
OpenAI has introduced Lockdown Mode, a new ChatGPT setting designed to reduce the risk of prompt injection attacks by limiting how the product handles external content. The company says the feature is aimed at people and organizations working with sensitive data, and that it adds stricter protections against data exfiltration when users rely on ChatGPT to process information from the web or uploaded files.
What Lockdown Mode changes
Prompt injection attacks work by hiding malicious instructions inside content that an AI system later reads, such as web pages, documents, or other source material. OpenAI says Lockdown Mode is intended to make those attacks harder to exploit by cutting off several features that can expose ChatGPT to risky content.
When Lockdown Mode is turned on, ChatGPT will disable live web browsing, meaning users can only access cached content instead of fresh pages from the internet. The mode also turns off retrieval and display of images from the web, although users can still generate images. In addition, it disables deep research and agent mode.
Those limits matter because features that browse, retrieve, and reason across external sources can create more opportunities for hidden instructions to influence a model’s behavior. By reducing the number of active pathways for web content and tools, OpenAI is trying to make it harder for malicious prompts to steer responses or cause sensitive material to be shared unintentionally.
Why OpenAI says the mode is needed
OpenAI was careful to note that Lockdown Mode is not a complete defense. The company says ChatGPT could still be vulnerable to prompt injections even with the setting enabled. It gave two examples: malicious instructions could still “appear in cached web content or in an uploaded file, and could still affect the behavior or accuracy of a response.”
That caveat is important. Lockdown Mode is not being presented as a guarantee that prompt injection is impossible. Instead, OpenAI describes it as a way to reduce the chances that sensitive data gets shared during an attack. In practical terms, the goal is to lower risk rather than eliminate it entirely.
OpenAI said, “Lockdown Mode is not intended for everyone,” adding that it is “designed for people and organizations that handle sensitive data and want stricter protection from data exfiltration risks related to prompt injection.”
Who can use it now
The company says it is currently rolling out Lockdown Mode to self-serve ChatGPT Business accounts, as well as eligible personal accounts. OpenAI did not provide additional detail in the source material about the rollout timeline or any broader availability plans beyond that initial release.
That positioning suggests the feature is aimed first at users with stronger security needs rather than general consumers. Business customers are more likely to work with private internal information, client data, or other material that would benefit from a tighter operational profile. Eligible personal accounts may also include users who want to use ChatGPT in more constrained settings where data handling is a concern.
How the feature fits into the prompt-injection problem
Prompt injection has become one of the central security concerns for AI systems that can read outside content and act on it. The basic risk is that a system may not fully distinguish between a user’s request and instructions embedded by a third party inside a document, page, or file. If the model follows those hidden instructions, it can produce inaccurate output, reveal data, or behave in ways the user did not intend.
Lockdown Mode appears to be OpenAI’s response to that specific class of risk. By disabling live browsing, web image retrieval, deep research, and agent mode, the company is removing or reducing features that may broaden the model’s exposure to untrusted content. That does not make the system immune, but it does reduce the number of moving parts that can be manipulated.
The feature also reflects a broader trend in enterprise AI: customers want more control over when models can connect to the open web and how they treat information from outside sources. Security-conscious users often prefer a narrower toolset if it offers a better chance of preventing accidental disclosure or behavior influenced by malicious content.
What the source material does and does not say
The announcement, as described in the source material, focuses on the security purpose of Lockdown Mode and the feature restrictions it introduces. It does not include technical implementation details, pricing changes, or statements about whether the mode affects model quality beyond the limitations of the disabled functions.
- OpenAI says Lockdown Mode is meant to add protection from prompt injection attacks.
- Live web browsing is disabled, leaving cached content as the available web source.
- Retrieval and display of web images are disabled, but image generation still works.
- Deep research and agent mode are also disabled.
- OpenAI says prompt injection risk is reduced, not eliminated.
- The rollout is underway for self-serve ChatGPT Business accounts and eligible personal accounts.
Why this matters for sensitive workflows
For many users, browsing the web inside an AI interface is one of the most useful features ChatGPT offers. But that convenience can create a security tradeoff when the content being read may not be trustworthy. A malicious actor can hide instructions in a webpage or file with the hope that an AI system will treat them as legitimate directives. In settings where the consequences of data exposure are high, that tradeoff becomes harder to accept.
Lockdown Mode is OpenAI’s answer for those situations. The design suggests a deliberate move toward a more conservative operating mode, one that favors reduced exposure over maximum capability. Users who need live browsing, image retrieval, research functions, or agentic behavior may still prefer the standard experience, but those with stricter controls may see the new mode as a practical option.
At the same time, OpenAI’s warning that the feature is not foolproof sets expectations appropriately. The company is signaling that prompt injection remains an unsolved problem across the industry and that features like Lockdown Mode are part of a layered defense strategy rather than a final fix.
Bottom line
OpenAI’s Lockdown Mode is a targeted security feature for ChatGPT users handling sensitive data. It disables live web browsing, web image retrieval, deep research, and agent mode to reduce the chances that hidden instructions in external content can influence the model and lead to data exfiltration. OpenAI says the setting is now rolling out to self-serve ChatGPT Business accounts and eligible personal accounts, while also making clear that prompt injection risks can still remain even with the mode enabled.
Source: Original report
Was this helpful?
Last Modified: July 7, 2026 at 9:20 pm
10 views

