OpenAI Help: Lockdown Mode

Simon Willison's Blog Products

Summary

OpenAI has launched Lockdown Mode for ChatGPT to prevent data exfiltration from prompt injection attacks by limiting outbound network requests. The feature is rolling out to eligible accounts including Free, Plus, Pro, and self-serve Business.

No content available
Original Article
View Cached Full Text

Cached at: 06/08/26, 03:32 AM

# OpenAI Help: Lockdown Mode Source: [https://simonwillison.net/2026/Jun/5/openai-help-lockdown-mode/](https://simonwillison.net/2026/Jun/5/openai-help-lockdown-mode/) 5th June 2026 \- Link Blog **[OpenAI Help: Lockdown Mode](https://help.openai.com/en/articles/20001061-lockdown-mode)**\. OpenAI first teased this[in February](https://openai.com/index/introducing-lockdown-mode-and-elevated-risk-labels-in-chatgpt/), but now it's live and "rolling out to eligible personal accounts, including Free, Go, Plus, and Pro, and self\-serve ChatGPT Business accounts": > Lockdown Mode is designed to help prevent the final stage of data exfiltration from a prompt injection attack by limiting outbound network requests that could transfer sensitive data to an attacker\. Lockdown Mode does not prevent prompt injections from appearing in the content ChatGPT processes\. For example, a prompt injection could appear in cached web content or in an uploaded file, and could still affect the behavior or accuracy of a response\. This looks really good to me\. The[Lethal Trifecta](https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/)occurs when an LLM system has access to all three of access to private data, exposure to untrusted content and a way to steal data and transmit it back to the attacker\. The only way to solve the trifecta is to cut off one of the three legs, and by far the easiest leg to restrict without making your LLM systems far less useful is the exfiltration vectors to steal data\. It looks to me like lockdown mode directly attacks that leg, using mechanisms that are deterministic and, crucially, are not evaluated by AI systems that themselves can be subverted by sufficiently devious attacks\. The existence of lockdown mode does however imply that ChatGPT, in its default settings, does*not*provide robust protection against sufficiently determined data exfiltration attacks\! **Update**:[This tweet](https://twitter.com/cryps1s/status/2062923575049531422)OpenAI CISO Dane Stuckey: > Lockdown mode is not meant for everyone\. However, for folks who have an elevated risk profile \- due to who they are, what they work on, or the types of data they work with \- it's an excellent tool for further securing themselves\. This has some tradeoffs on functionality and utility, but for these users, the tradeoff is worthwhile\.

Similar Articles

OpenAI Adds Lockdown Mode (3 minute read)

TLDR AI

OpenAI introduces Lockdown Mode, an optional security setting that limits web browsing and external service access in ChatGPT to reduce data exfiltration risks from prompt injection attacks. It is rolling out to eligible personal and business accounts.

OpenAI unveils Lockdown Mode to protect sensitive data from prompt injection attacks

TechCrunch AI

OpenAI announced Lockdown Mode, a new feature for ChatGPT that provides additional protection against prompt injection attacks by disabling live web browsing, image retrieval, deep research, and agent mode. The feature is designed for users handling sensitive data and is rolling out to Business and eligible personal accounts.

Introducing Lockdown Mode and Elevated Risk labels in ChatGPT

OpenAI Blog

OpenAI introduces Lockdown Mode and Elevated Risk labels in ChatGPT to mitigate prompt injection attacks and protect sensitive data. Lockdown Mode is an advanced security setting for high-risk users that constrains ChatGPT's interaction with external systems and is available for enterprise plans with planned consumer rollout.

Introducing ChatGPT Enterprise

OpenAI Blog

OpenAI is launching ChatGPT Enterprise, offering enterprise-grade security and privacy, unlimited GPT-4 access, 32k context windows, advanced data analysis, and admin controls, with a guarantee that business data is not used for model training.