Voice-driven ChatGPT on a smartphone can now do more than simply answer aloud; it can launch entire workflows. OpenAI has added voice control to Work mode on iOS and Android, so a task can be phrased by voice, and the agent will connect the necessary tools itself and carry the work through to a result. OpenAI documented the update in its ChatGPT release notes.
What a Voice Command Can Trigger
In mobile Work, a voice command can launch the creation of a document, presentation, or spreadsheet, work with connected apps, and actions within the cloud browser. Earlier, ChatGPT Work had already gained the ability to open websites on its own, click buttons, fill out forms, and continue tasks even after the user left the conversation.
A New Way to Interact
The key change concerns the interaction pattern itself. Users no longer need to type out a lengthy request and monitor every step. One can describe the desired end result by voice, refine the requirements as the work proceeds, and interrupt the agent whenever the direction needs to change. Text responses and intermediate results remain visible in the chat throughout.
Ending the voice conversation does not stop the task. If Work has not yet finished, the process can continue in text mode. Work’s cloud-based conversations sync across the mobile app, the web version, and the desktop client, so a task begun on a smartphone can later be opened on a computer and continued with its context preserved.
Live Voice Also Gains Plugin Access
At the same time, OpenAI has expanded the ordinary Live voice mode. It can now reach plugins and connected apps on the web version, iOS, and Android. This capability is not limited to Work subscribers: Free and Go users can work by voice with whichever plugins their plan permits. Work itself on mobile devices, however, remains available only to qualifying paid plans.
Voice Does Not Grant Extra Privileges
A voice command does not, by itself, grant the model any additional rights. Work uses only the services already connected and operates within the permissions already granted. If an operation requires confirmation, the app displays the request on screen, and it cannot be approved by voice. For enterprise accounts, workspace restrictions that an administrator can set for apps, the browser, and individual features continue to apply.
A Familiar Risk as Connections Multiply
This arrangement grows especially sensitive as the number of connections to email, corporate chat, and other services increases. Over the summer, PromptArmor specialists found that, within six weeks, the set of capabilities had changed for 37% of the ChatGPT and Claude connectors they examined. Voice control does not eliminate the pre-existing risks tied to the broad permissions integrations carry.
Bringing the Desktop Agent Model to the Phone
OpenAI is, in effect, transplanting to the smartphone an interaction model once characteristic of desktop AI agents. The phone becomes the point where a task is set, not merely a window for conversation: the user states a goal by voice, Work reaches out to apps and the browser, assembles the result, and can keep working after the conversation itself has ended.
The update rolled out on September 23, 2026. Availability depends on plan, region, app version, and workspace settings. OpenAI also keeps a separate, ordinary Chat mode for quick conversations, so moving into the agentic mode remains the user’s own choice rather than a replacement for the familiar interface.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.