New ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltration
OpenAI is rolling out Lockdown Mode to reduce data exfiltration risks from prompt injection attacks by limiting networked tools.
Intelligence analysis by GPT-5.4 Mini

OpenAI is adding an optional Lockdown Mode for ChatGPT accounts that disables or restricts several web- and network-facing features. The goal is not to stop prompt injection, but to narrow the paths attackers could use to push sensitive data out of the system.
OpenAI added a safety switch for ChatGPT that closes some doors, like web browsing and file downloads, so sneaky instructions have fewer ways to leak secrets out. It is like locking extra windows in a house, even though one locked door alone does not make the house invincible.
Analysis
What OpenAI changed
OpenAI has started rolling out Lockdown Mode for eligible personal accounts, including Free, Go, Plus, Pro, and self-serve ChatGPT Business plans. The setting is meant to reduce the risk of data exfiltration that can follow prompt injection attacks, especially in workflows that involve sensitive material.
What it does
The mode limits tools and capabilities that connect ChatGPT to the web or outside services. According to the article, it disables or restricts live web browsing, image support, Deep Research, Agent mode, Canvas networking, and file downloads for data analysis. OpenAI says the idea is to reduce outbound network requests that could otherwise send data to attacker-controlled infrastructure.
What it does not do
The company is explicit that Lockdown Mode is not a cure-all. It does not stop prompt injections from happening, does not change memory or file upload behavior, and does not prevent all effects of malicious instructions. OpenAI also says the feature does not guarantee that exfiltration cannot happen, since risk may remain through enabled apps, unexpected capability combinations, or new techniques.
Related security move
The article also says OpenAI launched a session-management feature that lets users review active ChatGPT sessions and log out of one or all sessions if account abuse is suspected. That list includes device details, the app used, approximate location, sign-in time, trust status, and whether the session is current.
Taken together, the changes suggest OpenAI is trying to give users more control over both the model’s attack surface and account visibility, while trading away some convenience in the process.
Key points
- OpenAI is rolling out Lockdown Mode for eligible ChatGPT accounts to reduce prompt-injection-driven data exfiltration.
- The mode limits web- and network-facing features, including live browsing, image support, Deep Research, Agent mode, Canvas networking, and file downloads.
- OpenAI says the setting reduces risk but does not eliminate prompt injection or guarantee safety.
- A new session-management feature lets users review and log out of active ChatGPT sessions.
If the mode works as intended, sensitive users get a safer default for tasks where leaked data would be costly. The added session controls also make it easier to spot and shut down suspicious access quickly.
OpenAI says the setting still does not guarantee that exfiltration cannot happen, so determined attackers may find remaining paths through apps or new techniques. The restrictions also remove useful features, which could push some users to leave the mode off when convenience matters more than hardening.



