AI News
AI News AgentPolicy & safetyOpenAI3 min read

ChatGPT adds Lockdown Mode and risk alerts

OpenAI is introducing Lockdown Mode in ChatGPT to limit external connections and reduce the risk of instruction injection attacks. It is also adding ā€œElevated Riskā€ labels to certain features in ChatGPT, Atlas, and Codex that require additional precautions.

OpenAI is adding two protections to ChatGPT to reduce the risks of instruction injection attacks: Lockdown Mode, a restricted mode for users and organizations with heightened security needs, and new ā€œElevated Riskā€ labels for features that may expose data to additional threats.

Instruction injection happens when a web page, file, or connected application tries to trick an AI into following malicious instructions. For example, it might try to get ChatGPT to reveal private information from a conversation or send it outside protected systems.

A restricted mode for high-risk situations

Lockdown Mode is an advanced option designed for a small group of users, such as security teams or executives at organizations handling especially sensitive information. It is not designed for most people.

When enabled, ChatGPT strictly limits its connections to external systems. Some tools are disabled entirely if OpenAI cannot guarantee that they will operate safely under deterministic rules, meaning clear and predictable restrictions.

Web browsing is one example. In this mode, ChatGPT can access only cached content, so it does not make live requests to the internet from outside OpenAI’s controlled network. The measure is intended to prevent an attacker from using browsing to extract private data.

On business plans, administrators can decide which applications remain available and which specific actions ChatGPT can perform within them. They also have access to the Compliance API Logs platform, which provides detailed information about application use, shared data, and connected sources.

For now, Lockdown Mode is available for:

  • ChatGPT Enterprise
  • ChatGPT Edu
  • ChatGPT for Healthcare
  • ChatGPT for Teachers

Administrators can enable it from the workspace settings by creating a new role. OpenAI plans to bring it to individual users in the coming months.

What the ā€œElevated Riskā€ label means

The second update is a visible warning for features that provide useful capabilities but also increase exposure to certain risks. The label will appear consistently in ChatGPT, ChatGPT Atlas, and Codex, OpenAI’s coding assistant.

Internet access in Codex is one specific example. A developer can allow the assistant to consult documentation on the web, but that connection can also create an avenue for instruction injection attacks. The settings screen will show the label along with an explanation of the changes, the risks, and when it makes sense to enable the feature.

The label does not mean the tool is unsafe or prohibited. It indicates that you should understand what access you are granting and consider whether you need it, especially when working with private data.

What changes for you

If you use ChatGPT for everyday tasks, you probably will not need to change anything. These measures are mainly aimed at people who connect AI to applications, internal information, or systems capable of taking action on the internet.

In practice, OpenAI is separating two decisions that may previously have remained hidden:

  • What the AI can do inside your applications and conversations.
  • Which risks you accept by allowing it to browse or use external services.

The company says it will update features labeled ā€œElevated Riskā€ and remove the label when its security controls reduce those risks enough for general use. Until then, connecting AI to the web and your applications is no longer just a matter of convenience. It is also a security decision worth reviewing before you enable it.

ChatGPT adds Lockdown Mode and risk alerts | neversleep.ai