OpenAI has introduced a new Lockdown Mode for ChatGPT, providing additional protection against prompt injection attacks that attempt to steal sensitive data. The company says the setting is for people at higher risk of cyberattacks, such as executives, security teams, or those handling confidential information.
In a prompt injection attack, an attacker hides instructions in web pages, documents, emails, and even calendar invites, then tries to get the AI on those platforms to follow those instructions instead of the user’s request. Generally, these instructions are not visible to the naked eye or are hidden in a way that makes them out of scope for normal users.
Lockdown Mode responds by cutting off many network paths attackers could use to exfiltrate data. When users turn it on, ChatGPT stops making live web requests and instead relies on cached content, which reduces the risk of leaking fresh or sensitive information during browsing.
But there is a downside to it as well: Lockdown Mode also turns off Deep Research, Agent Mode, and certain Canvas networking approvals, and it also stops ChatGPT from downloading files from the internet for analysis.
Users can still upload their own files and can create images, but ChatGPT will not show images directly in its responses in this mode. It’s confusing because OpenAI does not describe any special “later” display path for images in Lockdown Mode; it simply says ChatGPT responses cannot include images, even though image generation and uploads still work.
Lockdown Mode is available in ChatGPT Enterprise, ChatGPT Edu, ChatGPT for Healthcare, and ChatGPT for Teachers, with OpenAI planning to expand it over time. Users should be aware that the feature can’t 100% protect them from prompt injections, but it should be a useful safeguard.
Disclosure: Ziff Davis, ExtremeTech’s parent company, filed a lawsuit against OpenAI in April 2025, alleging it infringed Ziff Davis’s copyrights in training and operating its AI systems.

