OpenAI launched ChatGPT Lockdown Mode on June 6, 2026, a workspace-level control that lets administrators strip the assistant of its networked abilities. The feature is a direct answer to a question enterprise security teams have raised since agents arrived: how do you use ChatGPT without giving a model a path to the open web or third-party systems.
What Lockdown Mode Does
When enabled, the mode removes every capability that reaches outside the model’s context window.
- Disables web browsing and live retrieval
- Blocks agent mode and autonomous tool use
- Cuts off third-party connectors and external data sources
- Retains core chat, file upload, document analysis and code assistance
OpenAI described the setting as a switch that turns ChatGPT from a connected agent back into a self-contained assistant.
Who It Is For
The feature is aimed at regulated industries. Banks, hospital networks, defense contractors and government agencies have been slow to deploy agentic AI precisely because a single tool call can move sensitive data to an outside service. Lockdown Mode gives those buyers a configuration they can show auditors.
How Admins Turn It On
Administrators on ChatGPT Enterprise and Business plans can enable Lockdown Mode for an entire workspace or for named user groups, which lets a company give engineering open access while keeping finance and legal locked down. The setting is managed from the same admin console used for data retention and SSO controls.
The Security Rationale
The main threat is prompt injection, where malicious content tricks an agent into leaking data or taking unintended actions. By removing browsing, connectors and tool execution, Lockdown Mode eliminates the channels an attacker would use. It also prevents accidental exfiltration when an employee pastes material into a prompt that an agent might otherwise forward.
Limits and Trade-offs
The control is not a substitute for a security program. It does not change how the model handles data internally, and it does not stop a user from copying text out of a chat. It also narrows what ChatGPT can do: no live web results, no multi-step research and no integrations with ticketing or CRM systems.
What This Means
Lockdown Mode is a sign that enterprise AI adoption is being paced by security review, not model capability. OpenAI is now shipping knobs that let cautious buyers say yes, which may matter more for revenue in the near term than any benchmark gain.