This has broader implications than Custom GPTs
--
Yeah this seems overblown. Custom GPTs can already make requests via function calls / tools to 3rd party services.
The only difference I see here, is the UI shows you when a function call happens, but even that is easy to obscure behind a 'reasonable sounding' label.
The expectation should be: If I'm using a 3rd party's GPT, they can see all the data I input.
This is the same as any mobile app on a phone, or any website you visit.
The only real 'line' here in a cultural sense might be offline software or tools that you don't expect to connect to the web at all for their functionality.