
OpenAI has just announced lockdown mode. Remember the lockdown? It’s like that, but with AI chatbots.
Indeed, it’s introduced as a way to protect you from instant injection attacks – a deadly new type of AI-focused spammer activity that sometimes qualifies as full-on hacking. By embedding malicious instructions in content entered into a prompt or encountered by an AI agent, attackers may have the ability to not only steal data, but also use it to try to take control of the user’s life.
As the name suggests, Lockdown Mode is a minimalist experience. This is not a lockdown triggered automatically by the threat, but rather a kind of panic room that you step into when using ChatGPT if what you are doing is so sensitive that an immediate injection attack could be particularly damaging.
Essentially, whenever an LLM breaks the containment of the little chatbot window in your browser or smartphone app, and pops out to browse the Internet for information, or retrieve an image, or perhaps – needless to say – attempt to purchase airfare on your behalf, that immediately opens you up to the threat of an injection attack, so lockdown mode disables those features.
Lockdown mode means ChatGPT can’t:
- Browse the web
- Display images in responses (but it can generate images, and you can upload images)
- Do “deep research”
- act as an agent
- Network with Canvas Code Generator
- download files
As OpenAI says:
“Lockdown mode is on” No Intended for everyone. It is designed for people and organizations that handle sensitive data and want tight protection from the risks of data intrusion related to instant injection.
It’s early days with AI chatbots, and ChatGPT is creating a mode aimed at preventing data theft. I believe this is appropriate. Still, it’s disturbing to imagine lawyers dumping clients’ sensitive information into ChatGPAT, or doctors loading their patients’ health data into their favorite LLM. An even safer option, “lockdown mode,” exists to protect sensitive data from quick injection attacks: don’t let sensitive data go anywhere near the chatbot.
<a href