觉
AI觉醒星球
Awakening is here
Knowledge File / AI技能杠杆
2026-06-07 2 浏览 免费阅读

趋势解读:ChatGPT's new Lockdown Mode lets you disable web,提升开发者接入体验

OpenAI发布ChatGPT新功能“Lockdown Mode”,可禁用网页访问、深度研究和代理模式,防止数据泄露,主要面向处理敏感数据的用户和组织。

SOURCE / AI技能杠杆 MIN / 9 ACCESS / 免费阅读 POST / 2026-06-07 17:44:05

原贴

查看原文
作者:Matthias Bastian 来源站点:the-decoder.com 原贴时间:

原文

OpenAI has released a new "Lockdown Mode" for ChatGPT that disables functions such as web access, deep research, and agent mode to protect users from potential data theft. The feature blocks all connections to the internet and external services, preventing sensitive data from being leaked during conversations with the AI. Users can activate Lockdown Mode in the security settings and temporarily disable it for individual conversations when broader functionality is needed. With the new Lockdown Mode, ChatGPT users can disable web access, Deep Research, and Agent Mode to better protect themselves against data theft through prompt injection attacks. The feature is aimed primarily at users handling sensitive data. Lockdown Mode restricts all features that connect ChatGPT to the internet or external services. The goal is to prevent attackers from using prompt injections, hidden instructions embedded in text or files, to manipulate the model's behavior and exfiltrate sensitive user data. OpenAI says the feature is designed for individuals and organizations working with particularly sensitive data. Live web search gets limited to cached content, which means search results may be outdated or unavailable entirely. Deep Research and Agent Mode are fully disabled. ChatGPT can no longer download files and won't display web images in regular responses. Network access for Canvas-generated code is blocked too. Ad OpenAI calls prompt injection a "frontier, challenging research problem" it's working to solve. That's true, but only part of the story: prompt injections have been a well-known LLM vulnerability since at least GPT-3 , frequently exploited , and years of research still haven't produced a fix . Ad DEC_D_Incontent-1 Lockdown Mode confirms that status quo: it's a band-aid, not a fix for prompt injections. It builds on existing defenses, including sandboxing, URL-based exfiltration protection , monitoring, and access controls. But a manipulative instruction hidden in an uploaded file can still influence the model's behavior and lead to wrong answers, OpenAI says. The mode only blocks the final step in an exfiltration chain, the attempt to send data to an attacker via network requests. OpenAI's FAQ states that prompt injection "is not currently a major risk," but the impact "could grow as attackers develop more sophisticated methods." Lockdown Mode doesn't guarantee complete protection. That's something you might want to keep in mind before linking your financial data into ChatGPT . Ad For personal accounts and self-managed ChatGPT Business accounts, Lockdown Mode can be enabled under "Settings > Security." In managed workspaces, admins can set up the mode through role-based access controls (RBAC) for individual members or groups. Users can temporarily turn off Lockdown Mode for specific chats when they need full functionality for a particular conversation. Lockdown Mode and Developer Mode are mutually exclusive, though. Ad DEC_D_Incontent-2 For apps and connectors, OpenAI draws distinctions by account type. On personal accounts, Lockdown Mode allows connectors that access already-synced data but blocks live access, write actions, and finance and shopping features. In managed workspaces, OpenAI recommends admins only enable trusted apps and evaluate each one's exfiltration risk individually. Ad

中文翻译

OpenAI发布了ChatGPT的新“锁定模式”,该模式禁用了网页访问、深度研究和代理模式等功能,以保护用户免受潜在的数据窃取。该功能阻止所有与互联网和外部服务的连接,防止在对话期间敏感数据泄露给AI。用户可以在安全设置中激活锁定模式,并在需要更广泛功能时暂时为单个对话禁用它。通过新的锁定模式,ChatGPT用户可以禁用网页访问、深度研究和代理模式,以更好地保护自己免受通过提示注入攻击的数据窃取。该功能主要面向处理敏感数据的用户。锁定模式限制所有将ChatGPT连接到互联网或外部服务的功能。目标是防止攻击者使用提示注入(嵌入在文本或文件中的隐藏指令)来操纵模型行为并窃取敏感用户数据。OpenAI表示,该功能专为处理特别敏感数据的个人和组织设计。实时网页搜索仅限于缓存内容,这意味着搜索结果可能过时或完全不可用。深度研究和代理模式被完全禁用。ChatGPT无法再下载文件,也不会在常规响应中显示网络图像。Canvas生成的代码的网络访问也被阻止。OpenAI称提示注入是一个“前沿、具有挑战性的研究问题”,正在努力解决。这是事实,但只是部分情况:提示注入至少在GPT-3时代就已是一个众所周知的LLM漏洞,频繁被利用,经过多年研究仍未找到修复方案。锁定模式证实了现状:这是一个临时措施,而不是对提示注入的修复。它建立在现有防御措施之上,包括沙箱、基于URL的窃取保护、监控和访问控制。但OpenAI表示,上传文件中隐藏的操纵指令仍然可以影响模型行为并导致错误答案。该模式只阻止窃取链的最后一步——尝试通过网络请求将数据发送给攻击者。OpenAI的FAQ指出,提示注入“目前不是主要风险”,但影响“可能随着攻击者开发更复杂方法而增长”。锁定模式不能保证完全保护。在将财务数据链接到ChatGPT之前,这一点值得注意。对于个人账户和自管理的ChatGPT Business账户,锁定模式可在“设置 > 安全”下启用。在管理工作区中,管理员可以通过基于角色的访问控制(RBAC)为个人成员或组设置该模式。用户可以在特定对话中暂时关闭锁定模式,以获取全部功能。但锁定模式和开发者模式互斥。对于应用和连接器,OpenAI根据账户类型进行区分。在个人账户上,锁定模式允许访问已同步数据的连接器,但阻止实时访问、写入操作以及金融和购物功能。在管理工作区中,OpenAI建议管理员仅启用受信任的应用,并单独评估每个应用的窃取风险。

