# OpenAI Expands ChatGPT Security Controls: Lockdown Mode and Session Management Now Broadly Available


OpenAI is significantly expanding its account security offerings for ChatGPT users, rolling out three layered security features designed to protect accounts from increasingly sophisticated attacks targeting AI users and organizations. The deployment marks a notable shift in how the AI industry is addressing emerging threats specific to large language models, including prompt injection attacks and unauthorized account access.


The rollout includes Lockdown Mode to prevent data exfiltration from prompt injection attacks, Active Sessions to track and manage login locations, and enhanced Advanced Account Security with passwordless authentication. These features arrive amid growing concern about AI systems being weaponized for credential theft, data extraction, and account takeover attacks.


## The Threat


ChatGPT users and organizations increasingly face sophisticated attack vectors that exploit the capabilities of AI systems themselves. Prompt injection attacks—where malicious actors craft inputs designed to override a model's intended behavior—represent one of the most pressing emerging threats in the AI security landscape.


Key attack vectors:

  • Prompt injection attacks: Malicious instructions embedded in user inputs or files that trick ChatGPT into extracting sensitive data or performing unintended actions
  • Data exfiltration through prompts: Attackers using prompt injection to coerce the model into sending sensitive information to external systems or revealing it in responses
  • Account takeover: Compromised credentials leading to unauthorized access to accounts with access to sensitive conversations and uploaded files
  • Session hijacking: Exploiting active sessions across multiple devices to maintain persistent access

  • Organizations handling sensitive information—including healthcare providers, law firms, financial firms, and government agencies—face particularly acute risks. ChatGPT conversations can inadvertently contain proprietary information, personal data, or other sensitive content that becomes vulnerable if accounts are compromised.


    ## Background and Context


    OpenAI has faced persistent pressure to strengthen its security posture as ChatGPT adoption has exploded across enterprise environments. The AI company disclosed multiple security incidents over the past 18 months, including a temporary outage affecting user data visibility and various credential-related vulnerabilities affecting API users.


    The specific focus on prompt injection protection reflects a maturing threat landscape. Unlike traditional cybersecurity threats, prompt injection attacks exploit the very capabilities that make large language models valuable—their ability to understand complex instructions and adapt their behavior based on input. This creates a fundamental tension: the more capable the model, the more creative attackers can be in subverting its intended use.


    Recent context:

  • Rising reports of prompt injection attacks in production environments
  • Multiple instances of AI tools being tricked into revealing training data or system prompts
  • Supply chain attacks leveraging AI tools to steal credentials from developers
  • Organizations discovering sensitive data inadvertently exposed through ChatGPT conversations

  • OpenAI's incremental approach to security mirrors moves by other major AI providers who are similarly grappling with how to secure models that operate fundamentally differently than traditional software.


    ## Technical Details: How Each Feature Works


    ### Lockdown Mode


    Lockdown Mode represents the most technically sophisticated of OpenAI's new offerings. When enabled, it reduces the attack surface by disabling ChatGPT's outbound capabilities that could theoretically be exploited for data exfiltration.


    What Lockdown Mode disables:

  • Live web browsing
  • Image support and upload capabilities
  • Deep research functions
  • Agent mode (autonomous task execution)
  • Canvas networking
  • File downloads

  • OpenAI emphasizes an important limitation: Lockdown Mode does not prevent prompt injections from occurring or appearing in content ChatGPT processes. Instead, it prevents the final stage of data exfiltration by eliminating network channels through which an attacker could extract information.


    The feature is designed for organizations that handle highly sensitive information where preventing any possibility of data exfiltration through outbound channels justifies the loss of ChatGPT's advanced capabilities. Users enable it through Settings > Security > Advanced Security.


    ### Active Sessions


    Active Sessions provides straightforward account security visibility. Users can review all locations and devices where their ChatGPT account is currently authenticated, similar to Google's or Microsoft's account security dashboards.


    Capabilities:

  • View all active session locations (by IP address/geographic location)
  • Review device information and browser details
  • Immediately log out of unrecognized sessions
  • Monitor for unauthorized access

  • This feature is available to all ChatGPT account types except those linked to organization SSO setups. It's accessible via Settings > Security.


