Opt-In ChatGPT Lockdown Cuts Exfil Paths, Not Prompt Injection
Lockdown Mode narrows ChatGPT’s outbound access, so the protection only exists for accounts that turn it on and only against exfiltration paths that rely on the assistant reaching out to other services. It does not stop prompt injection itself, and it still leaves room for abuse through enabled apps and new capability combinations.
OpenAI is rolling it out for logged-in users on Free, Go, Plus, Pro, and self-serve ChatGPT Business plans. The mode limits web and external-service access, including live browsing, deep research, agent mode, canvas networking, image retrieval, and file downloads, and OpenAI also added session review controls so users can inspect and log out of active sessions.
The practical shift is that defenders have to decide which users get reduced tool access, not just watch for suspicious prompts. The remaining risk is the assistant’s permitted outbound paths, which can still carry sensitive data out if a workflow leaves one open.