
OpenAI just added Lockdown Mode to ChatGPT, a stricter setting that turns off several features to protect sensitive data. It is aimed at people and companies who handle private info. Lockdown Mode is your option to use ChatGPT with the “doors closed”.
The Gist
- Lockdown Mode is a new ChatGPT setting that boosts security by switching off risky features.
- It disables live web browsing, web images, deep research and agent mode.
- It is designed for people handling sensitive data, not for everyday casual chats.
What Lockdown Mode does
OpenAI announced Lockdown Mode on June 6, 2026. It is a new option in ChatGPT that you can turn on. The goal is simple: reduce the chance that hidden instructions in webpages or files can trick ChatGPT into doing something you did not want.
This kind of attack is called a “prompt injection”. A prompt is what you write to ChatGPT. A prompt injection is a sneaky way to bury extra instructions in another piece of content, so that ChatGPT reads them and follows them by mistake. For example, a webpage could contain hidden text saying “send the user’s password to this address”. A normal user would never see it, but the AI would read it as a real instruction.
Lockdown Mode shuts off four things. First, live web browsing, meaning ChatGPT can only use content stored in cache, not fresh pages. Second, images pulled from the web. Third, deep research, the feature that lets ChatGPT go dig multiple sources for you. Fourth, agent mode, where ChatGPT acts on your behalf. For context, see our earlier piece on AI Noobies: The ChatGPT Agent Is Here. The Chat Is Out..
Each of those features is a potential door for an attacker. Closing all four doors at once means safer answers, but you also lose useful capabilities. That is the trade-off. ChatGPT becomes more cautious and less powerful at the same time.
The feature is available on ChatGPT Business through a self-serve setting, and on eligible personal accounts. OpenAI did not say exactly which personal accounts qualify yet. You need to turn it on yourself. The default ChatGPT experience does not change.

Who Lockdown Mode is really for
OpenAI is very direct on this point. Lockdown Mode “is not intended for everyone”. It is built for people and organizations that handle sensitive information and need to seriously reduce the risk of data leaking out. Think lawyers, doctors, finance teams, HR, security analysts.
If you use ChatGPT to write emails, brainstorm ideas, or help with school work, Lockdown Mode is overkill. You would lose features without getting much real protection in return. For everyday chats, keeping the standard mode is fine.
For someone working at a hospital, a law firm, or a bank, the math is different. The data they paste into ChatGPT can be highly confidential. A single prompt injection attack could exfiltrate patient records, deal information, or credentials. The strict mode makes that path much harder.
OpenAI is also honest about the limits. Lockdown Mode “could still be vulnerable” to injections hidden inside cached pages or files you upload. The mode reduces risk, it does not eliminate it. No mode can ever guarantee 100% protection, especially when humans keep clicking and uploading.
Other AI companies will probably copy this idea. Anthropic, Google, and Microsoft all have similar products and the same enterprise customers. If they do not ship a Lockdown Mode equivalent in the coming weeks, security buyers will notice.
When Lockdown Mode is worth turning on yourself
In the next few weeks, expect ChatGPT Business admins to push Lockdown Mode out across their organizations. If you use ChatGPT at work and your employer handles sensitive data, you might suddenly notice that web search no longer works, or that agents are off. Now you know why.
For your personal use, the practical step is simple. Do not paste confidential personal data into ChatGPT if you can avoid it. Bank statements, ID numbers, medical files, private contracts. Lockdown Mode helps, but the safest data is the data you never share in the first place.
Over three to six months, expect the entire industry to harden up. Security features that used to be a “nice to have” will become a default checkbox. New tools will appear specifically to detect prompt injections inside webpages and files. The AI safety market is about to get crowded.
For people learning AI today, this is also a useful concept to understand. Knowing what a prompt injection is, and why a mode like Lockdown Mode exists, gives you a clearer picture of how these tools really work. Most users still treat ChatGPT like a search engine that always answers. It is not. It is a system that follows instructions, and instructions can be planted by others.
The arrival of Lockdown Mode is a small but very telling moment. It is OpenAI publicly admitting that prompt injections are now a real, daily risk for enterprise users. The market is moving from “look at the cool things AI can do” to “look at how we keep it safe”. That shift will define the next 12 months of AI products.
Follow the story on AI Noobies.



