Introducing Lockdown Mode and Elevated Risk labels in ChatGPT
📰 OpenAI News
OpenAI introduces Lockdown Mode and Elevated Risk labels in ChatGPT to mitigate prompt injection attacks
Action Steps
- Enable Lockdown Mode for high-risk users to constrain interactions with external systems
- Use Elevated Risk labels to inform users about potentially risky capabilities in ChatGPT
- Monitor and enforce security settings using enterprise controls like role-based access and audit logs
Who Needs to Know This
Security teams and developers at organizations using ChatGPT can benefit from these new features to protect against cyberattacks and data exfiltration
Key Insight
💡 Lockdown Mode and Elevated Risk labels provide an additional layer of security for ChatGPT users, especially those at high risk of cyberattacks
Share This
🚨 Introducing Lockdown Mode and Elevated Risk labels in ChatGPT to protect against prompt injection attacks! 🚨
Key Takeaways
OpenAI introduces Lockdown Mode and Elevated Risk labels in ChatGPT to mitigate prompt injection attacks
Full Article
# Introducing Lockdown Mode and Elevated Risk labels in ChatGPT | OpenAI
[Skip to main content](https://openai.com/index/introducing-lockdown-mode-and-elevated-risk-labels-in-chatgpt#main)
[](https://openai.com/)
* [Research](https://openai.com/research/index/)
* Products
* [Business](https://openai.com/business/)
* [Developers](https://openai.com/api/)
* [Company](https://openai.com/about/)
* [Foundation(opens in a new window)](https://openaifoundation.org/)
[Try ChatGPT(opens in a new window)](https://chatgpt.com/)
* Research
* Products
* Business
* Developers
* Company
* [Foundation(opens in a new window)](https://openaifoundation.org/)
[Try ChatGPT(opens in a new window)](https://chatgpt.com/)
OpenAI
Table of contents
* [Helping organizations protect employees most at-risk of cyberattacks](https://openai.com/index/introducing-lockdown-mode-and-elevated-risk-labels-in-chatgpt#helping-organizations-protect-employees-most-at-risk-of-cyberattacks)
* [Helping users make informed choices about risk](https://openai.com/index/introducing-lockdown-mode-and-elevated-risk-labels-in-chatgpt#helping-users-make-informed-choices-about-risk)
* [What’s next](https://openai.com/index/introducing-lockdown-mode-and-elevated-risk-labels-in-chatgpt#whats-next)
February 13, 2026
[Safety](https://openai.com/news/safety-alignment/)[Product](https://openai.com/news/product-releases/)
# Introducing Lockdown Mode and Elevated Risk labels in ChatGPT
Loading…
Share
As AI systems take on more complex tasks—especially those that involve the web and connected apps—the security stakes change.
One emerging risk has become especially important: [prompt injection](https://openai.com/index/prompt-injections/). In these attacks, a third party attempts to mislead a conversational AI system into following malicious instructions or revealing sensitive information.
Today, we’re introducing two new protections designed to help users and organizations mitigate prompt injection attacks, with clearer visibility into risk and stronger controls:
* **Lockdown Mode** in ChatGPT, an advanced, optional security setting for higher-risk users
* **“Elevated Risk” labels**for certain capabilities in ChatGPT, ChatGPT Atlas, and Codex that may introduce additional risk
These additions build on our existing protections across the model, product, and system levels. This includes sandboxing, [protections against URL-based data exfiltration](https://openai.com/index/ai-agent-link-safety/), monitoring and enforcement, and [enterprise controls](https://openai.com/business-data/) like role-based access and audit logs.
## Helping organizations protect employees most at-risk of cyberattacks
Lockdown Mode is an optional, advanced security setting designed for a small set of highly security-conscious users—such as executives or security teams at prominent organizations—who require increased protection against advanced threats. It is not necessary for most users. Lockdown Mode tightly constrains how ChatGPT can interact with external systems to reduce the risk of prompt injection–based data exfiltration.
