Turn on ChatGPT’s Lockdown Mode and here is what stops working: live web browsing, deep research, agent mode, images inside responses, Canvas code that reaches the network, and file downloads for data analysis. That list is not a warning label someone bolted onto the feature. It is the feature, published by OpenAI in its own Lockdown Mode documentation, and reading the bill before the benefit is the only honest way to decide whether this setting belongs anywhere near your business.
Almost every write-up of Lockdown Mode leads with what it protects. That gets the decision backward, because the protection is easy to want and costs nothing to switch on. Those six subtractions are the real price, they are paid by one specific person doing one specific job, and the answer is different for your bookkeeper than for the person who spends all day researching suppliers.
The part that changed while nobody was looking
When OpenAI introduced Lockdown Mode on February 13, 2026, it was an enterprise control. The announcement listed it as available for ChatGPT Enterprise, ChatGPT Edu, ChatGPT for Healthcare and ChatGPT for Teachers. For a ten-person company that settled the matter early: you did not have the plan, so you did not have the decision.
That quietly stopped being true. An update dated June 4, 2026 on that same announcement page says Lockdown Mode is rolling out to personal ChatGPT accounts as well as self-serve ChatGPT Business accounts, and the current Help Center article lists eligibility as personal accounts on Free, Go, Plus and Pro, plus self-serve ChatGPT Business.
Read that against the price list. On OpenAI’s pricing page, Free is $0 per month, Go is $8, Plus is $20, and Pro starts at $100. ChatGPT Business runs $20 per seat per month billed annually or $25 billed monthly for a standard seat, and $100 annually or $125 monthly for a premium seat, for teams of 2 to 200 people. Enterprise is custom pricing through sales.
The useful conclusion is a subtraction, not an addition: there is no Lockdown Mode tier and no Lockdown Mode surcharge. If you are already paying for any of those plans, the incremental cost of this control is zero dollars. Whatever has been stopping small businesses from using it, budget was never it.
The six things you give up, read as six questions about your business
OpenAI’s documentation is unusually specific about what gets disabled, which makes this a decision you can actually run rather than guess at. Each item below is what the Help Center article says happens, followed by the question it puts to you.
Live web browsing is limited to cached content. OpenAI’s own wording is that search results “may be limited, unavailable, or stale.” The question: does this person’s work depend on what is true today, or on what they already have? A bookkeeper reconciling last month’s statements does not need the live web. Someone pricing a bid against current supplier rates does.
Deep research is disabled. Not limited, off. The question: is long-form multi-source research part of this role at all? For most seats in a small business, honestly, no.
Agent mode is disabled. The question: is anyone here letting ChatGPT take multi-step actions on their behalf? Agent features across the industry have moved fast enough that AI tools can now click through real applications that were never built to be automated, which is genuinely useful and is also the capability with the widest blast radius if a stray instruction gets in. If anyone here is using it, that is the account worth thinking hardest about.
Image support in responses is limited. ChatGPT may not display images in regular responses or pull images from the web. Uploading your own image files still works, and image generation still works where it is otherwise available. The question: is this a text job or a visual one?
Canvas networking is off. Users cannot approve Canvas-generated code to reach the network. The question: does anyone in a non-developer seat need generated code to make outbound calls? For most small businesses this costs nothing because nobody was doing it.
File downloads for data analysis are blocked. ChatGPT can still work on files you upload by hand, it just cannot fetch them itself. The question: does this person hand ChatGPT files, or expect ChatGPT to go get them?
Connectors sit slightly apart. For personal and self-serve Business accounts, the documentation says Lockdown Mode allows connectors that use synced data but blocks live connector access and connector write actions, and that Finances in ChatGPT and shopping-agent experiences are unavailable. In a managed workspace, apps and connectors stay governed by workspace settings and role-based access controls instead, so Lockdown Mode does not automatically switch every app off.
The switch that makes this survivable
Here is the detail that decides whether any of this holds up in a real week, and it is buried in the documentation rather than the announcement: you can turn Lockdown Mode off for a single chat.
When it is on, a status message appears above the composer. Select Manage in that message and then Turn off for this chat, or open the more options menu and set Lockdown to Disabled. It changes that conversation only.
That inverts the usual economics of a security setting. The normal failure pattern is familiar to anyone who has ever administered anything: the protective option blocks real work once, somebody switches it off in frustration, and it stays off for a year. A per-conversation exception means the safe state is the one you return to by default, and the unsafe state has to be chosen deliberately, one chat at a time, by someone who knows why they are choosing it. Protection that bends does not break.
One constraint worth knowing before you promise it to anyone: Lockdown Mode and Developer Mode cannot run at the same time. Turning on either one turns off the other.
