OpenAI introduced Lockdown Mode, an optional setting that deterministically disables or limits capabilities an attacker could exploit through prompt injection, such as live web access, image support in responses, Deep Research, Agent Mode, live connectors and file downloads. Elevated Risk labels flag network-related features in ChatGPT, Atlas and Codex that carry extra risk. Lockdown Mode first launched for enterprise-type plans, and a June 4, 2026 update says it is rolling out to personal and self-serve Business accounts.
Why it matters
A major vendor chose to offer capability removal, not only detection, as the stronger control for high-risk users.
Key facts
As stated in the sources, with where to find them.
- Initial availability: ChatGPT Enterprise, Edu, ChatGPT for Healthcare and ChatGPT for Teachers; admins enable it in Workspace Settings by creating a role.OpenAI post, 'Helping organizations protect employees' section
- In Lockdown Mode, web browsing is limited to cached content so no live network requests leave OpenAI's network; features without strong deterministic data-safety guarantees are disabled.OpenAI post, 'Helping organizations protect employees' section
- A June 4, 2026 update says Lockdown Mode is rolling out to personal and self-serve ChatGPT Business accounts.OpenAI post, update note
Findings that cite this record
Key questions this bears on
- Can prompt injection against AI agents be reliably defended?Not reliably. Defenses reduce injection but none has eliminated it; limiting what untrusted input can trigger is the most defensible approach.
Sources
Related records
Jan 28, 2026
Jan 19, 2026
Aug 6, 2025
Oct 31, 2025
Oct 8, 2025
Sep 25, 2025