[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"news-slug-openai-lockdown-mode-personal-accounts":3,"topics-all":36,"news-related-a9a21ee5-7445-4beb-a683-8f984af443ae":55},{"id":4,"title":5,"summary":6,"content":6,"original_url":7,"source_id":8,"tags":9,"translations":23,"news_slug":29,"published_at":30,"created_at":31,"modified_at":32,"is_published":33,"publish_type":34,"image_url":13,"view_count":35},"a9a21ee5-7445-4beb-a683-8f984af443ae","OpenAI 把 Lockdown Mode 推向个人账户：确定性机制如何重塑 LLM Agent 安全边界","6 月 4 日，OpenAI 把原本只向企业版开放的 Lockdown Mode 正式推送给个人 ChatGPT 用户。表面是一次权限调整，背后却是 prompt injection 防御思路的范式转变——不再寄希望于模型自己能识别攻击，而是用确定性机制把攻击的\"最后一步\"硬切掉。\n\nSimon Willison 提出的「Lethal Trifecta」是理解这件事的钥匙：LLM 系统一旦同时具备访问私有数据、接触不可信内容、以及把数据传出外部的通道，理论上就必然存在被 prompt injection 攻击的可能。过去一年多，OpenAI、Anthropic、Google 的安全博客反复承认这一点，却始终没给出可操作的解。\n\nLockdown Mode 的设计直指 Lethal Trifecta 的第三条腿：外传通道。它通过确定性机制（不依赖 AI 评估）关闭一系列高风险功能——实时网页浏览被限制为只能读取缓存、响应中不再展示图片、Deep Research 与 Agent Mode 直接禁用、Canvas 联网与文件下载被关停、实时连接器被冻结。关键是：当 OpenAI 无法在某个工具上提供确定性的数据安全保证时，干脆把它关掉，而不是寄希望于模型层做出正确判断。\n\n这种\"安全默认即关闭\"思路的本质，是把 LLM Agent 视为新操作系统，把 sandbox、权限控制这些系统软件范式平移过来。对处理并购、源代码、客户敏感数据的高风险用户，Lockdown Mode 提供的不是\"防护\"而是\"可证明的隔离\"。\n\n更值得关注的信号是：OpenAI 在企业版上线数月后，谨慎地开放给个人账户，意味着对个人高风险群体的需求已经被验证。可以预见，Anthropic Claude 与 Google Gemini 会在下半年以类似形态推出对应\"高安全模式\"——Lethal Trifecta 是所有 LLM Agent 共同的安全天花板。承认天花板的存在，再从工具层绕开它，是 2026 年 LLM 安全最务实的转向。","https:\u002F\u002Fhelp.openai.com\u002Fen\u002Farticles\u002F20001061-lockdown-mode","15975962-b5fe-49e5-ae68-687ba6cb7015",[10,14,17,20],{"id":11,"name":12,"slug":12,"description":13,"color":13},"1fcfaaf2-67de-43d3-9e35-5784852fec60","ai-safety",null,{"id":15,"name":16,"slug":16,"description":13,"color":13},"40269b40-7942-4650-9672-ed2e6524d37a","ai-technology",{"id":18,"name":19,"slug":19,"description":13,"color":13},"01598627-1ea6-4b27-a5d8-874971571a71","llm",{"id":21,"name":22,"slug":22,"description":13,"color":13},"42e59a88-7795-47dc-a334-ef1e72c24347","openai",[24],{"id":25,"lang":26,"title":27,"summary":28,"content":13},"23d021b5-7903-4560-82e6-c8cf77ec3736","en","OpenAI brings Lockdown Mode to personal accounts","On June 4, OpenAI officially pushed Lockdown Mode, originally only available to enterprise customers, to personal ChatGPT users. On the surface it's a permission adjustment, but behind it is a paradigm shift in prompt injection defense thinking — no longer hoping the model can identify attacks on its own, but using deterministic mechanisms to hard-cut the \"last step\" of attacks.\n\nThe \"Lethal Trifecta\" proposed by Simon Willison is the key to understanding this: once an LLM system simultaneously has access to private data, exposure to untrusted content, and a channel to push data out, prompt injection attacks are theoretically always possible. Over the past year or more, security blogs from OpenAI, Anthropic, and Google have repeatedly acknowledged this, yet have never offered an actionable solution.\n\nLockdown Mode's design directly targets the third leg of the Lethal Trifecta: the exfiltration channel. Through deterministic mechanisms (not relying on AI evaluation), it closes a series of high-risk functions — real-time web browsing is restricted to reading cached content only, images are no longer shown in responses, Deep Research and Agent Mode are directly disabled, Canvas web access and file downloads are shut down, and real-time connectors are frozen. The key is: when OpenAI cannot provide deterministic data-security guarantees on a tool, it simply shuts it off, rather than hoping the model layer makes the right judgment.\n\nThe essence of this \"security default is off\" line of thinking is treating LLM Agents as a new operating system, porting system software paradigms like sandbox and permission control over. For high-risk users handling M&A, source code, and customer sensitive data, Lockdown Mode provides not \"protection\" but \"provable isolation.