    ### Advanced Account Security


    Building on previous releases, Advanced Account Security removes password-based authentication entirely, replacing it with:


    Authentication methods:

  • Physical security keys (hardware devices like YubiKeys)
  • Passkeys (cryptographic authentication tied to devices)
  • Backup passkeys and recovery keys for account recovery

  • The feature also shortens session duration to minimize the window of opportunity if a device is compromised, reducing the risk from stolen session tokens.


    ## Implications for Users and Organizations


    These security controls introduce meaningful but complex tradeoffs that different user categories will evaluate differently.


    For individual users:

  • Advanced Account Security provides robust protection but requires purchasing security keys (~$40-60 per device)
  • Active Sessions offers valuable visibility with no functionality tradeoff
  • Lockdown Mode may be impractical for most individual users who rely on ChatGPT's research and browsing capabilities

  • For organizations:

  • Lockdown Mode addresses real risks but comes at significant capability cost
  • Organizations handling regulated data (healthcare, financial, legal) should evaluate whether the tradeoff is justified
  • The SSO exception for Active Sessions suggests enterprise authentication integration is forthcoming
  • These features don't address systemic risks of AI-generated content being untrained on sensitive organizational data

  • Regulatory considerations:

  • Organizations subject to data protection regulations (GDPR, HIPAA, SOC 2) should evaluate whether using external AI services aligns with their compliance obligations, regardless of security features
  • Healthcare organizations and law firms may need to reassess whether ChatGPT is appropriate for handling any sensitive data, even with Lockdown Mode enabled

  • ## Recommendations


    For all users:

    1. Enable Active Sessions monitoring immediately — this provides visibility with zero tradeoff. Check your sessions regularly and remove any unrecognized devices.

    2. Evaluate Advanced Account Security if your account contains sensitive information or you work in a security-sensitive role. Invest in security keys.


    For organizations:

    1. Implement usage policies before deploying ChatGPT widely — establish guidelines on what data can or cannot be shared with ChatGPT, independent of technical security features.

    2. Evaluate Lockdown Mode for high-risk workflows — if your organization needs to use ChatGPT with sensitive data, Lockdown Mode should be mandatory for those use cases, even if functionality is limited.

    3. Prefer passkeys and security keys over password-based access — use Advanced Account Security as your default authentication method for organizational accounts.

    4. Assume data you send to ChatGPT can be indexed — OpenAI's data retention policies permit training data use unless users opt out. Treat ChatGPT as an external service, not a private tool.

    5. Monitor for prompt injection risks — train your team to recognize and avoid patterns that could inadvertently trigger model behaviors that expose sensitive information.


    ## HackWire Analysis


    OpenAI's security rollout is pragmatic but reveals the fundamental tensions facing the AI industry as these systems become critical business infrastructure.


    The timing is significant. Prompt injection attacks were largely theoretical security exercises two years ago; they're now production incidents. Organizations like 1Password, GitHub, and others have publicly disclosed instances where AI agents were tricked into exfiltrating credentials. This isn't hypothetical anymore—attackers are actively exploiting these vectors.


    What's telling is what these features *don't* address: they're reactive measures against specific attack techniques, not architectural solutions to the underlying problem. Lockdown Mode is essentially a security feature that says "disable the capability if you don't trust the model's judgment." That's a valid short-term control, but it's a band-aid on a larger issue—namely, that LLMs can be reliably manipulated to override their intended behavior if an attacker is creative enough with prompts.


    The more important observation: these are all opt-in features for users who think deeply about security. Average users won't enable Lockdown Mode. Organizations will struggle to justify the cost of security keys for thousands of employees. The gap between "available security controls" and "actually deployed security controls" is where breaches happen.


    There's also a business model tension here. OpenAI's revenue depends on making ChatGPT as useful as possible—agents, file handling, web browsing, image generation. Every capability Lockdown Mode disables is functionality that customers signed up to use. The fact that users have to choose between security and functionality suggests OpenAI hasn't solved the underlying problem; they've just given users a way to turn off the risky features.


    The real test will be whether organizations actually deploy these controls. Advanced Account Security makes sense for high-value accounts, but widespread enterprise adoption requires security key distribution infrastructure. Active Sessions is valuable but insufficient—it catches account compromises after the fact. Lockdown Mode is the most important control, but it's only useful if organizations commit to using ChatGPT differently when handling sensitive data.


    OpenAI deserves credit for adding these controls in response to emerging threats. But the security community should recognize these as necessary but not sufficient. Organizations using AI systems with sensitive data need comprehensive policies, not just feature toggles.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)