OpenAI adds Lockdown Mode and risk labels to ChatGPT
OpenAI ships Lockdown Mode and Elevated Risk labels in ChatGPT to help organizations defend against prompt injection and AI-driven data exfiltration.

Updated
Why it matters
- OpenAI introduced Lockdown Mode and Elevated Risk labels in ChatGPT
- The features target prompt injection and AI-driven data exfiltration
- The controls are aimed at organizations defending AI deployments
OpenAI has introduced two new security features in ChatGPT — Lockdown Mode and Elevated Risk labels — designed to help organizations defend against prompt injection and AI-driven data exfiltration.
Prompt injection, in which hidden or crafted instructions trick a model into ignoring its intended guidelines, has become one of the most persistent attack vectors as companies connect large language models to internal tools, documents, and external websites. Data exfiltration attacks exploit that same mechanism: instead of merely manipulating model behavior, they push sensitive information — file contents, credentials, conversation history — out to attacker-controlled destinations.
Lockdown Mode gives administrators a stricter operating profile for ChatGPT deployments where the threat of manipulation is high. Elevated Risk labels, in turn, flag activity that suggests a higher likelihood of an attempted attack, giving security teams a signal to act on rather than forcing them to audit every interaction manually.
The release matters because enterprise adoption of AI assistants increasingly hinges on whether security teams can trust those systems with access to corporate data. Agentic workflows — models that browse, read documents, and call tools — widen the attack surface for injection and exfiltration, and buyers have been demanding finer-grained controls from vendors. OpenAI shipping these features signals that defensive tooling for LLMs is moving from research papers and startup products into the default feature set of a mainstream consumer and enterprise platform.
The announcement does not specify rollout timing or licensing details, so organizations will need to watch OpenAI's enterprise documentation for when the controls land in their admin consoles. Expect rivals such as Google and Microsoft to face similar pressure to match these defenses as prompt injection stays at the top of AI security threat models.
Source: OpenAI News
More from Marcus Bennett
Show full bio
Senior reporter covering consumer brands and retail at AI In Context.
108 articles
Related articles
- OpenAI Launches Safety Bug Bounty to Pay for AI Abuse Findings
- OpenAI ships prompt-based teen safety policies for gpt-oss-safeguard
- OpenAI Lays Out Its Defense Playbook Against Prompt Injection
- Security Researchers Used Anthropic's Claude to Hack Into OpenAI
- OpenAI Launches Advanced Account Security for High-Risk ChatGPT Users