Lockdown Mode deterministically disables certain tools and capabilities in ChatGPT that an adversary could attempt to exploit to exfiltrate sensitive data from users’ conversations or connected apps via attacks such as prompt injections.
For example, web browsing in Lockdown Mode is limited to cached content, so no live network requests leave OpenAI’s controlled network. This restriction is designed to prevent sensitive data from being exfiltrated to an attacker through browsing. Some features are disabled entirely when we can’t provide strong deterministic guarantees of data safety.

[](https://openai.com/)
* [Research](https://openai.com/research/index/)
* Products
* [Business](https://openai.com/business/)
* [Developers](https://openai.com/api/)
* [Company](https://openai.com/about/)
* [Foundation(opens in a new window)](https://openaifoundation.org/)
[Try ChatGPT(opens in a new window)](https://chatgpt.com/)
* Research
* Products
* Business
* Developers
* Company
* [Foundation(opens in a new window)](https://openaifoundation.org/)
[Try ChatGPT(opens in a new window)](https://chatgpt.com/)
OpenAI
Table of contents
* [Helping organizations protect employees most at-risk of cyberattacks](https://openai.com/index/introducing-lockdown-mode-and-elevated-risk-labels-in-chatgpt#helping-organizations-protect-employees-most-at-risk-of-cyberattacks)
* [Helping users make informed choices about risk](https://openai.com/index/introducing-lockdown-mode-and-elevated-risk-labels-in-chatgpt#helping-users-make-informed-choices-about-risk)
* [What’s next](https://openai.com/index/introducing-lockdown-mode-and-elevated-risk-labels-in-chatgpt#whats-next)
February 13, 2026
[Safety](https://openai.com/news/safety-alignment/)[Product](https://openai.com/news/product-releases/)
# Introducing Lockdown Mode and Elevated Risk labels in ChatGPT
Loading…
Share
As AI systems take on more complex tasks—especially those that involve the web and connected apps—the security stakes change.
One emerging risk has become especially important: [prompt injection](https://openai.com/index/prompt-injections/). In these attacks, a third party attempts to mislead a conversational AI system into following malicious instructions or revealing sensitive information.
Today, we’re introducing two new protections designed to help users and organizations mitigate prompt injection attacks, with clearer visibility into risk and stronger controls:
* **Lockdown Mode** in ChatGPT, an advanced, optional security setting for higher-risk users
* **“Elevated Risk” labels**for certain capabilities in ChatGPT, ChatGPT Atlas, and Codex that may introduce additional risk
These additions build on our existing protections across the model, product, and system levels. This includes sandboxing, [protections against URL-based data exfiltration](https://openai.com/index/ai-agent-link-safety/), monitoring and enforcement, and [enterprise controls](https://openai.com/business-data/) like role-based access and audit logs.
## Helping organizations protect employees most at-risk of cyberattacks
Lockdown Mode is an optional, advanced security setting designed for a small set of highly security-conscious users—such as executives or security teams at prominent organizations—who require increased protection against advanced threats. It is not necessary for most users. Lockdown Mode tightly constrains how ChatGPT can interact with external systems to reduce the risk of prompt injection–based data exfiltration.
Lockdown Mode deterministically disables certain tools and capabilities in ChatGPT that an adversary could attempt to exploit to exfiltrate sensitive data from users’ conversations or connected apps via attacks such as prompt injections.
For example, web browsing in Lockdown Mode is limited to cached content, so no live network requests leave OpenAI’s controlled network. This restriction is designed to prevent sensitive data from being exfiltrated to an attacker through browsing. Some features are disabled entirely when we can’t provide strong deterministic guarantees of data safety.
![Image 1: Diagram titled “Lockdown mode” showing ChatGPT inside a secured boundary with connections to a Private Web Cache, Download Files, Access Web via Canvas, and Browse Public Web. An external “Attacker” and the Public Web are depicted outside the
DeepCamp AI