# OpenAI Expands ChatGPT Security Controls: Lockdown Mode and Session Management Now Broadly Available
OpenAI is significantly expanding its account security offerings for ChatGPT users, rolling out three layered security features designed to protect accounts from increasingly sophisticated attacks targeting AI users and organizations. The deployment marks a notable shift in how the AI industry is addressing emerging threats specific to large language models, including prompt injection attacks and unauthorized account access.
The rollout includes Lockdown Mode to prevent data exfiltration from prompt injection attacks, Active Sessions to track and manage login locations, and enhanced Advanced Account Security with passwordless authentication. These features arrive amid growing concern about AI systems being weaponized for credential theft, data extraction, and account takeover attacks.
## The Threat
ChatGPT users and organizations increasingly face sophisticated attack vectors that exploit the capabilities of AI systems themselves. Prompt injection attacks—where malicious actors craft inputs designed to override a model's intended behavior—represent one of the most pressing emerging threats in the AI security landscape.
Key attack vectors:
Organizations handling sensitive information—including healthcare providers, law firms, financial firms, and government agencies—face particularly acute risks. ChatGPT conversations can inadvertently contain proprietary information, personal data, or other sensitive content that becomes vulnerable if accounts are compromised.
## Background and Context
OpenAI has faced persistent pressure to strengthen its security posture as ChatGPT adoption has exploded across enterprise environments. The AI company disclosed multiple security incidents over the past 18 months, including a temporary outage affecting user data visibility and various credential-related vulnerabilities affecting API users.
The specific focus on prompt injection protection reflects a maturing threat landscape. Unlike traditional cybersecurity threats, prompt injection attacks exploit the very capabilities that make large language models valuable—their ability to understand complex instructions and adapt their behavior based on input. This creates a fundamental tension: the more capable the model, the more creative attackers can be in subverting its intended use.
Recent context:
OpenAI's incremental approach to security mirrors moves by other major AI providers who are similarly grappling with how to secure models that operate fundamentally differently than traditional software.
## Technical Details: How Each Feature Works
### Lockdown Mode
Lockdown Mode represents the most technically sophisticated of OpenAI's new offerings. When enabled, it reduces the attack surface by disabling ChatGPT's outbound capabilities that could theoretically be exploited for data exfiltration.
What Lockdown Mode disables:
OpenAI emphasizes an important limitation: Lockdown Mode does not prevent prompt injections from occurring or appearing in content ChatGPT processes. Instead, it prevents the final stage of data exfiltration by eliminating network channels through which an attacker could extract information.
The feature is designed for organizations that handle highly sensitive information where preventing any possibility of data exfiltration through outbound channels justifies the loss of ChatGPT's advanced capabilities. Users enable it through Settings > Security > Advanced Security.
### Active Sessions
Active Sessions provides straightforward account security visibility. Users can review all locations and devices where their ChatGPT account is currently authenticated, similar to Google's or Microsoft's account security dashboards.
Capabilities:
This feature is available to all ChatGPT account types except those linked to organization SSO setups. It's accessible via Settings > Security.
### Advanced Account Security
Building on previous releases, Advanced Account Security removes password-based authentication entirely, replacing it with:
Authentication methods:
The feature also shortens session duration to minimize the window of opportunity if a device is compromised, reducing the risk from stolen session tokens.
## Implications for Users and Organizations
These security controls introduce meaningful but complex tradeoffs that different user categories will evaluate differently.
For individual users:
For organizations:
Regulatory considerations:
## Recommendations
For all users:
1. Enable Active Sessions monitoring immediately — this provides visibility with zero tradeoff. Check your sessions regularly and remove any unrecognized devices.
2. Evaluate Advanced Account Security if your account contains sensitive information or you work in a security-sensitive role. Invest in security keys.
For organizations:
1. Implement usage policies before deploying ChatGPT widely — establish guidelines on what data can or cannot be shared with ChatGPT, independent of technical security features.
2. Evaluate Lockdown Mode for high-risk workflows — if your organization needs to use ChatGPT with sensitive data, Lockdown Mode should be mandatory for those use cases, even if functionality is limited.
3. Prefer passkeys and security keys over password-based access — use Advanced Account Security as your default authentication method for organizational accounts.
4. Assume data you send to ChatGPT can be indexed — OpenAI's data retention policies permit training data use unless users opt out. Treat ChatGPT as an external service, not a private tool.
5. Monitor for prompt injection risks — train your team to recognize and avoid patterns that could inadvertently trigger model behaviors that expose sensitive information.
## HackWire Analysis
OpenAI's security rollout is pragmatic but reveals the fundamental tensions facing the AI industry as these systems become critical business infrastructure.
The timing is significant. Prompt injection attacks were largely theoretical security exercises two years ago; they're now production incidents. Organizations like 1Password, GitHub, and others have publicly disclosed instances where AI agents were tricked into exfiltrating credentials. This isn't hypothetical anymore—attackers are actively exploiting these vectors.
What's telling is what these features *don't* address: they're reactive measures against specific attack techniques, not architectural solutions to the underlying problem. Lockdown Mode is essentially a security feature that says "disable the capability if you don't trust the model's judgment." That's a valid short-term control, but it's a band-aid on a larger issue—namely, that LLMs can be reliably manipulated to override their intended behavior if an attacker is creative enough with prompts.
The more important observation: these are all opt-in features for users who think deeply about security. Average users won't enable Lockdown Mode. Organizations will struggle to justify the cost of security keys for thousands of employees. The gap between "available security controls" and "actually deployed security controls" is where breaches happen.
There's also a business model tension here. OpenAI's revenue depends on making ChatGPT as useful as possible—agents, file handling, web browsing, image generation. Every capability Lockdown Mode disables is functionality that customers signed up to use. The fact that users have to choose between security and functionality suggests OpenAI hasn't solved the underlying problem; they've just given users a way to turn off the risky features.
The real test will be whether organizations actually deploy these controls. Advanced Account Security makes sense for high-value accounts, but widespread enterprise adoption requires security key distribution infrastructure. Active Sessions is valuable but insufficient—it catches account compromises after the fact. Lockdown Mode is the most important control, but it's only useful if organizations commit to using ChatGPT differently when handling sensitive data.
OpenAI deserves credit for adding these controls in response to emerging threats. But the security community should recognize these as necessary but not sufficient. Organizations using AI systems with sensitive data need comprehensive policies, not just feature toggles.
— HackWire Editorial
## Related Coverage