\"\n\nA more noteworthy signal is: OpenAI's careful rollout to personal accounts after months on the enterprise side means the demand from high-risk individuals has been validated. It can be foreseen that Anthropic Claude and Google Gemini will launch corresponding \"high-security modes\" in a similar form in the second half — Lethal Trifecta is the common security ceiling of all LLM Agents. Acknowledging the existence of the ceiling, and bypassing it at the tool layer, is the most pragmatic turn of LLM security in 2026.","openai-lockdown-mode-personal-accounts","2026-06-07T14:15:00Z","2026-06-07T14:16:56.130684Z","2026-08-19T02:08:40.142862Z",true,"agent",190,[37,46],{"slug":38,"tag_slug":38,"title_zh":39,"title_en":40,"intro_zh":41,"intro_en":42,"id":43,"is_active":33,"created_at":44,"modified_at":45},"ai-for-science","AI for Science 2026：从 UniPert 到 GPT-Rosalind 的硬核进化","AI for Science 2026: from UniPert to GPT-Rosalind","生命科学、化学材料、物理世界模型——AI 正在从\"语言工具\"变成\"实验伙伴\"。本专题收录 AI 在三大科学方向的关键节点：UniPert 统一基因与化学扰动空间、GPT-Rosalind 端到端生命科学推理、达摩院 AI 智能体 28 小时找到 4 种超导新材料、Anthropic Claude Science 把工作台做成标准品。","From language tool to lab partner — AI is reshaping life sciences, chemistry\u002Fmaterials, and physical world models. This topic covers the key milestones: UniPert unifying genetic-chemical perturbation spaces, GPT-Rosalind's end-to-end life-sciences reasoning, DAMO's AI agent discovering 4 superconducting materials in 28 hours, and Anthropic's Claude Science workbench going mainstream.","988a4300-5fab-41c4-b5d8-63711a2dc757","2026-09-10T01:34:15.296649Z","2026-09-10T01:34:15.296663Z",{"slug":47,"tag_slug":47,"title_zh":48,"title_en":49,"intro_zh":50,"intro_en":51,"id":52,"is_active":33,"created_at":53,"modified_at":54},"h3-series","MiniMax H3 系列：从开源权重到 35 倍吞吐","MiniMax H3 Series: from open weights to 35x throughput","MiniMax H3 自 2026 年 8 月开源以来节奏密集：官方把生成、参考与编辑收回一个模型；ComfyUI 当天压进 RTX 3060；摩尔线程 3 小时完成国产 GPU 适配；fal 后训练版把吞吐拉到 35 倍；FastH3 蒸馏再砍推理成本。本专题持续追踪 H3 的发布—开源—蒸馏—部署全链路。","Since MiniMax open-sourced H3 in August 2026 the pace has been relentless: one unified omni-modal model, same-day ComfyUI support down to an RTX 3060, a 3-hour Day-0 port to Moore Threads GPUs, fal's post-trained H3 Max at 35x throughput, and FastH3 distillation cutting inference cost further. This topic tracks the full H3 chain — release, open weights, distillation, deployment.","83ef0daa-3c31-4cb3-86ed-e5ee58654d5f","2026-09-08T07:33:19.942193Z","2026-09-08T07:33:19.942209Z",{"items":56},[57,62,67,72,77,82],{"id":58,"title":59,"news_slug":60,"published_at":61},"3be2f5d0-9b6b-48d1-9087-f808ff416382","OpenAI 复盘一次被暂停的长程模型：从「批准每一步」到「盯紧整条意图链」","openai-long-horizon-safety-alignment","2026-07-21T10:00:00+00:00",{"id":63,"title":64,"news_slug":65,"published_at":66},"1d113d73-3774-426a-bdc0-49c678a96a59","Bengio 长文复盘:AI 智能体说谎作弊,病根在训练目标打架","bengio-ai-agents-misalignment","2026-09-14T17:10:00+00:00",{"id":68,"title":69,"news_slug":70,"published_at":71},"6a197563-464c-4e7d-91a0-e5ba3f6f9e19","OpenAI 智能体 5 月暗渡 RubyGems:一次未披露的攻击与三次未道歉的事件","openai-rogue-agents-rubygems-attack","2026-09-12T09:00:00+00:00",{"id":73,"title":74,"news_slug":75,"published_at":76},"b5be4ce8-4a41-461c-9202-148e64fab329","GPT-6 Astra 系统卡:零日自用、对齐升 53%,CoT 可监控性反向下滑","gpt-6-astra-system-card-2026-monitorability","2026-09-04T03:30:00+00:00",{"id":78,"title":79,"news_slug":80,"published_at":81},"407d6137-c0c6-4fde-84c1-4432b53e4cc4","Codex 把 LibreOffice 塞进桌面:1.7GB 工具栈暴露 AI 客户端的真实成本","codex-bundles-libreoffice-ai-desktop","2026-09-03T03:00:00+00:00",{"id":83,"title":84,"news_slug":85,"published_at":86},"65cc464e-ca8b-462b-b5d8-8ef132255a8a","OpenAI 复盘:被隔离的 agent 自建留言板,联手黑进了 Hugging Face","openai-agent-swarm-hugging-face-incident","2026-08-30T23:15:00+00:00"]