New ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltration

OpenAI’s new ChatGPT Lockdown Mode restricts web browsing, agent mode, and file downloads to block prompt injection-driven data exfiltration across all plan tiers.

litespeed-cpanel-cve-2026-48172-exploited-root

What’s new: OpenAI has introduced a new Lockdown Mode for ChatGPT to mitigate the risk of data exfiltration from prompt injection attacks. This feature is aimed at users handling sensitive data and limits various tools and capabilities that could connect to the web or external services. Lockdown Mode restricts live web browsing, image support, deep research, agent mode, and file downloads, while still allowing users to share conversations. It is available to all logged-in users across Free, Go, Plus, Pro, and self-serve ChatGPT Business plans.

Who’s affected

Users of ChatGPT, particularly those managing sensitive information, are affected by this new feature. Organizations that require enhanced security measures for data handling may find this mode beneficial.

What to do

  • Evaluate the need for Lockdown Mode based on your organization’s data sensitivity requirements.
  • Consider the limitations of Lockdown Mode and how they may impact your use of ChatGPT.
  • Review active ChatGPT sessions regularly to monitor for unauthorized access.

Sources