OpenAI unveils Lockdown Mode to protect sensitive data from prompt injection attacks
OpenAI added Lockdown Mode, a stricter setting meant to reduce prompt-injection risks for sensitive users. It turns off live web browsing, web images, deep research, and agent mode.
Intelligence analysis by GPT-5.4 Mini

OpenAI is rolling out Lockdown Mode for ChatGPT Business and some personal accounts. The feature limits several web-connected capabilities to lower the chance that hidden instructions in online content or files can trick ChatGPT into exposing sensitive data.
OpenAI added a special safety setting like a stronger seat belt for ChatGPT. It turns off some features that look at the web so tricky hidden instructions are less likely to fool it into sharing private stuff.
Analysis
What OpenAI changed
OpenAI says Lockdown Mode adds extra protection against prompt injection attacks, where malicious instructions are hidden inside webpages or other content sources that a chatbot might read. With the mode enabled, ChatGPT loses access to live web browsing, web image retrieval and display, deep research, and agent mode.
What it is meant to do
The company frames the feature as a way to reduce the chance that sensitive information gets shared during an attack. It is aimed at people and organizations that handle sensitive data and want stricter protection from data exfiltration risks tied to prompt injection.
The limits
OpenAI is not presenting Lockdown Mode as a full fix. The company says ChatGPT can still be vulnerable even with the mode on, including cases where malicious instructions appear in cached web content or uploaded files and still influence a response. That makes the feature a risk-reduction tool, not a guarantee.
Rollout
OpenAI says Lockdown Mode is now rolling out to self-serve ChatGPT Business accounts and eligible personal accounts. The release signals that security controls are becoming a more explicit part of AI product design, especially for users who need tighter safeguards around external content.
Key points
- OpenAI introduced Lockdown Mode as an added defense against prompt injection attacks.
- The mode disables live web browsing, web image retrieval, deep research, and agent mode.
- OpenAI says the feature is not a complete fix and can still be vulnerable in some cases.
- The rollout is starting with self-serve ChatGPT Business accounts and eligible personal accounts.
If Lockdown Mode works as intended, it could give businesses and cautious individuals a safer way to use ChatGPT with sensitive material. The narrower feature set may lower the chance that hidden instructions in web content can influence answers or expose data.
The protection is not complete, and OpenAI says cached web content or uploaded files can still carry harmful instructions. That means users may assume they are fully safe when some prompt-injection risk still remains.



