OpenAI announced Lockdown Mode on June 6, a new feature designed to provide extra protection against prompt injection attacks in ChatGPT, particularly for users managing sensitive information [1, 2]. Prompt injection attacks involve malicious instructions hidden in webpages or other content that try to manipulate chatbot responses.

Lockdown Mode disables several features that could allow such attacks to affect the model’s output. Specifically, it turns off live web browsing, retrieval and display of images from the internet, Deep Research, and Agent Mode capabilities [1, 2]. Users can still upload photos and generate images, but these images cannot be pulled live from the web or shown within the chatbot's replies [2].

Despite these restrictions, OpenAI warns that prompt injections can still occur through cached web content or uploaded files, potentially influencing response behavior or accuracy [1, 2]. The feature aims to reduce the chance that sensitive data is exposed during these attacks.

OpenAI stated Lockdown Mode is not meant for all users. "It is designed for people and organizations that handle sensitive data and want stricter protection from data exfiltration risks related to prompt injection," the company said [1].

The mode does not alter other settings such as memory, file uploads, conversation sharing, or the use of conversations for model improvement. These remain independently configurable by workspace administrators [2].

Lockdown Mode is currently rolling out to self-serve ChatGPT Business accounts and eligible personal accounts, including free tier users [1, 2]. This step aims to give more users tools to secure their data in environments vulnerable to prompt manipulation.

The rollout began in early June and will continue to expand across user accounts that require enhanced safeguards against prompt injections.