OpenAI has added a new security setting to ChatGPT called Lockdown Mode. The goal is to reduce the risk of sensitive data leaking out through prompt injection attacks. When the setting is on, web browsing is limited to cached content, and Deep Research and Agent Mode are turned off. Alongside it, OpenAI also introduced "Elevated Risk" labels that flag features carrying higher risk. This article breaks down what the new setting restricts, who it is meant for, and where its limits lie.
What prompt injection actually is
A prompt injection is an attack that gets an AI to quietly carry out instructions other than the ones it was given. Attackers plant malicious instructions inside web pages, in files that users upload, or in data from connected third-party apps. When the AI reads that content, it can be tricked into behaving in ways the user never intended, or into sending sensitive information from the conversation to an outside party.
The more ChatGPT expands features such as web browsing, file reading, and integration with external services, the more often it comes into contact with these "instructions that slip in from outside." Lockdown Mode works by deliberately narrowing that surface area, cutting off the routes that can lead to data exfiltration.
The features Lockdown Mode restricts
With Lockdown Mode enabled, the ways ChatGPT can interact with the outside world are intentionally pared back. The main restrictions are as follows.
First, web browsing is limited to cached content, so real-time access is no longer possible. The point is to avoid sending new traffic outside the network OpenAI controls, and thereby to prevent sensitive data from being smuggled out to an attacker within that traffic. Retrieval and display of images from the web are also blocked, although image generation itself remains available.
In addition, Deep Research, which investigates across multiple sources, and Agent Mode, in which ChatGPT carries out actions on its own, are disabled entirely. OpenAI says it shuts these tools off "deterministically," reflecting an approach of closing down the capabilities most likely to serve as a foothold for an attack before they can be used.
Who it is for and where it is available
OpenAI is clear that "Lockdown Mode is not intended for everyone." It is aimed at individuals and organizations that handle sensitive data and want stricter protection against data exfiltration. The company has in mind users who need to guard against advanced threats, such as executives at prominent organizations and security teams.
Availability is expanding in stages. The setting is offered on the business, education, healthcare, and educator plans (ChatGPT Enterprise, ChatGPT Edu, ChatGPT for Healthcare, and ChatGPT for Teachers), and it is also rolling out to self-serve ChatGPT Business accounts as well as eligible personal accounts on Free, Go, Plus, and Pro. OpenAI has signaled that it plans to widen access for general consumers over the coming months.
"Elevated Risk" labels arrive at the same time
In the same announcement, OpenAI also unveiled "Elevated Risk" labels. These are indicators that tell users when a feature carries relatively higher risk because the AI is connecting to the web or to external apps.
The labels are being organized as a shared standard across multiple products, including the browsing-focused ChatGPT Atlas and the developer-oriented Codex, in addition to ChatGPT itself. The aim is to make it clearer which actions involve risk through outside connections, so that users can take appropriate care based on how they use the tools.
A reminder that it is not a cure-all
While Lockdown Mode tightens defenses in exchange for some convenience, OpenAI cautions that it is not a cure-all. It can substantially reduce the risk of prompt injection, but it does not guarantee that data exfiltration cannot happen.
Malicious instructions may, for example, still be lurking inside cached web content or an uploaded file, in which case they could affect the behavior or accuracy of a response. Using Lockdown Mode also means giving up some of the convenience of web browsing, agents, and deep research. The strength of the protection and ease of use are a trade-off, and it is a setting to choose based on how sensitive the information you handle is.
Summary
Lockdown Mode is a new security setting that deliberately narrows the routes ChatGPT uses to interact with the outside world, lowering the risk that sensitive data leaks out through prompt injection. Web browsing is limited to cached content, and retrieval of web images, Deep Research, and Agent Mode are turned off. It is aimed mainly at individuals and organizations that handle sensitive information, and availability is spreading from the business plans to eligible personal accounts. Together with the newly introduced "Elevated Risk" labels, it adds one more option for using AI safely. Still, because it is not a complete defense, users will need to weigh protection against convenience depending on the information they handle.
