AIToday

OpenAI's Lockdown Mode rolls out to prevent data theft in prompt injection attacks

Simon Willison's WeblogJun 6, 2026

Summaries like this, in your inbox every morning.

Sign up free →

3 Key Points

  1. OpenAI first teased Lockdown Mode in February; it is now live and rolling out to eligible personal accounts (Free, Go, Plus, and Pro) and self-serve ChatGPT Business accounts.

  2. Lockdown Mode limits outbound network requests to prevent the final stage of data exfiltration from a prompt injection attack (a technique where malicious instructions embedded in content can alter ChatGPT's behavior). It does not prevent the injection itself from appearing in cached web content or uploaded files.

  3. The feature addresses what the article calls the "Lethal Trifecta"—when an LLM system has access to private data, exposure to untrusted content, and a way to transmit data back to an attacker. By cutting off the exfiltration vector using deterministic mechanisms not evaluated by AI systems, Lockdown Mode attacks one leg of that attack chain.

Get the latest AI Business & Industry news every morning

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytime

Discussion

No comments yet. Be the first to share your thoughts!

Log in to join the discussion

Related Articles

Stay ahead with AI news

Get curated AI news from 200+ sources delivered daily to your inbox. Free to use.

Get Started Free

Free · takes 30 seconds · unsubscribe anytime

1 minute a day. The AI essentials.

200+ sources · Email / LINE / Slack

Get it free →