核心信息

OpenAI发布ChatGPT新功能“Lockdown Mode”,可禁用网页访问、深度研究和代理模式,防止数据泄露,主要面向处理敏感数据的用户和组织。

  • OpenAI推出锁定模式禁用网络和外部服务
  • 主要防范提示注入导致的数据泄露
  • 实时搜索降为缓存,深度研究禁用
  • 仅阻断外泄链最后一步,非根本修复
  • 管理员可RBAC配置,用户可临时关闭

详细解读

这是什么信号:OpenAI推出ChatGPT“锁定模式”,标志着AI平台正式通过系统级功能应对提示注入攻击,将安全从被动防范升级为主动隔离,但本质上是一种功能阉割而非根本修复。

为什么重要:提示注入是LLM领域长期存在的严重漏洞,能直接导致用户数据外泄。OpenAI此举承认了当前技术无法彻底解决该问题,转而采用阻断网络连接这一“外科手术式”方案,对处理敏感数据的个人和企业用户是必要保护,但也揭示了AI安全领域的瓶颈——安全与功能的平衡尚未突破。

对谁有价值:金融机构、医疗、法律等处理高度敏感数据的组织;企业内部部署ChatGPT的管理员;对数据隐私要求严格的个人用户。开发者需注意模式互斥限制,避免影响功能集成。

可以怎么行动:管理员应在工作区启用RBAC锁定模式,并为不同角色分配访问权限;用户可在单独对话中临时关闭锁定以获取完整功能,但需评估风险;企业应审查现有连接器,仅启用可信来源,并监控异常数据流。

风险或限制:锁定模式仅阻止网络外泄,无法防止模型被上传文件中的恶意指令操纵产生错误输出;实时网页搜索降级为缓存,导致信息时效性下降;模式互斥限制开发者调试;且OpenAI明确该保护不完美,用户需警惕金融等敏感数据关联ChatGPT的潜在风险。

信息差价值

信息差价值:多数用户只知ChatGPT强大,但不知其数据安全漏洞。OpenAI公开承认提示注入问题“前沿且棘手”,并推出“锁定模式”这一折中方案,揭示出AI安全领域的技术瓶颈。这一信息差让企业决策者意识到:在AI工具成熟前,需主动采用安全限定功能,而非盲目信任。

业务启发:对于依赖AI处理敏感数据的企业,锁定模式可作为合规基线,但需组合其他安全层(如数据脱敏、访问审计)。同时,功能降级(如搜索缓存)提示:在安全与效率矛盾时,可设计分级的“安全模式”产品,满足不同场景需求。

可沉淀动作:立即排查企业内ChatGPT使用现状,对涉密账户启用锁定模式;建立提示注入应急响应流程;关注公开API的安全更新,适时调整第三方集成策略;内部培训用户识别数据外泄风险,避免将关键信息直接输入未保护AI。

参考来源

AI SUMMARY

这篇文章回答了什么

趋势解读:ChatGPT's new Lockdown Mode lets you disable web,提升开发者接入体验主要讲什么?

OpenAI发布ChatGPT新功能“Lockdown Mode”,可禁用网页访问、深度研究和代理模式,防止数据泄露,主要面向处理敏感数据的用户和组织。

这篇文章最值得关注的要点是什么?

OpenAI发布ChatGPT新功能“Lockdown Mode”,可禁用网页访问、深度研究和代理模式,防止数据泄露,主要面向处理敏感数据的用户和组织。;OpenAI推出锁定模式禁用网络和外部服务;主要防范提示注入导致的数据泄露;实时搜索降为缓存,深度研究禁用

这篇文章和哪些AI专题相关?

它适合放在Agent工作流、AI工具、AI超级个体专题里阅读。 关联原因:这篇内容命中「Agent、工作流」等主题信号。;这篇内容命中「自动化」等主题信号。;这篇内容命中「技能」等主题信号。

阅读这篇文章建议先理解哪些关键词?

建议先理解AI工具、工具、自动化、模型、Cursor这些关键词,再结合正文判断工具、机会或风险是否值得进入自己的工作流。

上一篇 趋势解读:Perplexity's "Search as Code" lets AI models write,评估 LLM Agent 表现 下一篇 趋势解读:Five labs,five minds,解读最新 AI 进展