OpenAI is rolling out Lockdown Mode for ChatGPT users who handle sensitive files. The setting is meant to reduce the damage from prompt injection, where a hidden instruction inside a file or web page tries to make the model leak data.
Eligible personal accounts include Free, Go, Plus and Pro. Self-serve ChatGPT Business accounts get it too. OpenAI says users must be logged in and may not see it yet.
OpenAI Lockdown Mode help page
ChatGPT loses live tools
Lockdown Mode blocks or limits the tools most likely to send data out. Web browsing can only use cached content, so answers may be stale or missing. Deep research and agent mode are disabled. Live connector access and write actions are blocked for personal and self-serve business accounts.
ChatGPT can still read files you upload by hand. Image generation also stays available where it already works. But Canvas code loses approved network access, and ChatGPT cannot download files for data analysis.
OpenAI Lockdown Mode tool limits
It is not magic
Lockdown Mode does not stop hidden instructions from appearing in a document or changing an answer. It tries to block the final step, where private data leaves through a network request.
Managed workspaces still need admin controls for apps, connectors, roles and actions. For a lawyer, reporter, executive or company worker dropping private files into ChatGPT, losing agent mode may be an acceptable trade if it removes a path back to the internet.




