AI · 98 days ago
Lockdown Mode narrows ChatGPT’s outbound access, so the protection only exists for accounts that turn it on and only against exfiltration paths that rely on the assistant reaching out to other services. It does not stop prompt injection itself, and it still leaves room for abuse through enabled apps and new capability combinations.
OpenAI is rolling it out for logged-in users on Free, Go, Plus, Pro, and self-serve ChatGPT Business plans. The mode limits web and external-service access, including live browsing, deep research, agent mode, canvas networking, image retrieval, and file downloads, and OpenAI also added session review controls so users can inspect and log out of active sessions.
The practical shift is that defenders have to decide which users get reduced tool access, not just watch for suspicious prompts. The remaining risk is the assistant’s permitted outbound paths, which can still carry sensitive data out if a workflow leaves one open.
6 sources covering this story
OpenAI’s Lockdown Mode is trying to solve the problem that it created
The feature reduces the possibility of data exfiltration by slashing external capabilities, but OpenAI oddly tells enterprise CISOs ‘prompt injection is not currently a major risk.’
OpenAI Unveils ChatGPT Account Security Controls
OpenAI brings Lockdown Mode and Active Sessions to ChatGPT to curb prompt injection data theft
OpenAI is locking down parts of ChatGPT to reduce data theft risks - Help Net Security
OpenAI is rolling out Lockdown Mode for ChatGPT, a security feature that restricts external access to reduce data theft risks.
OpenAI Rolling Out ChatGPT Account Security Controls
The Active Sessions and Lockdown Mode features are being made more broadly available by the AI giant.
OpenAI unveils Lockdown Mode to protect sensitive data from prompt injection attacks | TechCrunch
Even with Lockdown Mode, ChatGPT could be vulnerable to prompt injections, but the goal is to reduce the likelihood that sensitive data gets shared in the process.
New ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltration
OpenAI Lockdown Mode limits outbound ChatGPT requests to reduce prompt injection data exfiltration risk for eligible accounts.
Part of the PlainSec briefing for 2026-06-07