OpenAI、プロンプト注入攻撃から機密データを保護する「ロックダウンモード」を発表
OpenAI は、ウェブページや外部ソースに埋め込まれた悪意ある指示によるプロンプトインジェクション攻撃からユーザーデータを保護するための新機能「Lockdown Mode」を発表した。
キーポイント
プロンプトインジェクション対策の強化
ウェブページや外部コンテンツに隠された悪意あるチャットボットの指示(プロンプトインジェクション)を検知・防御する新機能を導入した。
ライブ閲覧機能の制限
Lockdown Mode 有効時には、生きたウェブ検索を無効化し、キャッシュされたコンテンツのみへのアクセスを許可することで攻撃経路を遮断する。
画像取得と高度機能の一時停止
ウェブからの画像取得・表示機能を無効化する一方、画像生成機能は維持し、また「Deep Research」やエージェントモードといった複雑な機能も制限される。
ロックダウンモードの機能制限
ライブウェブ閲覧(キャッシュのみ)、画像検索、深層調査、エージェントモードを無効化し、データ漏洩リスクを低減します。
完全な防御ではないことの明記
キャッシュされたコンテンツやアップロードファイル内にプロンプトインジェクションが含まれる場合、依然として脆弱性が残る可能性があります。
対象ユーザーと展開状況
機密データを扱う個人および組織向けに設計され、現在は ChatGPT Business アカウントや対象となる個人アカウントへ順次展開されています。
重要な引用
OpenAI announced a new feature that it says will provide additional protection from prompt injection attacks, where malicious chatbot instructions are hidden in webpages and other content sources.
Lockdown Mode will disable live web browsing (so you can only access cached content), the retrieval and display of images from the web (you can still generate images)...
"Lockdown Mode is not intended for everyone. It is designed for people and organizations that handle sensitive data and want stricter protection from data exfiltration risks related to prompt injection."
"even with Lockdown Mode turned on, ChatGPT could still be vulnerable to prompt injections — which could, for example, 'appear in cached web content or in an uploaded file, and could still affect the behavior or accuracy of a response.'"
影響分析・編集コメントを表示
影響分析
この発表は、生成 AI の実社会での活用が進む中で深刻化している「プロンプトインジェクション」という脆弱性に対する、主要ベンダーによる即応の証左です。特に企業や個人が機密情報を扱う際、外部リンクを介した攻撃リスクを低減する重要なセキュリティレイヤーとなり、AI ツールの信頼性を高める一歩となります。
編集コメント
生成 AI の普及に伴い、外部コンテンツを介した攻撃リスクが現実的な脅威となっています。OpenAI がセキュリティと機能性のバランスを取りながら対策を講じたことは、業界全体のセキュリティ基準引き上げにも寄与する重要な動きです。
概要
投稿日:
2026年6月6日 午後1時32分 PDT
image画像クレジット: sarayut Thaneerat / Getty Images
OpenAI は、悪意のあるチャットボットの指示がウェブページやその他のコンテンツソースに隠されるプロンプトインジェクション攻撃(prompt injection attacks)から追加の保護を提供すると述べている新機能を発表しました。
Lockdown Mode(ロックダウンモード)では、ライブウェブブラウジング(キャッシュされたコンテンツのみアクセス可能)、ウェブからの画像の取得と表示(画像生成は引き続き可能)、ディープリサーチ(deep research)、およびエージェントモード(agent mode)が無効化されます。
同社は、Lockdown Mode をオンにしても ChatGPT がプロンプトインジェクションに対して依然として脆弱である可能性があると述べています。例えば、「キャッシュされたウェブコンテンツやアップロードされたファイルに現れ、応答の動作や精度に影響を与える可能性がある」とのことです。
しかし、その目的は、この過程で機密データが共有される可能性を減らすことです。
OpenAI は「Lockdown Mode はすべての人向けではありません。これは、機密データを扱い、プロンプトインジェクションに関連するデータ漏洩リスクからより厳格な保護を望む個人や組織のために設計されています」と述べています。
同社は現在、Lockdown Mode をセルフサービス型の ChatGPT Business アカウントおよび対象となる個人アカウントに向けて展開中だと述べています。
トピック
業界最大のテックニュースを購読する
AI 最新情報
原文を表示
In Brief
Posted:
1:32 PM PDT · June 6, 2026

-
OpenAI announced a new feature that it says will provide additional protection from prompt injection attacks, where malicious chatbot instructions are hidden in webpages and other content sources.
Among other things, Lockdown Mode will disable live web browsing (so you can only access cached content), the retrieval and display of images from the web (you can still generate images), deep research, and agent mode.
The company says that even with Lockdown Mode turned on, ChatGPT could still be vulnerable to prompt injections — which could, for example, “appear in cached web content or in an uploaded file, and could still affect the behavior or accuracy of a response.”
But the goal is to reduce the likelihood that sensitive data gets shared in the process.
“Lockdown Mode is not intended for everyone,” OpenAI says. “It is designed for people and organizations that handle sensitive data and want stricter protection from data exfiltration risks related to prompt injection.”
The company says it’s currently rolling Lockdown Mode out to self-serve ChatGPT Business accounts, as well as eligible personal accounts.
Topics
Subscribe for the industry’s biggest tech news
Latest in AI
関連記事
今日のまとめ
AI日報で今日の重要ニュースをまとめ読み