HeadlinesBriefing favicon HeadlinesBriefing.com

OpenAI’s Lockdown Mode Slashes External Access to Thwart Prompt Injection

Hacker News •
×

OpenAI launches Lockdown Mode, an optional setting that throttles web and external service access to curb data exfiltration from prompt injection attacks. Available to Free, Go, Plus, Pro and self‑serve ChatGPT Business accounts, the feature disables live browsing, image retrieval, deep research, agent mode, canvas networking, and file downloads. Users can still upload images and generate them for every user.

Lockdown Mode hinges on layered safeguards: sandboxing, URL‑based exfiltration shields, monitoring, role‑based access, and audit logs. It stops outbound network requests that could ferry sensitive data to attackers, while still allowing cached web browsing and local file handling. The setting does not alter memory, conversation sharing, or training usage, keeping core ChatGPT functions intact for all users in this mode.

Admins can enforce Lockdown Mode as a role in managed workspaces, restricting live connector access and write actions while permitting read‑only synced data. The feature does not affect Codex network access, and image generation remains available. Users may toggle the setting per chat, but turning on Lockdown automatically disables Developer Mode. The rollout targets accounts handling sensitive data for organizations.