ChatGPT gets optional security mode that cuts web access

AI NewsJune 8, 2026·6 min read

OpenAI has begun rolling out Lockdown Mode, an optional security feature that disables ChatGPT’s web access and external integrations to reduce data exfiltration risk from prompt injection attacks. For institutional investors and enterprise users handling sensitive data, the feature represents a critical step toward operational security in AI deployment, though it does not eliminate the underlying injection threat itself.

  • Lockdown Mode disables live web browsing, deep research, agent mode, file downloads, and connected financial tools and shopping features entirely.
  • Enterprise account admins can create custom Lockdown Mode roles and assign them to specific members or groups within their organizations.
  • The feature does not prevent malicious instructions embedded in cached content or uploaded files from altering model responses, it only blocks data exfiltration after injection occurs.
  • 76% Prompt injection attack success rate jump across model generations in three months
  • 27% Baseline capture-the-flag security challenge score before Lockdown Mode development
  • December 2025 Date OpenAI disclosed escalating prompt injection vulnerability metrics

OpenAI has begun a gradual rollout of Lockdown Mode across personal and business accounts, marking the platform’s most direct response yet to the accelerating threat of prompt injection attacks. The optional security setting cuts off ChatGPT’s ability to browse the live web, execute deep research functions, operate in agent mode, and download files for data analysis.

It also terminates access to connected experiences including financial tools and shopping agent features. The feature is designed specifically for users and organizations that process sensitive data and require stricter isolation from external data channels.

The rollout spans Free, Go, Plus, and Pro personal accounts, as well as ChatGPT Business accounts, with Enterprise customers gaining the ability to assign custom Lockdown Mode roles to specific team members or groups.

Prompt injection attacks jumped from 27% to 76% success across model generations in three months

Prompt injection has emerged as one of the most difficult security challenges in AI product deployment. Attackers embed hidden instructions within documents, web pages, or other content that a language model processes, attempting to trick the system into disclosing sensitive information or executing malicious actions.

The attack vector is subtle: it does not require breaking encryption or exploiting traditional code vulnerabilities, but instead leverages the model’s tendency to follow instructions embedded anywhere in its input stream, including content it retrieves from external sources.

OpenAI’s own December 2025 security analysis revealed the severity of this threat in stark terms. In a capture-the-flag security challenge designed to measure prompt injection vulnerability, success rates climbed from 27 percent to 76 percent across successive model generations within a single three-month window.

That 49-percentage-point jump underscores the pace at which attack techniques are outrunning defensive measures. The disclosure prompted OpenAI to prioritize architectural changes that would allow users to reduce their exposure, even if the underlying vulnerability persists.

The company has layered multiple defensive approaches already: sandboxing, URL filters, system monitoring, and audit logs all run in the background. Lockdown Mode adds another tier, but with a critical limitation. It does not prevent malicious instructions from appearing in cached web pages or uploaded files that the model processes.

Instead, it intercepts data at the exit point, blocking the final step where exfiltrated information would leave OpenAI’s infrastructure and reach an attacker.

Lockdown Mode blocks external data channels but leaves injection vectors open

The feature operates through a straightforward mechanism: when enabled, it cuts off the pathways through which ChatGPT normally interacts with the outside world. Web search results are restricted to cached content, which may be incomplete or outdated. Live image retrieval stops functioning, though users retain the ability to upload their own images and generate new ones.

Canvas code loses network access entirely. The restrictions are granular enough that a user can toggle Lockdown Mode on or off for individual conversations without affecting the entire account setting.

OpenAI has been explicit about what Lockdown Mode does not accomplish. The feature will not prevent prompt injections from appearing in content that ChatGPT processes. An attacker who embeds malicious instructions in a document that a user uploads, or in a cached web page that the model retrieves, can still alter how the model responds and what it outputs.

Lockdown Mode merely ensures that if the model is tricked into exfiltrating data, that data cannot be transmitted out of OpenAI’s systems to an external recipient. In security terms, it is a containment measure rather than a prevention measure.

This distinction carries significant implications for institutional deployment. Organizations handling highly sensitive data, financial records, intellectual property, trade secrets, medical information, must understand that Lockdown Mode reduces risk but does not eliminate it.

Enterprise admins gain granular control over Lockdown Mode deployment per team

The rollout structure reflects OpenAI’s recognition that security requirements vary across users and use cases.

OpenAI explicitly states that “Lockdown Mode is not intended for everyone,” but rather “designed for people and organizations that handle sensitive data and want stricter protection from data exfiltration risks related to prompt injection.” For enterprise customers, this translates into operational flexibility.

Enterprise account administrators can create custom Lockdown Mode roles and assign them to specific members or groups, allowing security policies to be tailored to individual departments or projects without forcing a one-size-fits-all restriction across the entire organization.

The feature can be toggled within advanced security settings and operates independently of Developer Mode: enabling Lockdown Mode automatically disables Developer Mode, and vice versa. Importantly, Lockdown Mode does not alter ChatGPT’s memory settings, file upload capabilities, conversation sharing options, or whether conversations are used for model training.

Those functions remain separate and controllable through existing privacy and data governance controls. This separation is critical for organizations that need to balance security with workflow efficiency and model improvement cycles.

The gradual rollout means some accounts will not see the feature immediately in their settings menu, and users must wait for OpenAI to extend access to their specific account tier.

Institutional investors face security-capability tradeoff in production AI deployments

For institutional crypto investors and enterprise blockchain operators, Lockdown Mode presents a strategic choice. The feature allows organizations to reduce the attack surface for systems handling sensitive data, private keys, contract details, financial records, user PII, by trading broad functionality for narrower, more defensible scope.

A blockchain firm that uses ChatGPT to analyze smart contracts, review transaction patterns, or process customer inquiries can now segment that usage: high-sensitivity workstreams run with Lockdown Mode enabled, while lower-risk analysis or user-facing queries run with full feature access.

The feature’s availability across both personal and business tiers means individual contributors, small teams, and large enterprises can adopt it at different scales. Business account holders gain enterprise-grade role management, while smaller organizations can enable Lockdown Mode uniformly or selectively.

This flexibility is essential for crypto and fintech firms that often operate with distributed security postures, where different teams handle data with different sensitivity levels and regulatory requirements.

OpenAI’s acknowledgment of the three-month surge in prompt injection attack success rates signals that the threat will likely continue to evolve faster than defenses can keep pace. Organizations that deploy ChatGPT in production environments for sensitive workloads should treat Lockdown Mode as a necessary but insufficient control.

It reduces one specific attack vector, data exfiltration through external channels, without addressing the underlying vulnerability. Institutions will need to layer Lockdown Mode with additional safeguards: input validation, output filtering, access controls, audit logging, and segmentation of sensitive data before it reaches the model.

The key decision point for institutional users is whether to adopt Lockdown Mode as a standard policy for sensitive workstreams now, or to wait for OpenAI to announce additional prompt injection defenses. OpenAI has not disclosed a timeline for further security enhancements beyond Lockdown Mode, leaving organizations to assess their own risk tolerance and compliance obligations independently.

Get this in your inboxThe Crypto Coin Show newsletter covers the policy and market moves institutional crypto investors are pricing in.

Subscribe