OpenAI has added a new security feature called Lockdown Mode to ChatGPT. It is an optional setting designed to reduce the risk of confidential data being exfiltrated through prompt injection attacks, and when enabled it restricts many of the features ChatGPT uses to connect to the web and external services. It is rolling out to the Free, Go, Plus, and Pro personal plans and to Business accounts, and is aimed mainly at users who handle sensitive information and want stricter protection.

What Is Lockdown Mode?

Lockdown Mode is an additional security feature for ChatGPT that became available on June 6 (US time). It was originally announced in February and is now officially available.

The goal is simple: to lower the risk of confidential data being taken out of the system when a prompt injection attack occurs. OpenAI describes prompt injection as a frontier research problem and says it addresses the issue with multiple layers of defense. Lockdown Mode is positioned as one more layer stacked on top of those.

The Threat of Prompt Injection

Prompt injection is an attack technique in which a third party embeds malicious instructions into web pages, uploaded files, and the like, tricking the AI into performing actions it would not normally be permitted to do, such as quietly sending confidential information to an outside party.

What Lockdown Mode protects is precisely this stage of sending data out. By restricting network requests, it cuts off the path that would transmit confidential data to a server prepared by an attacker. However, it does not stop the injection itself. In its FAQ, OpenAI states clearly that the feature aims to greatly reduce the risk of data exfiltration caused by prompt injection, but does not guarantee that no leakage will occur.

Features That Are Restricted When Enabled

In exchange for stronger security, turning the mode on disables or limits some of ChatGPT's features.

Live web browsing is limited to cached content, so search results may be out of date. Displaying or fetching web images within responses also becomes unavailable. The Deep Research feature and the autonomous Agent Mode are disabled, and network access for code generated in Canvas can no longer be approved. Automatically downloading external files for data analysis also stops.

On the other hand, the network access of the Codex coding assistant is not affected. Because a broad range of everyday features are narrowed, it is worth keeping in mind that you are trading convenience for security.

How to Enable It and Who It Is For

Individual users can switch it on with the Lockdown Mode toggle found under Settings, then Security, then Advanced Security. Once enabled, a status indicator appears above the input field, and you can also temporarily turn it off for specific chats. Note that Lockdown Mode and Developer Mode cannot be used at the same time; turning one on automatically turns the other off.

OpenAI says the feature is not necessary for everyone. It is intended for individuals and organizations that handle highly confidential data and want stronger protection against exfiltration via prompt injection. For general use, it is realistic to stay in the normal mode and switch as needed depending on how sensitive the information you handle is.

Summary

Lockdown Mode is an optional setting that gives up some convenient web-browsing and agent features in exchange for reducing the risk of confidential data being exfiltrated through prompt injection. It is rolling out to personal plans and Business accounts and does not affect how Codex works. As AI takes on more autonomous actions, this looks like a move by OpenAI that treats prompt injection as an ongoing challenge and lets users choose the strength of their defenses according to their own risk tolerance.