Skip to main content
Live
Main content

OpenAI ships Lockdown Mode to blunt prompt injection attacks in ChatGPT

The new setting disables live browsing, image retrieval, deep research, and agent mode for accounts handling sensitive data.

Jaeden Schafer
Editor in Chief · · 4 min read
OpenAI logo

OpenAI introduced Lockdown Mode for ChatGPT on June 6, 2026, a setting that strips out the model's most exposed surfaces to reduce the risk of prompt injection attacks against sensitive data. When the mode is on, ChatGPT loses live web browsing, web-based image retrieval, deep research, and agent mode — the features most likely to pull attacker-controlled instructions into a session. The rollout is going first to self-serve ChatGPT Business accounts and eligible personal accounts.

Prompt injection is the attack where malicious instructions are hidden inside webpages, documents, or other content that a model ingests, then executed as if the user had typed them. The risk has scaled in step with agentic features: the more autonomy a model has to browse, fetch, and act, the more damage a buried instruction can do. Lockdown Mode is OpenAI's attempt to give security-conscious customers a kill switch for that attack surface.

Lockdown Mode will disable live web browsing (so you can only access cached content), the retrieval and display of images from the web (you can still generate images), deep research, and agent mode.
OpenAI, company statement

The specifics matter. Live browsing is replaced with cached content only, web image retrieval is disabled while generation is preserved, and deep research and agent mode are turned off entirely. That is a deliberate trade: users keep the conversational core of ChatGPT and lose the parts that reach out to the open internet on their behalf.

Key facts

  • 01OpenAI announced Lockdown Mode on June 6, 2026, a ChatGPT setting aimed at reducing data exfiltration risks from prompt injection.
  • 02The mode disables live web browsing, web image retrieval, deep research, and agent mode while leaving image generation intact.
  • 03OpenAI concedes ChatGPT can still be vulnerable to prompt injections hidden in cached web content or uploaded files.
  • 04The rollout targets self-serve ChatGPT Business accounts and eligible personal accounts.
  • 05OpenAI explicitly says Lockdown Mode is not designed for general users, but for organizations handling sensitive data.

OpenAI is candid that the feature is not a complete fix. The company notes that even with Lockdown Mode active, ChatGPT can still be vulnerable to prompt injections that arrive through cached web content or uploaded files, and those injections could still affect the behavior or accuracy of a response. The goal, OpenAI says, is to reduce the likelihood that sensitive data leaks during such an interaction — not to eliminate the attack class.

The framing of who this is for is unusually direct for a consumer-facing AI feature.

That positioning lines up with the ChatGPT Business rollout. The customers most likely to flip Lockdown Mode on are firms in regulated sectors — legal, healthcare, finance, defense contracting — where the cost of a single data exfiltration incident dwarfs the productivity hit from losing browsing and agent mode. For a knowledge worker drafting documents against internal files, the trade reads as cheap insurance.

It also reflects where the industry's threat model has moved. A year ago, prompt injection was largely a research curiosity demonstrated against early browsing plugins. With agentic workflows now in production at OpenAI, Anthropic, Google, and Microsoft, security teams have a real concern that an LLM acting on a user's behalf can be hijacked by content the user never explicitly trusted. Lockdown Mode is an acknowledgment that defenses at the model layer alone are not yet good enough.

The caveat OpenAI flagged — that uploaded files can still carry injections — is the unresolved piece. Document upload is core to how enterprise users actually work with ChatGPT, and Lockdown Mode does not disable it. That means a malicious PDF or spreadsheet routed through a normal business workflow remains a plausible attack vector, even with the strictest setting enabled. Security teams adopting the feature will need layered controls around document intake rather than treating Lockdown Mode as a single solution.

Related · from this week
EU designates ChatGPT a Very Large Online Search Engine under DSA
Jaeden Schafer · 4 min read →

Lockdown Mode shifts the burden of the trade-off onto the customer in a way that is healthier than pretending prompt injection is solved. OpenAI is telling business buyers: here is a switch, here is exactly what it disables, and here is what it still cannot protect you from. That clarity is the right posture for selling AI into regulated industries, where procurement teams want to see specific controls rather than vague safety claims. The harder question for OpenAI — and every competitor shipping agentic features — is how long the market will tolerate a security model that depends on customers turning capabilities off to stay safe.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

OpenAI logo
Security

EU designates ChatGPT a Very Large Online Search Engine under DSA

OpenAI, Reddit and Roblox have until end of December 2026 to comply with the bloc's toughest platform rulebook.

Jaeden Schafer4 min read
OpenAI logo
Security

Chatbots keep failing users in mental health crises — clinicians want the safety data opened up

13% of Americans report using chatbots for emotional advice, but researchers still can't measure how often the models cause harm.

Jaeden Schafer5 min read
OpenAI logo
Security

ChatGPT logs entered as evidence in Palisades fire trial, jury unconvinced

Prosecutors leaned on Jonathan Rinderknecht's chatbot history; the jury split 10-2 for the defense and the judge declared a mistrial.

Jaeden Schafer4 min read