OpenAI rolls out ChatGPT Lockdown mode to all users to block prompt injection data theft
OpenAI has expanded Lockdown mode to all ChatGPT plan tiers, including Free, Go, Plus, Pro, and Business users. The security feature blocks outbound network requests to prevent prompt injection attacks from stealing sensitive data, but disables live web browsing, Deep Research, and Agent mode.
OpenAI Rolls Out Lockdown Mode to All ChatGPT Users
OpenAI has expanded its Lockdown mode security feature to all ChatGPT users across Free, Go, Plus, Pro, and Business plans, according to ZDNET. The optional setting, which launched in February 2025 for Enterprise, Edu, Healthcare, and Teachers plans, aims to protect users from data theft through prompt injection attacks.
How Lockdown Mode Works
Lockdown mode blocks outbound network requests to the internet and external file services to prevent attackers from exfiltrating sensitive information through malicious prompts. The feature does not prevent prompt injection attacks themselves—attackers can still inject malicious commands that access cached web content or uploaded files.
What Gets Disabled
When enabled, Lockdown mode restricts the following capabilities:
- Live web browsing: ChatGPT can only access cached content, making search results potentially outdated or unavailable
- Web image retrieval: The model cannot display or retrieve images from the live web, though users can still upload images and request image generation
- Deep Research: The feature is completely disabled
- Agent mode: Unavailable in Lockdown mode
- Canvas networking: Code generated through Canvas cannot access network resources
- File downloads: ChatGPT cannot download files for analysis, but can still process uploaded files
Target Use Case
According to the report, Lockdown mode is designed for individuals and organizations handling sensitive or confidential information requiring additional security layers. The feature trades functionality for security by preventing live data connections that could be exploited by prompt injection attacks.
Availability and Activation
The feature is rolling out gradually across all ChatGPT accounts. Users can enable it through Settings > Security > Advanced Security > Lockdown Mode. A warning message explains the restrictions before activation.
What This Means
Lockdown mode represents a defensive approach to prompt injection rather than a solution. By cutting off live network access, OpenAI acknowledges that the underlying vulnerability—the ability to inject malicious instructions into prompts—remains unsolved. Organizations working with highly sensitive data now have a protection option, but at the cost of ChatGPT's web-connected capabilities. The tradeoff reveals the security challenges inherent in AI systems that blend user instructions with dynamic external data sources.
Related Articles
OpenAI Launches GPT-6 Astra With Half the Message Allowance of GPT-5.6 Sol
OpenAI has begun rolling out GPT-6 Astra to top-tier ChatGPT plans, the API, Azure, and AWS Bedrock. The model delivers roughly half the usage allowance of GPT-5.6 Sol across comparable plans, with Plus and Business users gaining access in the coming days.
OpenAI Publishes GPT-6 Astra Prompting Guide With Banned 'Slop Words' List
OpenAI has published detailed prompting guidance for GPT-6 Astra, addressing the model's tendency to over-clarify, over-test, and use clichéd AI phrasing. The documentation includes specific prompts to encourage more autonomous action and a blocklist of banned words and phrases.
Simon Willison's Pelican Benchmark Shows GPT-6 Astra Outperforming GPT-5.6 Sol at Every Reasoning Level
Developer Simon Willison ran his signature 'pelican riding a bicycle' SVG test on newly-accessed GPT-6 Astra across five reasoning levels, comparing results against GPT-5.6 Sol, Terra, and Luna. Even Astra's lowest reasoning setting reportedly beat every Sol output, though Astra costs roughly twice as much per token.
OpenAI Lists GPT-6 Astra Pro on OpenRouter: Same Model, Higher-Compute Reasoning Mode
GPT-6 Astra Pro, now listed on OpenRouter, is the existing GPT-6 Astra model configured to run with reasoning.mode set to 'pro' for higher-quality output on complex tasks. It carries a 1M-token context window and tiered pricing from $5/$25 to $20/$100 per million input/output tokens depending on the serving tier.
Comments
Loading...