OpenAI rolls out ChatGPT Lockdown mode to all users to block prompt injection data theft
OpenAI has expanded Lockdown mode to all ChatGPT plan tiers, including Free, Go, Plus, Pro, and Business users. The security feature blocks outbound network requests to prevent prompt injection attacks from stealing sensitive data, but disables live web browsing, Deep Research, and Agent mode.
OpenAI Rolls Out Lockdown Mode to All ChatGPT Users
OpenAI has expanded its Lockdown mode security feature to all ChatGPT users across Free, Go, Plus, Pro, and Business plans, according to ZDNET. The optional setting, which launched in February 2025 for Enterprise, Edu, Healthcare, and Teachers plans, aims to protect users from data theft through prompt injection attacks.
How Lockdown Mode Works
Lockdown mode blocks outbound network requests to the internet and external file services to prevent attackers from exfiltrating sensitive information through malicious prompts. The feature does not prevent prompt injection attacks themselves—attackers can still inject malicious commands that access cached web content or uploaded files.
What Gets Disabled
When enabled, Lockdown mode restricts the following capabilities:
- Live web browsing: ChatGPT can only access cached content, making search results potentially outdated or unavailable
- Web image retrieval: The model cannot display or retrieve images from the live web, though users can still upload images and request image generation
- Deep Research: The feature is completely disabled
- Agent mode: Unavailable in Lockdown mode
- Canvas networking: Code generated through Canvas cannot access network resources
- File downloads: ChatGPT cannot download files for analysis, but can still process uploaded files
Target Use Case
According to the report, Lockdown mode is designed for individuals and organizations handling sensitive or confidential information requiring additional security layers. The feature trades functionality for security by preventing live data connections that could be exploited by prompt injection attacks.
Availability and Activation
The feature is rolling out gradually across all ChatGPT accounts. Users can enable it through Settings > Security > Advanced Security > Lockdown Mode. A warning message explains the restrictions before activation.
What This Means
Lockdown mode represents a defensive approach to prompt injection rather than a solution. By cutting off live network access, OpenAI acknowledges that the underlying vulnerability—the ability to inject malicious instructions into prompts—remains unsolved. Organizations working with highly sensitive data now have a protection option, but at the cost of ChatGPT's web-connected capabilities. The tradeoff reveals the security challenges inherent in AI systems that blend user instructions with dynamic external data sources.
Related Articles
OpenAI Testing ChatGPT Feature to Export Custom Stickers Directly to WhatsApp
An APK teardown of ChatGPT's Android app reveals a hidden 'ChatGPT Stickers' feature that would let users create custom stickers and export them directly into WhatsApp as sticker packs. The feature is unreleased and its public launch timeline is unknown.
OpenAI Removes Text Chat Limits for Free ChatGPT Users, Launches GPT-5.6 Luna
OpenAI is removing text chat limits for Free and Go ChatGPT users, powered by a new GPT-5.6 Luna model with a 'Think' button for harder questions. The company also upgraded GPT-5.6 Sol for Plus and Pro users, claiming a 68% reduction in factual errors versus GPT-5.5-Instant.
OpenAI Refines GPT-5.6 Sol for ChatGPT, Unifies Instant/Thinking Modes, Makes Free Text Chat Unlimited
OpenAI is rolling out a ChatGPT-specific tuning of GPT-5.6 Sol that merges Instant and Thinking modes behind a new reasoning slider for Plus and Pro subscribers. Free users now get unlimited text chats with GPT-5.6 Luna and a new Think button.
OpenAI Removes Text Message Rate Limits for Free ChatGPT Accounts
OpenAI is removing rate limits on text-only prompts for Free and Go tier ChatGPT accounts starting next week. Image generation, file uploads, and voice mode will still be capped, and GPT-5.6 Luna becomes the new default model for those tiers.
Comments
Loading...