OpenAI introduced Lockdown Mode for ChatGPT on June 6, 2026, a setting that strips out the model's most exposed surfaces to reduce the risk of prompt injection attacks against sensitive data. When the mode is on, ChatGPT loses live web browsing, web-based image retrieval, deep research, and agent mode — the features most likely to pull attacker-controlled instructions into a session. The rollout is going first to self-serve ChatGPT Business accounts and eligible personal accounts.
Prompt injection is the attack where malicious instructions are hidden inside webpages, documents, or other content that a model ingests, then executed as if the user had typed them. The risk has scaled in step with agentic features: the more autonomy a model has to browse, fetch, and act, the more damage a buried instruction can do. Lockdown Mode is OpenAI's attempt to give security-conscious customers a kill switch for that attack surface.
“Lockdown Mode will disable live web browsing (so you can only access cached content), the retrieval and display of images from the web (you can still generate images), deep research, and agent mode.”— OpenAI, company statement
The specifics matter. Live browsing is replaced with cached content only, web image retrieval is disabled while generation is preserved, and deep research and agent mode are turned off entirely. That is a deliberate trade: users keep the conversational core of ChatGPT and lose the parts that reach out to the open internet on their behalf.
Key facts
- 01OpenAI announced Lockdown Mode on June 6, 2026, a ChatGPT setting aimed at reducing data exfiltration risks from prompt injection.
- 02The mode disables live web browsing, web image retrieval, deep research, and agent mode while leaving image generation intact.
- 03OpenAI concedes ChatGPT can still be vulnerable to prompt injections hidden in cached web content or uploaded files.
- 04The rollout targets self-serve ChatGPT Business accounts and eligible personal accounts.
- 05OpenAI explicitly says Lockdown Mode is not designed for general users, but for organizations handling sensitive data.
OpenAI is candid that the feature is not a complete fix. The company notes that even with Lockdown Mode active, ChatGPT can still be vulnerable to prompt injections that arrive through cached web content or uploaded files, and those injections could still affect the behavior or accuracy of a response. The goal, OpenAI says, is to reduce the likelihood that sensitive data leaks during such an interaction — not to eliminate the attack class.
The framing of who this is for is unusually direct for a consumer-facing AI feature.
That positioning lines up with the ChatGPT Business rollout. The customers most likely to flip Lockdown Mode on are firms in regulated sectors — legal, healthcare, finance, defense contracting — where the cost of a single data exfiltration incident dwarfs the productivity hit from losing browsing and agent mode. For a knowledge worker drafting documents against internal files, the trade reads as cheap insurance.
It also reflects where the industry's threat model has moved. A year ago, prompt injection was largely a research curiosity demonstrated against early browsing plugins. With agentic workflows now in production at OpenAI, Anthropic, Google, and Microsoft, security teams have a real concern that an LLM acting on a user's behalf can be hijacked by content the user never explicitly trusted. Lockdown Mode is an acknowledgment that defenses at the model layer alone are not yet good enough.
The caveat OpenAI flagged — that uploaded files can still carry injections — is the unresolved piece. Document upload is core to how enterprise users actually work with ChatGPT, and Lockdown Mode does not disable it. That means a malicious PDF or spreadsheet routed through a normal business workflow remains a plausible attack vector, even with the strictest setting enabled. Security teams adopting the feature will need layered controls around document intake rather than treating Lockdown Mode as a single solution.
Lockdown Mode shifts the burden of the trade-off onto the customer in a way that is healthier than pretending prompt injection is solved. OpenAI is telling business buyers: here is a switch, here is exactly what it disables, and here is what it still cannot protect you from. That clarity is the right posture for selling AI into regulated industries, where procurement teams want to see specific controls rather than vague safety claims. The harder question for OpenAI — and every competitor shipping agentic features — is how long the market will tolerate a security model that depends on customers turning capabilities off to stay safe.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




