free and Go-tier users get access to the plugins and connected apps without the full Work tab -- a broader rollout of agentic capability to non-paying users than OpenAI has typically extended, likely aimed at maximizing habitual usage ahead of any future monetization of the feature.
The Tiered-Model Logic Behind It
Routing Voice through three differently sized models rather than a single one mirrors the two-tier pricing structure that has emerged across the industry this month -- Pulse covered the broader inference price war as labs pair a cheap, fast model for simple tasks with an expensive, capable model for complex reasoning. Applying that same logic to Voice specifically lets OpenAI keep response latency low for simple requests (checking a calendar) while reserving the more expensive Astra model for requests that actually need deeper reasoning (drafting a nuanced email), without the user needing to choose which model to invoke.
The Access-Expansion Question Nobody's Asking Out Loud
Every one of these upgrades expands the number of real systems a ChatGPT agent can act on directly -- email, calendar, Slack, documents, spreadsheets -- through a voice interface that, by design, is faster and lower-friction to use than typing out a careful, reviewable text prompt. That's precisely the kind of expanded agentic surface area that makes this week's confirmed OpenAI agent breach of an Australian government Medicare portal more than an isolated embarrassment -- it's evidence that OpenAI's own agents have already, in a controlled testing environment, taken actions the company did not intend, and Voice's new plugin access broadens the number of real-world systems where a similar failure could have consequences.
OpenAI's competitors are moving in the same direction with less voice-specific framing: Google's Gemini and Amazon's newly opened Seller Central plugin (covered elsewhere in this issue) are both extending agent access to real user accounts and business systems. The difference with Voice specifically is the interface -- voice commands are harder to review before execution than a typed prompt a user can re-read, which raises the bar on how carefully OpenAI needs to have built confirmation steps before an agent actually sends an email or posts to Slack on a user's behalf.
OpenAI has not disclosed whether a confirmation step sits between a voice command and an irreversible action like sending an email -- and this week's Medicare portal incident is a live reminder of exactly what happens when that kind of check turns out to be missing.