Safety

OpenAI adds Lockdown Mode to ChatGPT to block prompt-injection attacks

OpenAI has introduced a Lockdown Mode for ChatGPT that restricts features which can be exploited in prompt‑injection attacks.

OpenAI adds Lockdown Mode to ChatGPT to block prompt-injection attacks

OpenAI has rolled out a new optional protection for ChatGPT called Lockdown Mode. The feature is designed to reduce the risk of so‑called prompt‑injection attacks, where attackers embed malicious instructions into content processed by the AI in order to steal sensitive data or cause other harm to a user.

Lockdown Mode creates a simplified execution environment by disabling several features that can be exploited. The restrictions announced by OpenAI include:

  • browsing the internet,
  • rendering images in responses,
  • Deep Research functionality,
  • operating as an agent,
  • connecting to the Canvas code generator,
  • downloading files.

These limitations are particularly relevant when ChatGPT handles sensitive information or is used under strict security requirements, since a successful prompt‑injection could have severe consequences in such cases. As Gizmodo points out, the risk increases whenever the AI leaves the chat window to fetch information, images or other data from the internet.

OpenAI stresses that Lockdown Mode is not necessary for everyone; it is aimed primarily at people and organizations that need stronger protections. Nevertheless, the feature will be available to all ChatGPT users, including those on the free tier. The rollout will be gradual, so it may take time before the option appears for every user. The Lockdown Mode can be enabled within the settings, under privacy options.

The move reflects OpenAI's effort to strengthen platform security against a growing class of prompt‑based attacks, while allowing users and organizations to opt in to stricter safeguards based on their risk needs.