product updateOpenAI

OpenAI launches Lockdown Mode to block prompt injection data exfiltration attacks

TL;DR

OpenAI has released Lockdown Mode, an optional security setting that protects against prompt injection attacks by limiting network requests and image fetching in ChatGPT. The feature is designed for users handling sensitive data and disables some ChatGPT capabilities including Deep Research and Agent Mode.

2 min read
0

OpenAI launches Lockdown Mode to block prompt injection data exfiltration attacks

OpenAI has begun rolling out Lockdown Mode, an optional security setting available to all ChatGPT users including free tier accounts. The feature limits network functionality to prevent attackers from extracting sensitive data through prompt injection attacks.

What Lockdown Mode disables

When enabled, Lockdown Mode restricts several ChatGPT features:

  • ChatGPT cannot fetch images from the internet or display images in responses (though users can still generate and upload images)
  • File downloads are blocked (manual document uploads still work)
  • Deep Research feature is completely disabled
  • Agent Mode is completely disabled
  • Network requests that could be exploited for data exfiltration are blocked

According to OpenAI, "Lockdown Mode is not intended for everyone. It is designed for people and organizations that handle sensitive data and want stricter protection from data exfiltration risks related to prompt injection."

How prompt injection attacks work

Prompt injection is a social engineering technique targeting conversational AI systems. Attackers hide malicious instructions on webpages and other content that AI systems access when pulling information from the internet. These hidden instructions attempt to trick the AI into executing unauthorized actions.

OpenAI emphasizes that Lockdown Mode doesn't prevent prompt injections from appearing in processed content. Instead, it prevents attackers from extracting data by blocking the network requests they would exploit.

Activation and session management

Users can enable Lockdown Mode through ChatGPT's settings menu under Safety and security > Advanced security. The protection can be temporarily disabled for individual conversations through a toggle above the chat window.

The feature does not affect memory, file uploads, conversation sharing, or whether conversations may be used for model training. Those settings remain separately configurable by workspace administrators.

OpenAI is also rolling out an active session manager that shows all devices and browsers with account access. Users can log out of individual sessions or all sessions at once, though complete logout can take up to 30 minutes.

What this means

Lockdown Mode represents OpenAI's acknowledgment that prompt injection remains a real security concern as AI systems gain more autonomous capabilities and internet access. The feature trades functionality for security—a reasonable tradeoff for enterprises and users handling confidential information. The fact that OpenAI specifically warns most users don't need this level of protection suggests their existing defenses are sufficient for typical use cases. Organizations using ChatGPT for sensitive work now have a straightforward way to reduce their attack surface without abandoning the platform entirely.

Related Articles

product update

OpenAI upgrades ChatGPT memory architecture with automatic 'dreaming' synthesis, now available to free users

OpenAI is rolling out a new memory architecture for ChatGPT that automatically synthesizes information across conversations without explicit user prompts. The company announced free tier users will access memory features for the first time, while Plus and Pro users receive expanded memory capacity.

product update

OpenAI expands ChatGPT memory to free users, doubles storage capacity for paid tiers

OpenAI is rolling out an upgraded memory system for ChatGPT that synthesizes context more efficiently across conversations. The company reduced compute requirements by approximately 5x, enabling it to offer the memory feature to free users for the first time while doubling storage capacity for Plus and Pro subscribers.

product update

Cline v3.88.0 Adds Fireworks AI Kimi K2.6 as Default Model, Fixes MCP Server Management

Cline, the AI coding assistant, released v3.88.0 on June 5, 2025, switching its default Fireworks AI model to Kimi K2.6. The update fixes critical MCP server management bugs and enables the upstream recommended models endpoint for all users.

product update

Canva adds Perplexity Computer connector for autonomous design asset creation

Canva launched a connector for Perplexity Computer that enables the AI agent platform to autonomously create editable design assets based on user prompts and data. The integration is available for Perplexity Pro, Max, Enterprise Pro, and Enterprise Max subscribers.

Comments

Loading...