Where this control does not reach
This is the section most coverage skips, and skipping it is how a reasonable setting turns into a false sense of safety.
Lockdown Mode does not affect network access in Codex. If the person you are actually worried about is a developer running a coding assistant with network permissions, this is the wrong control and you should be looking at the Elevated Risk label on that settings screen instead, which is the other half of what OpenAI shipped in February.
It also does not stop prompt injection from happening. OpenAI is direct about this: the mode is designed to limit the final stage, the outbound network request that carries data to an attacker, and a malicious instruction can still arrive inside cached web content or an uploaded file and skew what ChatGPT tells you. Wrong answers are still on the table. And it does not change memory, file uploads, conversation sharing, or whether your conversations may be used to improve models, which are separate settings you have to handle separately.
Then there is the line I did not expect to find in a vendor’s own FAQ. Asked whether prompt injection is a major risk, OpenAI answers: “Prompt injection is not currently a major risk, but its impact could grow as attackers develop more sophisticated methods.”
That is a company arguing against over-buying its own security feature, and it deserves to be repeated rather than buried. This is the part where I will state a view rather than a finding: treat Lockdown Mode as cheap, narrow insurance on two or three accounts, not as a company-wide policy. The risk is real enough to hedge and not yet common enough to reorganize around. We have covered how researchers hijacked ChatGPT Atlas with a single planted comment and an AI agent that broke into three companies using weak passwords, and the pattern in both is the same: the exotic-sounding attack lands through an ordinary door.
The alternative small businesses usually reach for is worse. Faced with a story like those, plenty of owners issue a blanket rule that nobody may use AI with client data, which slows down every person on the team to manage the exposure of two of them. A per-account switch lets you keep the capability broad and put the restriction exactly where the sensitive data actually sits. Nobody loses their tools, and nobody becomes the accidental vector.
What to actually do this week
- Name the accounts, not the department. Write down the two or three people who routinely put other people’s information into ChatGPT: client financials, patient or customer records, contracts, payroll. In most small businesses this is a shorter list than anyone expects, and it is rarely a whole team.
- Run each name against the six subtractions above. If someone loses nothing they use, the decision is finished. If someone loses live browsing they genuinely need, they are a candidate for Lockdown Mode with the per-chat exception rather than a reason to abandon it.
- Turn it on and check the app list. On a personal or self-serve Business account, go to Settings, select Security, and under Advanced security turn on Lockdown Mode, then confirm in the modal. In a managed workspace an admin creates a custom role, designates it a Lockdown Mode role, and assigns members or groups to it. Workspace admins should then enable only trusted apps and actions for those members; OpenAI’s guidance rates write actions for apps with broad or uncertain visibility as the highest exfiltration risk and read actions for trusted apps as lower.
If nothing appears under Advanced security, the rollout has not reached that account yet. The documentation says as much, and it is worth checking again rather than concluding the feature is not for you.
Frequently asked questions
Do I need to upgrade my plan to get Lockdown Mode?
No. The Help Center article lists it as rolling out to personal accounts on Free, Go, Plus and Pro, plus self-serve ChatGPT Business accounts. Since Free is $0 per month on OpenAI’s pricing page, there is no tier to buy and no surcharge to pay. If you do not see it in Settings under Security, it has not reached your account yet.
Will Lockdown Mode stop someone on my team from pasting client data into a chat?
No, and it is not designed to. It limits the outbound network requests that could carry data to an attacker after a prompt injection. A person copying sensitive information into a conversation is a separate problem that needs a written data-handling rule, not a setting.
Does it protect our developer running Codex?
No. OpenAI states plainly that Lockdown Mode does not affect network access in Codex. For that case, the relevant control is the Elevated Risk label OpenAI standardized across ChatGPT, ChatGPT Atlas and Codex, which flags the network-access setting and explains what changes when it is granted.
Can one person use it some of the time?
Yes, and this is the practical answer for most small teams. Lockdown Mode can be turned off for a single chat from the status message above the composer, and it stays on everywhere else. That lets one account run locked down by default and open up for the specific conversation that needs live browsing.
The two-minute version
Open Settings and select Security on the one account in your business that handles the most sensitive client information. If Lockdown Mode is sitting there under Advanced security, you are not making a budget decision or a security-strategy decision. You are deciding whether that person can do their job without live browsing, deep research, agent mode, response images, Canvas networking and automatic file downloads, knowing they can switch any single conversation back if the answer turns out to be no.
For a lot of small businesses that is a two-minute conversation about six features. It has been available since June and most owners still do not know the question is theirs to answer.
