OpenAI's Lockdown Mode Admits the Problem It Can't Quite Fix
The new containment feature reduces AI-enabled data exfiltration — it doesn't stop it. Experts are divided on whether enterprises should even trust a vendor to police itself.

OpenAI quietly built a panic room. Lockdown Mode, now available in enterprise product settings, restricts web browsing to cached content, disables Deep Research and Agent Mode, blocks Canvas-generated code from reaching the network, and prevents ChatGPT from pulling down files for analysis. Manually uploaded files still flow through. The company announced the feature in a blog post without responding to follow-up questions.
The feature's own FAQ is revealing. OpenAI asked itself whether prompt injection is a major risk, then answered: not currently, though impact could grow as attackers develop more sophisticated methods. That's a contradiction security consultants didn't miss.
"A vendor does not build a panic room for a house it believes is safe," said Sanchit Vir Gogia, chief analyst at Greyhound Research. "Lockdown Mode is the admission itself."
The mode is also porous by design. Gogia described the residual exposure bluntly: data can still leave through a side door, carried by a model acting on instructions hidden inside untrusted content while holding a trusted user's authority. Tom Findling, CEO of Conifers.ai, was candid about the ceiling. "Is it Nirvana? Probably not, but this is likely the best they could have done, given the infrastructure they have today." An unnamed executive at a major agentic cybersecurity firm noted that sandboxing has a poor record against AI: "Almost every sandboxing solution out there, AI has been able to break out of."
The human factor adds a layer no mode can address. An agent instructed to pull quarterly revenue figures from internal finance documents and share them with the requesting employee doesn't know — and isn't designed to know — that selective pre-announcement disclosure violates SEC rules. The model supplies the data. The user commits the violation. Lockdown Mode is irrelevant to that sequence.
Analysts split hard on the governance question. Erik Avakian of Info-Tech Research Group argued enterprises already have the tools: network segmentation, least privilege, Zero Trust, application controls. Dennis Xu, research VP at Gartner, pushed back directly. "ChatGPT is a web/SaaS based application that cannot be air gapped. In the shared responsibility model, this falls under provider responsibility." Xu's conclusion: if enterprises want this control from other AI vendors, they need to file feature requests — because OpenAI can only govern OpenAI.
That last point may be the sharpest one. Flavio Villanustre, CISO at LexisNexis Risk Solutions Group, warned the result is a "patchwork of controls" across vendors until independent third-party governance tools mature. Gogia agreed, noting that each vendor's lockdown mode constrains only its own product — a local model in a business unit, or an assistant embedded in a third-party workflow, sits entirely outside OpenAI's perimeter.
Lockdown Mode is an incremental improvement. It is not an architecture.
What enterprise teams should do now: Audit which AI products your organization uses and which sit outside any vendor-provided lockdown controls. Apply network egress restrictions at the infrastructure layer where possible. Document data-classification rules explicitly in AI usage policies — don't assume the model infers them. Treat vendor-supplied containment features as one control in a layered stack, not a substitute for the stack itself.



