security
Jun 6, 2026
By Teun
OpenAI rolls out Lockdown Mode for ChatGPT accounts
OpenAI has started rolling out Lockdown Mode to eligible personal ChatGPT accounts and self-serve ChatGPT Business accounts. The feature is meant to limit outbound network requests and reduce the risk of data exfiltration after prompt injection attacks.
OpenAI has begun rolling out Lockdown Mode, a new ChatGPT security feature designed to block one of the main ways prompt injection attacks can steal data. According to OpenAI, the feature is now available to eligible personal accounts, including Free, Go, Plus, and Pro users, as well as self-serve ChatGPT Business accounts.
OpenAI first teased the feature in February. The company says Lockdown Mode is intended to help stop the final stage of a prompt injection attack by limiting outbound network requests that could be used to send sensitive information to an attacker.
Prompt injection is a type of attack where hostile instructions are hidden inside content an AI system reads, such as a web page, cached content, or an uploaded file. If the model follows those instructions, it may behave in unexpected ways or expose data it should not share.
OpenAI said Lockdown Mode does not stop prompt injections from appearing in the content ChatGPT processes. That means the model can still encounter malicious instructions in web content or uploaded files, and those instructions could still affect the quality or correctness of a response.
The update has drawn attention from security-focused observers because it targets what some researchers call the “Lethal Trifecta.” In that model, an LLM system becomes especially risky when it has access to private data, can read untrusted content, and has a path to send stolen data back out. The source article argues that blocking exfiltration is the easiest of the three conditions to restrict without making the system much less useful.
The article also says Lockdown Mode appears to use deterministic controls rather than relying on another AI model to decide what is safe. That matters because systems that depend on AI-based judgment can themselves be manipulated by carefully crafted attacks.
The rollout suggests OpenAI is acknowledging a basic security problem in default chatbot setups: if an AI can read private information and access external services, it may also have a route to leak that information unless those outbound channels are tightly controlled.
For now, Lockdown Mode is limited to eligible personal accounts and self-serve ChatGPT Business accounts, according to OpenAI. The company has not said in the source article whether the feature will be expanded further or how broadly it will be applied beyond the current rollout.