ChatGPT Lockdown Mode rolls out to all users to combat prompt injection attacks and data theft

Reviewed byNidhi Govil

11 Sources

Share

OpenAI has expanded its ChatGPT Lockdown Mode to all users, including free tier accounts, offering enhanced protection against prompt injection attacks that could steal sensitive data. The optional security setting restricts outbound network requests to prevent data exfiltration, though it limits features like live web browsing, Deep Research, and Agent Mode. While the feature doesn't stop prompt injections entirely, it acts as a final defense layer by blocking ChatGPT from sending information to attackers.

ChatGPT Lockdown Mode Expands to All Users

OpenAI has rolled out ChatGPT Lockdown Mode to all users across Free, Go, Plus, Pro, and self-serve Business accounts, marking a significant expansion of a security feature initially launched in February 2025 for Enterprise, Edu, Healthcare, and Teachers plans

1

3

. This optional security setting addresses the growing threat of prompt injection attacks, which researchers increasingly identify as a critical AI security vulnerability with attacks growing in prevalence year-on-year

2

. The feature is designed specifically for people and organizations handling sensitive data who need stricter protection from data exfiltration risks related to prompt injection

4

.

Source: TelecomTalk

Source: TelecomTalk

How Prompt Injection Attacks Threaten Data Privacy

Prompt injection attacks represent a form of social engineering specific to conversational chatbots and LLM systems

4

. Bad actors hide malicious instructions inside content that AI processes—such as webpages, PDF files, or other materials—attempting to hijack the AI and extract valuable company data or personal information

2

3

. These attacks have already demonstrated real-world impact: researchers at Anthropic compromised Claude for Chrome browser extension users with a 23.6% success rate via prompt injections in August 2025, while Brave researchers showed Perplexity's Comet AI browser was similarly vulnerable

2

. By feeding malicious commands into prompts, attackers could infiltrate chats, access external files and services, and steal personal data—all without the user knowing

1

.

Source: ET

Source: ET

How Lockdown Mode Restricts Outbound Network Requests

To protect users from data theft, ChatGPT Lockdown Mode limits outbound network requests to the internet or external file services, preventing live sensitive information from falling into attackers' hands

1

. When enabled, the feature prevents ChatGPT from making live outbound network requests, acting as a final line of defense that stops the LLM from sending personal data to attackers even if malicious prompts successfully hijack the system

3

2

. OpenAI positions this as building on robust protections already offered through ChatGPT, its models, and backend systems

4

. However, the company acknowledges that while the feature is designed to substantially reduce the risk of successful prompt injection-based data exfiltration, it does not guarantee protection against newly discovered techniques or combinations of methods

2

.

Trade-offs for a Secure ChatGPT Experience

Enabling this optional security setting comes with significant functional limitations. Live web browsing is restricted to cached content only, meaning search results may be out of date or unavailable

1

2

. ChatGPT cannot display images in regular responses or retrieve images from the web, though users can still upload their own images and generate new ones

1

4

. Deep Research and Agent Mode are completely disabled

1

5

. Canvas-generated code cannot access the network, and ChatGPT cannot download files for data analysis, though manually uploaded files can still be processed

1

2

. OpenAI notes the mode doesn't change memory, file uploads, conversation sharing capabilities, or whether conversations may be used to improve models

4

.

Source: ZDNet

Source: ZDNet

What This Means for Handling Sensitive Data

OpenAI emphasizes that Lockdown Mode is not intended for everyone but specifically for users and organizations handling sensitive data who want a more conservative ChatGPT experience when working with confidential information or connected features

3

4

. The feature doesn't prevent actual prompt injection attacks from occurring—hackers could still infect prompts with malicious instructions that tap into cached web content or uploaded files

1

. Users can enable the feature by navigating to Settings, selecting Security, and turning on Lockdown Mode under Advanced Security

1

3

. The feature is currently rolling out and may not yet be accessible to all accounts

1

5

. Separately, OpenAI is rolling out an active session manager that allows users to see devices or browsers accessing their account, with the option to log out of individual or all sessions at once

4

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved