If you connected your inbox to ChatGPT Voice this week, the permission it is working under is the one you set for text chat. Saying something out loud does not get its own consent flow. Per WindowsForum's September 23 write-up, Voice "follows the same permissions as the tasks it directs in Chat, Work, and Codex" and adds "no separate security layer of its own."

WindowsForum is a forum-style aggregator and the only place I have seen that stated plainly, so hold it loosely. The setting behind it is something you can check yourself, and that is worth five minutes today.

Voice picked up app connectors globally on September 23, running on the GPT-6 suite (Astra, Sol, Luna), with ChatGPT Work getting it on web and mobile. The connector list is long: Google Drive, Gmail, Google Calendar, SharePoint, Outlook Email and Calendar, Microsoft Teams, Slack, GitHub, Box and Dropbox. One OpenAI help page still says "Voice mode currently does not support apps," which has not caught up with the rollout.

Two different things are happening here, and the difference is where most people will get it wrong. Voice cannot send an email, create a calendar event or post a Slack message without you confirming the action first, and that is confirmed by a second independent outlet. I am not telling you it acts silently, because it does not. The confirmation arrives as a card on your screen, and hands-free is the one mode where you are not looking at your screen. Anything OpenAI classifies as low-risk raises no card at all.

OpenAI's published low-risk examples are "saving a private draft, changing a non-security preference, or updating a shopping cart without completing a purchase." Read that list again and decide whether it matches your own definition of low risk.

Four checks, ideally before you talk to your inbox.

1
Set the global permission before anything else.

Open the profile menu → Settings → Apps → "Ask permission" under App Preferences. The four options are "Always ask", "Allow read actions", "Allow low-risk actions" and "Allow all actions". Per OpenAI's help center, if you have changed nothing you are on "Allow low-risk actions," the third of the four. Doing nothing means you are already letting it act. I would move to "Always ask" or "Allow read actions."

2
Set a tighter rule on the account that matters most.

OpenAI says "Your default applies to connected apps unless you choose a different permission for a specific app," so a per-app setting outranks the global one. OpenAI does not say the override is offered for every connector, so check the app you actually care about, which for most people is Gmail or Outlook.

3
Audit what is already connected.

Every connector on that list was authorized in a text chat. Voice inherited those grants and did not ask you again. Something you connected in June to summarize documents is now reachable by talking. OpenAI's own line is that "exactly what ChatGPT can do depends on the service, your account permissions, and the access you have granted," so the audit is on you.

4
Stay on "Always ask" while the phone is in your pocket.

OpenAI's stated example of a sensitive action, from its Health connector docs, is asking ChatGPT to email a training plan based on your data to a running partner. That is the kind of sentence you say on a walk, with the phone away and the confirmation card facing your leg.

A simple rule: the safeguard is something you have to see, so if you cannot see the screen, stay on "Always ask."

Separately, and with a deadline attached: Anthropic raised Pro, Max and Team five-hour limits by 20% on September 22 and handed out a one-time bankable rate-limit reset that expires October 22. Spend it before then.

If you have already opened this panel, hit reply and tell me what your "Ask permission" setting said the first time you looked, and whether you had ever looked before. I want to know whether the default is holding for everyone.