OpenAI Announces Lockdown Mode to Block Prompt Injection Data Leaks
Lockdown Mode gives organizations handling sensitive data a way to block the final stage of prompt injection attacks by cutting off outgoing network requests, though it cannot prevent the attacks themselves.
Key Facts
- OpenAI announced Lockdown Mode on June 7, 2026, as an optional security setting to reduce data leakage risks from prompt injection attacks.
- Lockdown Mode disables live web browsing, image fetching from the web, Deep Research, Agent Mode, Canvas network access for generated code, and file downloads for data analysis.
- The mode does not prevent prompt injection attacks but blocks outgoing network requests that could transfer sensitive data to attackers.
- Lockdown Mode is available for all account types and workspaces, rolling out gradually, and can be enabled in ChatGPT settings under Security > Advanced Security.
- Lockdown Mode and Developer Mode cannot be enabled simultaneously; a status message appears above the composer when Lockdown Mode is active.
Reporting from 1 source: GIGAZINE.
OpenAI has introduced Lockdown Mode, an optional security setting that restricts web-connected features in ChatGPT to reduce the risk of data leakage from prompt injection attacks. The mode disables live browsing, image fetching, Deep Research, Agent Mode, and other external network features, trading convenience for stricter protection. It is rolling out gradually to all account types.
OpenAI announced Lockdown Mode on June 7, 2026, as an optional security setting designed to reduce data leakage risks from prompt injection attacks. The mode works by limiting outgoing network requests that could transfer sensitive information to attackers, effectively blocking the final stage of such attacks. However, it does not prevent prompt injection from occurring in the content ChatGPT processes, such as cached web content or uploaded files.
When Lockdown Mode is enabled, several features are disabled: live web browsing is restricted to cached content only, image support cannot fetch images from the web, Deep Research and Agent Mode are turned off, Canvas cannot approve network access for generated code, and ChatGPT cannot download files for data analysis. Image generation remains available if other features are active.
Lockdown Mode is available for all account types and workspaces but is being rolled out gradually. It can be found in ChatGPT settings under Security > Advanced Security. OpenAI notes that Lockdown Mode and Developer Mode cannot be enabled simultaneously, and a status message appears above the composer when the mode is active. Users can disable it for a specific chat through the status message or the More options menu.
Synthesized by Yomimono from the 1 cited source below, including Japanese-language reporting where cited, then editorially reviewed before publishing.