News
AI SHIFT:

ChatGPT Lockdown Mode Narrows AI Data Exfiltration Paths

Newsroom brief

OpenAI is rolling out Lockdown Mode for eligible ChatGPT users to reduce data exfiltration risk from prompt injection. The optional setting limits outbound web and tool capabilities, trading some product flexibility for stronger containment around sensitive workflows.

Verified against source materialEdited by SendTech Times Cybersecurity Desk
ChatGPT Lockdown Mode Narrows AI Data Exfiltration Paths
Image source: The Hacker News

ChatGPT adds a narrower security posture

OpenAI has begun rolling out Lockdown Mode for eligible personal and self-serve ChatGPT Business accounts, giving users an optional setting that reduces the ways ChatGPT can connect to the web or outside services.

The feature is meant for users and organizations handling sensitive information, where data leakage risk can matter more than convenience.

The setting is available to logged-in users across Free, Go, Plus and Pro accounts, as well as self-serve ChatGPT Business plans.

Its central purpose is not to prevent prompt injection attempts from appearing, but to reduce the outbound paths that could let sensitive data leave a session.

Tool limits target exfiltration paths

Lockdown Mode builds on sandboxing and existing controls by limiting outbound network requests.

In practice, it restricts live web browsing to cached content, removes image support in regular responses and web retrieval, blocks network access for Canvas-generated code, and prevents file downloads for data analysis.

Those constraints are significant because prompt injection risk often depends on a model being persuaded to send information to an attacker-controlled destination.

By removing or narrowing tools that reach external systems, OpenAI is trading some product utility for a smaller data-exfiltration surface.

Security becomes a product configuration choice

The feature underlines how AI security is moving from back-end filtering alone toward user-visible operating modes.

OpenAI says the setting is not intended for everyone, which makes the trade-off explicit: stronger containment can make ChatGPT less flexible for web, image, code and file workflows.

That matters for enterprises because many employees use AI tools near confidential documents, internal context or customer data.

A lockdown-style control gives security teams a clearer option when the priority is containment rather than maximum feature access.

What to watch next

The next signal is whether similar modes become standard across AI assistants, especially those connected to browsers, coding tools, productivity suites and enterprise data stores.

The practical question is whether users can understand when to enable stricter controls before sensitive workflows begin.

For OpenAI, the feature also shows that prompt injection remains a hard unresolved class of risk for large language models.

Lockdown Mode does not remove the attack category, but it narrows the consequences by reducing outbound channels that an attacker could try to exploit.

Share this article
inXf

Related articles

More
UAE Cyber Summit Puts AI Risk Inside A National Resilience Plan
Cybersecurity

UAE Cyber Summit Puts AI Risk Inside A National Resilience Plan

The UAE’s 3rd Government Cybersecurity Summit in Abu Dhabi framed cyber defence as a national resilience issue, linking AI-enabled threats, telecom exposure, data compression and regional cooperation.

Unit 42 Finds 13,229 Malicious URLs In AI Phantom-Domain Study
Cybersecurity

Unit 42 Finds 13,229 Malicious URLs In AI Phantom-Domain Study

Palo Alto Networks’ Unit 42 said its phantom-squatting research generated 685,339 prompts across 913 brands and produced 2.1 million unique URLs, including 13,229 malicious URLs and about 250,000 unique phantom domains. The public report did not disclose the brand list, affected customer names or named domains tied to data loss.

WhatsApp Usernames Hide Phone Numbers But Scam Risk Remains
Cybersecurity

WhatsApp Usernames Hide Phone Numbers But Scam Risk Remains

WhatsApp is rolling out usernames and optional keys to reduce phone-number exposure, but security researchers warn that impersonation and social-engineering scams can move to handles, profile images and trusted-looking accounts.

AI Coding Agents Face Sandbox-Escape Findings Across Four Tools
Cybersecurity

AI Coding Agents Face Sandbox-Escape Findings Across Four Tools

BleepingComputer reported that Pillar Security reproduced sandbox-escape paths in Cursor, OpenAI Codex, Gemini CLI and Google Antigravity, shifting attention from agent containment to trusted developer tools around the workspace.

Sysdig Says AI Ransomware Still Needed Human Setup
Cybersecurity

Sysdig Says AI Ransomware Still Needed Human Setup

Sysdig described JadePuffer as agentic ransomware, but Michael Clark said a human still chose the victim, provisioned infrastructure and supplied database credentials before the AI agent executed the attack.

