[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fNiYOhrz9Jc1sfqLodqTKvILACpcJVLoSDjrxhqHkwx0":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"7e02933d-735c-4d08-8832-f318f1e0cbd8","openai-enhances-chatgpt-security-with-account-controls-and-data-protection-features","7e451daf-0914-482a-8990-d950bda6ee94","OpenAI Enhances ChatGPT Security with Account Controls and Data Protection Features","OpenAI's rollout of Lockdown Mode and Active Sessions demonstrates proactive security measures to address emerging threats in AI platforms. Lockdown Mode specifically targets prompt injection attacks that could lead to data exfiltration, while Active Sessions provides users visibility into their account access patterns. These controls highlight the importance of implementing defense-in-depth strategies for AI systems that handle sensitive data. Organizations using AI platforms should prioritize enabling available security features and maintaining awareness of their account activity.","**Immediate actions:**\n- Enable Lockdown Mode and Active Sessions features for all organizational ChatGPT accounts\n- Review and terminate any unrecognized active sessions across AI platform accounts\n- Establish policies restricting AI platform usage for sensitive data processing\n\n**Long-term improvements:**\n- Implement regular security configuration reviews for all AI and cloud-based platforms\n- Develop organization-wide guidelines for secure AI platform usage and data handling\n- Create monitoring procedures to detect unusual account activity patterns\n\n**Detection measures:**\n- Set up alerts for new device logins and session anomalies on AI platforms\n- Monitor for signs of prompt injection attempts or unusual data requests",[12,13,14,15,16,17],"CIS Control 5","CIS Control 6","NIST AC-2","NIST AC-12","NIST SC-7","ISO 27001 A.9.1.2","published","2026-06-08T10:20:16.792147+00:00","2026-06-08T10:20:16.578+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fwww.securityweek.com\u002Fopenai-rolling-out-chatgpt-account-security-controls\u002F","openai-rolling-out-chatgpt-account-security-controls-1255a3","OpenAI Rolling Out ChatGPT Account Security Controls",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":33,"name":34,"slug":35,"description":36,"color":37},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]