OpenAI rolls out Lockdown Mode to all ChatGPT users to combat prompt injection attacks

Reviewed byNidhi Govil

3 Sources

Share

OpenAI has expanded Lockdown Mode availability to all ChatGPT users, including free accounts, offering advanced protection against prompt injection attacks. The optional security setting blocks outbound network requests to prevent data exfiltration, though it disables features like Deep Research, Agent Mode, and live web browsing in exchange for enhanced security.

OpenAI Expands Security Feature to All ChatGPT Users

OpenAI is rolling out Lockdown Mode as an optional security setting across all ChatGPT account types, including Free, Plus, Pro, Go, and self-serve Business users

2

. Previously limited to enterprise plans, this ChatGPT security feature now provides protection against prompt injection attacks for anyone handling sensitive information

3

. The expansion marks a significant shift in how OpenAI approaches AI security, making advanced defenses accessible beyond corporate users.

Source: PC Magazine

Source: PC Magazine

Understanding Prompt Injection Attacks and Data Exfiltration Risk

Prompt injection attacks have emerged as a critical security issue as LLM use has skyrocketed in recent years, with researchers identifying these threats as increasingly prevalent

1

. These attacks involve bad actors hiding malicious instructions inside content that conversational chatbots process, such as PDF files or webpages, attempting to hijack the AI and extract valuable company data

1

. In August 2025, researchers at Anthropic compromised users of Claude for Chrome browser extension with a 23.6% success rate via prompt injections, while Brave researchers demonstrated similar vulnerabilities in Perplexity's Comet AI browser

1

. When someone sends an AI to perform tasks on the web, malicious actors can lace their materials with prompts designed to trick the LLM into surrendering personal data without user knowledge

2

.

How Lockdown Mode Functions to Prevent Outbound Network Requests

Lockdown Mode operates by limiting outbound network requests, acting as a final line of defense to prevent ChatGPT from sharing data with third parties if malicious prompts are encountered

1

. When enabled, it prevents ChatGPT from making live outbound network requests, stopping any attempts to exfiltrate sensitive information

2

. OpenAI bills this as building on robust protections already offered through ChatGPT, its models, and backend systems, specifically designed for people and organizations wanting stricter protection from data exfiltration risks related to prompt injection

3

. The feature doesn't stop prompt injections from appearing in processed content but prevents attackers from extracting sensitive data by restricting network requests they could exploit

3

.

Significant Trade-offs When Enabling the Optional Security Setting

Activating Lockdown Mode requires accepting substantial functionality limitations to restrict internet access. Web browsing becomes limited to accessing only cached content, meaning users have restricted access to freshly updated web pages

1

. ChatGPT may not display images in regular responses or retrieve images from the web, though users can still upload image files and generate their own images

1

. The chatbot cannot download files for data analysis, and users cannot approve Canvas-generated code to access the network

1

. Deep Research and Agent Mode are disabled completely when the feature is active

1

3

. OpenAI emphasizes the feature disables or limits specific features depending on outbound requests but maintains that memory, file uploads, conversation sharing, and model training settings remain unchanged and separately configurable

3

.

Activating Lockdown Mode and Additional Security Features

Users can enable Lockdown Mode by navigating to Settings, selecting Security, and turning on the toggle under Advanced Security

1

. The feature may take time to fully roll out to all eligible accounts

2

. Users can temporarily disable protection by selecting Manage from the status message above the chat window and choosing Turn off for this chat

3

. Separately, OpenAI is introducing an active session manager allowing users to view devices or browsers accessing their account, with options to log out of individual or all sessions at once, though the latter can take up to 30 minutes to complete

3

. OpenAI notes that while designed to substantially reduce the risk of successful prompt injection-based data exfiltration, the feature does not guarantee protection against newly discovered techniques or combinations of methods

1

. This acknowledgment suggests users should monitor emerging threats and maintain layered data privacy approaches as the cybersecurity landscape continues evolving alongside AI capabilities.

Source: Engadget

Source: Engadget

Today's Top Stories