OpenAI Ships ChatGPT Lockdown Mode to Block Prompt-Injection Data Exfiltration
Simon Willison / OpenAI Help·high signal
OpenAI's Lockdown Mode, first teased in February, is now live and rolling out to Free, Go, Plus, Pro, and self-serve Business accounts; it limits outbound network requests to cut the exfiltration leg of Simon Willison's 'lethal trifecta' using deterministic controls rather than AI-evaluated defenses. CISO Dane Stuckey framed it as a tool for elevated-risk users with functionality tradeoffs. The existence of an opt-in mode implies default ChatGPT settings do NOT robustly protect against determined exfiltration attacks — a key signal for builders deploying LLM agents with private data access.