Independent cybersecurity news and intelligence
HomeSourcesRSS
Cybersecurity News. Source-grounded Intelligence.
Back to newsroom
AI SecurityCyberDeltaForce Newsroom

ChatGPT can now connect to your personal apps to mimic writing style

ChatGPT can now connect to your personal apps to mimic writing style. OpenAI appears to be testing a new "Writing Style" feature for ChatGPT that can learn how you write by looking at examples from your connected apps.

BleepingComputerSep 7, 2026, 10:36 AM UTC3 min read
IN 30 SECONDS

Understand the story quickly

What happenedSource reporting

ChatGPT can now connect to your personal apps to mimic writing style.

Who or what is affectedSource reporting

OpenAI is now rolling out ChatGPT Astra, its most powerful model to date, to those with a $20 Plus subscription, but there's no word on when free users will get access.

Why it mattersSource reporting

OpenAI appears to be testing a new "Writing Style" feature for ChatGPT that can learn how you write by looking at examples from your connected apps.

Defender next stepCDF guidance

Identify whether the affected model, agent, framework or integration is used in your environment.

THE NEWS

The full story

Source-grounded reporting, presented as a continuous narrative.

ChatGPT can now connect to your personal apps to mimic writing style. OpenAI appears to be testing a new "Writing Style" feature for ChatGPT that can learn how you write by looking at examples from your connected apps. OpenAI is now rolling out ChatGPT Astra, its most powerful model to date, to those with a $20 Plus subscription, but there's no word on when free users will get access.

That is why agentic incidents can look different from a conventional software bug: the problem may emerge from the interaction between model behavior, permissions and connected tools rather than from one vulnerable line of code. The unusual part of this story is that the security boundary is not only the AI model itself; it also includes the tools, credentials, network access and external systems the agent is allowed to use. AI security stories frequently cross application, identity and data boundaries.

CyberDeltaForce will not infer attribution beyond the evidence currently attached to the story; that assessment can change as investigators, vendors or affected organizations release more information. AI security changes can alter data exposure, model access, agent permissions and trust boundaries. Organizations using connected AI services should map the reported issue to real models, plugins, identities, data stores and approval controls.

Action boundary — Required condition: the AI system must be able to act outside the model for a model decision to become an external security event. Privilege boundary — The effective blast radius is determined by the credentials, data, systems and permissions available to the agent or connected workflow. The security issue centers on AI models, agents, tools or connected data.

Input / influence — Required condition: OpenAI consumes instructions, content, messages or context that can influence its next action. An agent can make several individually valid intermediate decisions while pursuing a goal, and the combined sequence can become dangerous when no independent control stops a high-impact action. The practical impact depends on how models, agents, plugins and enterprise data are connected in the affected environment.

Defender interruption point — Reduce agent credentials to least privilege, require independent authorization for high-impact actions, isolate evaluation from production, and retain complete logs of instructions, decisions, tool calls and policy denials. BleepingComputer published the primary report used for this article on Sep 7, 2026. CyberDeltaForce will update the story when materially new facts, authoritative guidance or independent corroboration become available.

Identify whether the affected model, agent, framework or integration is used in your environment. Review tool permissions, data access, connected credentials and approval controls. Preserve prompt, tool-call and action logs needed to reconstruct suspicious agent behavior.

The public reporting does not establish a confirmed attacker or definitive root cause.

SOURCE EVIDENCE

What the reporting is based on

BleepingComputer

ChatGPT can now connect to your personal apps to mimic writing style

OpenAI appears to be testing a new "Writing Style" feature for ChatGPT that can learn how you write by looking at examples from your connected apps.

Open source
BleepingComputer

ChatGPT Astra is now rolling out to $20 Plus subscription

OpenAI is now rolling out ChatGPT Astra, its most powerful model to date, to those with a $20 Plus subscription, but there's no word on when free users will get access.

Open source
CYBERDELTAFORCE INTELLIGENCE

Reporting ends here. The sections below are CyberDeltaForce analysis and defender-focused interpretation.

CDF ANALYSIS

What this means

The security issue centers on AI models, agents, tools or connected data. The practical risk depends on what the AI system can access, which actions it can perform, how instructions reach it and whether high-impact actions require independent approval.

TECHNICAL PATH

Attack & Exploitation Path

A practical view of the conditions, trigger, technical path, and potential security outcome described by the available evidence.

  1. 1

    Input / influence — Required condition: OpenAI consumes instructions, content, messages or context that can influence its next action.

  2. 2

    Action boundary — Required condition: the AI system must be able to act outside the model for a model decision to become an external security event.

  3. 3

    Privilege boundary — The effective blast radius is determined by the credentials, data, systems and permissions available to the agent or connected workflow.

  4. 4

    Defender interruption point — Reduce agent credentials to least privilege, require independent authorization for high-impact actions, isolate evaluation from production, and retain complete logs of instructions, decisions, tool calls and policy denials.

DEFENDER ACTIONS

What security teams should check now

  • Identify whether the affected model, agent, framework or integration is used in your environment.
  • Review tool permissions, data access, connected credentials and approval controls.
  • Preserve prompt, tool-call and action logs needed to reconstruct suspicious agent behavior.
Continue the story

Related Cybersecurity Coverage

More cybersecurity news
CyberDeltaForce publication standards