OpenAI has added Lockdown Mode to ChatGPT to reduce the risk of sensitive data leaking during prompt injection attacks.
Prompt injection is a class of attack where malicious instructions embedded in external content steer an AI model away from its intended task. Lockdown Mode is designed to narrow the damage window: even when an injection succeeds, the goal is to limit how much sensitive data gets extracted. OpenAI has been explicit that the feature does not make ChatGPT immune to prompt injection; it reduces the likelihood of data exposure, not the likelihood of the attack itself.
That framing matters. As organizations feed sensitive internal data into AI assistants for document analysis, code review, and customer-facing tasks, prompt injection shifts from a theoretical concern to a practical liability. A mitigation that honestly describes its own limits is more credible than one that claims to solve a problem the field has not solved.
"Lockdown Mode" is a confident name for what OpenAI itself describes as a probability reducer. The attacks still land; the blast radius just shrinks.