Smart TV Proxy SDKs Turn Free Apps Into a Hidden AI Scraping Supply Chain
Cybersecurity

Smart TV Proxy SDKs Turn Free Apps Into a Hidden AI Scraping Supply Chain

Bright Data's SDK has been reverse-engineered in research showing how free apps can turn consumer devices, including smart TVs, into residential proxy nodes for web-scraping traffic. The issue matters because AI data harvesting is increasing demand for residential IPs, while consent screens and background network behavior may not be clear to users or IT teams.

Keep Reading

More Stories

Latest
Treasury Warning Sends Moonshot Distillation Claim Toward AI SanctionsCapital & PolicyJul 23, 2026Treasury Warning Sends Moonshot Distillation Claim Toward AI SanctionsA U.S. Treasury warning over alleged AI model distillation brings Moonshot’s Kimi K3 release into a policy test for Chinese open-weight models, Nvidia GB300 access and export-control enforcement.Google Keeps TPU Priority On AGI As Cloud Demand Strains CapacityAIJul 23, 2026Google Keeps TPU Priority On AGI As Cloud Demand Strains CapacityAlphabet told investors that its first compute-allocation priority is frontier AGI development, while Google Cloud demand and AI infrastructure spending are pushing the company to use third-party capacity as a bridge.White House Presses PJM Grid Reform As AI Power Demand RisesCloud & Data CentersJul 23, 2026White House Presses PJM Grid Reform As AI Power Demand RisesThe White House warned PJM Interconnection to reform its board governance and stakeholder process as AI data centres and other large loads intensify disputes over grid reliability, electricity prices and infrastructure cost allocation.OpenAI Presence Makes Enterprise AI Agents A Consulting SaleAIJul 22, 2026OpenAI Presence Makes Enterprise AI Agents A Consulting SaleOpenAI’s Presence service is available to eligible enterprise customers through deployed engineers, not as a self-service product, with pricing still scoped individually.Kratos Takedown Leaves Microsoft 365 Session-Theft Risk UnfinishedCybersecurityJul 22, 2026Kratos Takedown Leaves Microsoft 365 Session-Theft Risk UnfinishedGerman and US law enforcement took more than 200 Kratos phishing-kit servers offline, but investigators still tie the service to roughly 1,800 customers and session-theft attacks against Microsoft 365.Augustus Raises $180m For Dollar Rails Across Emerging-Market FintechsFintech & Digital PaymentsJul 22, 2026Augustus Raises $180m For Dollar Rails Across Emerging-Market FintechsAugustus announced a $180 million Series B at a $1 billion valuation, with funding aimed at dollar accounts, payment rails and stablecoin-enabled banking for fintechs and banks across Latin America, Southeast Asia, the Middle East and Africa.China IPv6 Plan Advances Single-Stack Network And Metadata ControlsTelco & ConnectivityJul 22, 2026China IPv6 Plan Advances Single-Stack Network And Metadata ControlsChina is setting 2027 and 2030 IPv6 targets while pushing IPv6+ work that could give carriers more metadata about traffic, raising policy questions for network and cloud buyers outside China.Prysmian Signs $6.29bn Molex Cable Deal For AI Data CentresCloud & Data CentersJul 22, 2026Prysmian Signs $6.29bn Molex Cable Deal For AI Data CentresData Center Dynamics reported that Prysmian’s €5.5 billion Molex agreement includes a €550 million upfront payment and a capacity plan to more than double US fibre output.Spain AI Campus Seeks 300 MW With On-Site Power PlanCloud & Data CentersJul 22, 2026Spain AI Campus Seeks 300 MW With On-Site Power PlanData Center Knowledge reported that EdgeMode, BlackBerry AIF and Mora are seeking regional support for DC MALPICA, a proposed €3 billion ($3.4 billion), 300 MW AI campus whose power model remains partly undisclosed.e& UAE And Core42 Launch Sovereign AI Compute PlatformCloud & Data CentersJul 21, 2026e& UAE And Core42 Launch Sovereign AI Compute PlatformMiddle East AI News reported that e& UAE and Core42 launched Sovereign AI Compute, giving UAE enterprises and government bodies in-country GPU access with data residency, connectivity and vendor-claimed zero egress fees.Microsoft Adds AMD Helios AI Racks To Azure Without Order SizeChips & SemiconductorsJul 21, 2026Microsoft Adds AMD Helios AI Racks To Azure Without Order SizeMicrosoft will deploy AMD Helios rack-scale AI accelerators for Azure AI workloads, with watts, dollars and rack counts still absent from the public terms of the commitment.AliExpress Hit With Record €550m EU Fine Over Illegal GoodsCapital & PolicyJul 21, 2026AliExpress Hit With Record €550m EU Fine Over Illegal GoodsBBC reported that the European Commission imposed a record €550m Digital Services Act penalty on AliExpress and ordered the Alibaba-owned marketplace to file a corrective action plan by 20 October.