Quick Facts

  • OpenAI launched Lockdown Mode on June 6, 2026, for all ChatGPT accounts including free tier users
  • The feature disables live web browsing, image retrieval, and external connections to prevent data exfiltration
  • Prompt injection attacks increased 340% in enterprise AI systems during late 2025

OpenAI rolled out Lockdown Mode across all ChatGPT accounts, including free tier users, to protect against prompt injection attacks that hide malicious instructions in web content and documents.

The security feature disables live web browsing, image retrieval from the web, Deep Research, Agent Mode, and other external connections. Web browsing gets limited to cached content only, preventing live network requests from leaving OpenAI’s controlled network.

Prompt injection attacks rose 340% year-over-year in enterprise environments during late 2025, with successful attacks climbing 190%. Google reported a 32% increase in malicious prompt injection attempts between November 2025 and February 2026.

“Lockdown Mode is not intended for everyone,” OpenAI stated. “It is designed for people and organizations that handle sensitive data and want stricter protection from data exfiltration risks related to prompt injection.”

The feature targets security-conscious executives and teams at prominent organizations who require increased protection against advanced threats. OpenAI first introduced Lockdown Mode for enterprise plans before expanding to personal and business accounts.

Prompt injection ranks number one in the OWASP Top 10 for LLM Applications 2025, making it the leading AI application security risk entering 2026. The attacks work by embedding malicious instructions in content that AI models process, potentially causing data exfiltration or unauthorized actions.

OpenAI acknowledges Lockdown Mode cannot prevent all prompt injections. Malicious instructions could still appear in cached web content or uploaded files and affect response behavior or accuracy.

Industry experts note that AI-driven cyberattacks are becoming autonomous, requiring minimal human expertise. The IBM Cost of a Data Breach Report 2023 found AI-related breaches typically cost more than the $4.45 million global average due to wider impact范围.

Other AI providers including Google and Anthropic have introduced similar isolation features for enterprise offerings, but OpenAI’s expansion to all account types marks a significant industry shift toward prioritizing AI security.

Read more: OpenAI unveils Lockdown Mode to protect sensitive data from prompt injection attacks

This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.