
OpenAI updated the ChatGPT Business release notes on September 24, 2026, with new External access controls. Global administrators can use the redesigned External access page in the Admin Console to separately manage whether ChatGPT Sites may use members’ connected apps and whether applications may access ChatGPT Ads.
The change separates identity from data access. OpenAI explicitly says identity-only sign-in is distinct from access to data. A user may be able to sign in, while Sites access to connected apps still depends on workspace settings, individual app settings, and the member’s own authorization.
Both new permissions are off by default during the admin preview. Members still authorize connected apps with their own permissions, so the administrator switch does not automatically elevate a member’s underlying access. This gives organizations a path to test data flows in a workspace before enabling the apps and workflows they actually need.
The governance significance is not simply the addition of another settings page. It is the separation of the external data surfaces an AI agent may touch. Sites, connected apps, and Ads represent different data paths and risks, so an administrator can block one class of cross-system access and expand it later for a specific department or workflow.
The same release notes also record a September 23 Voice update. ChatGPT Work voice conversations can use connected plugins and apps, create documents, presentations, and spreadsheets, and continue an unfinished task in text after a voice call ends. OpenAI says workspace controls, app permissions, and action restrictions still apply, with on-screen review when an action needs approval.
For enterprise adopters, a sensible checklist is to map the data sources required by each agent or Site; verify that administrator, workspace, app, and user permissions agree; test read and write directions with non-production data; and only then enable the permission in production. It is especially important to distinguish the ability to search data from the ability to act on a user’s behalf.
This remains an administrative control update, not a guarantee that external-data risks are solved. Organizations still need to address third-party data policies, over-permissioning, prompt injection, retention, and human approval for consequential actions. OpenAI’s notes describe the available control plane; the resulting security posture depends on how it is configured and monitored.



