Generated editorial image of a lock shielding data cards from outbound network paths
Generated editorial image of a lock shielding data cards from outbound network paths
+ OpenAI News

OpenAI makes Lockdown Mode available across ChatGPT account types

OpenAI's June 4 ChatGPT release notes put Lockdown Mode across account types, trading live network features for stronger prompt-injection data-exfiltration protection.

OpenAI made Lockdown Mode available across ChatGPT account types and workspaces in its June 4, 2026 ChatGPT release notes. The setting is for users and organizations that would rather disable some network-connected features than accept the full data-exfiltration risk that can come with prompt injections.

The practical trade is clear. When Lockdown Mode is on, OpenAI says ChatGPT restricts live web browsing, deep research, agent mode, Canvas networking, file downloads, and parts of web-derived image support. For personal accounts and self-serve ChatGPT Business, it also blocks live connector access and connector write actions while allowing connectors that use synced data.

The security switch has a product cost

Lockdown Mode is not a background hardening change. It is a visible mode that changes what ChatGPT can do.

That matters because prompt injection is not only a model problem. It becomes more dangerous when a model can read private context, follow instructions hidden in outside content, and then send data out through a browser request, connector action, generated link, or file. OpenAI’s Help Center frames Lockdown Mode around the final stage of that chain: limiting outbound network requests that could transfer sensitive data to an attacker.

The cost is that some of ChatGPT’s most useful work surfaces become unavailable or narrower. Live web browsing is limited to cached content. Deep research and agent mode are disabled. Canvas-generated code cannot be approved for network access. ChatGPT cannot download files for data analysis, though it can still work on files a user uploads manually.

That is a reasonable bargain for some work and a bad bargain for other work. A user handling sensitive internal documents may prefer a locked-down chat that cannot browse live sites or write through connectors. A user doing open-web research will probably turn it off for that conversation.

Connectors become the admin problem

The most important part for teams is not the personal toggle. It is how Lockdown Mode interacts with apps, connectors, MCPs, and workspace roles.

For personal accounts and self-serve ChatGPT Business, OpenAI says Lockdown Mode allows synced-data connectors but blocks live connector access and connector write actions. In managed workspaces, OpenAI does not automatically disable every app. Workspace admins still control apps, MCPs, connectors, and actions through settings and role-based access controls.

That makes Lockdown Mode less like a universal kill switch and more like a stricter policy layer. Admins still have to decide which apps are trusted, which actions are allowed, and whether a write action could create a side effect that a malicious actor can see.

What it does not change

OpenAI lists several limits that teams should not miss. Lockdown Mode does not change memory, file uploads, conversation sharing, or whether conversations may be used to improve models. It also does not change Compliance API Logs Platform behavior.

The Codex caveat is equally important. OpenAI says Lockdown Mode does not affect network access in Codex. A company that uses ChatGPT Lockdown Mode for sensitive-document workflows should not assume the same setting governs software-development agents or repo-connected environments.

There is also a usability caveat. Lockdown Mode and Developer Mode cannot be used at the same time for eligible personal and self-serve ChatGPT Business accounts. Turning one on turns the other off.

Sources

The AI Feed Desk

The AI Feed Desk

Editorial desk

The AI Feed Desk tracks AI provider updates, model releases, agent tooling, and enterprise adoption, turning fast-moving announcements into source-linked context for builders and operators.

Noticed a typo, incorrect information, or translation error?

Tell us so we can fix it.

Help Improve This Article

Related Articles

A central work agent connects documents, app windows, a calendar, and a code workspace on one desktop

ChatGPT Work turns ChatGPT into a desktop and app agent

OpenAI launched ChatGPT Work as a GPT-5.6-powered agent that can work across apps, files, browser tasks, scheduled tasks, Codex, documents, sheets, slides, and Sites.

The AI Feed Desk

By The AI Feed Desk

Three learning workflow tiles connect classroom materials, course documents, and a code workspace

OpenAI adds education plugins to ChatGPT Work and Codex

OpenAI launched education plugins for ChatGPT Work and Codex aimed at K-12 teachers, college educators, and students.

The AI Feed Desk

By The AI Feed Desk

A red testing prism sends abstract signals through a safety screen toward a shielded model core

OpenAI publishes GPT-Red for automated prompt-injection red-teaming

OpenAI's GPT-Red is an internal automated red-teaming model used to find prompt-injection failures and train stronger defenses.

The AI Feed Desk

By The AI Feed Desk

A governed enterprise AI hub connects code, support, devices, and security workflows

HP scales OpenAI Frontier from pilots into enterprise operating workflows

HP is expanding its OpenAI Frontier partnership after pilots in code, security, partner support, device operations, and employee workflows.

The AI Feed Desk

By The AI Feed Desk

Researchers gather around a shared AI-assisted laboratory workspace for academic discovery

OpenAI gives 100,000 academic researchers free ChatGPT access

OpenAI launched ChatGPT for Academic Researchers, starting with 10,000 researchers this summer and expanding to 100,000 through 2027.

The AI Feed Desk

By The AI Feed Desk