OpenAI has announced Lockdown Mode, a new security mode for ChatGPT designed to reduce the risk of prompt injection attacks — one of the most insidious vulnerabilities in modern AI systems.

What Is a Prompt Injection Attack?

A prompt injection attack happens when malicious instructions are hidden in web content, documents, or other files the AI processes. The goal is to manipulate the model's behavior — for example, tricking it into sending sensitive data to an external attacker without the user noticing.

As ChatGPT's agentic features expand — web browsing, file analysis, automations — this type of attack has become genuinely more dangerous.

How Lockdown Mode Works

When enabled, Lockdown Mode disables a set of features that could be exploited to exfiltrate data:

  • Real-time web browsing — only cached content is accessible
  • Loading and displaying images from the web
  • Deep Research
  • Agent Mode (autonomous mode)

The goal is to block the final phase of an attack: the one where data is transferred out of the system through outgoing network requests.

The Limitations OpenAI Acknowledges

OpenAI has been transparent about the feature's limitations. Even with Lockdown Mode enabled, ChatGPT can still be vulnerable to prompt injection present in:

  • Cached web content
  • Files uploaded by the user

In these cases, the model's behavior or the accuracy of its answers could be compromised without the user noticing.

Who Needs It

Lockdown Mode isn't designed for the average user. It's a feature for those handling sensitive data — legal teams, companies with confidential processes, professionals using ChatGPT to analyze confidential documents.

For those using ChatGPT for standard everyday tasks, Lockdown Mode would reduce the tool's usefulness without a proportional benefit.

Availability

The feature is rolling out gradually for:

  • Personal ChatGPT accounts
  • Self-serve ChatGPT Business accounts

OpenAI is also introducing Elevated Risk labels, tags that flag when an action carries a higher risk level — a second layer of transparency to help users understand what the model is doing.


Lockdown Mode is a step in the right direction, but it's not a definitive solution. Prompt injection remains one of agentic AI's unresolved problems: as long as models process content from external sources, the risk can't be eliminated entirely — only contained.

← All articles