OKTO Solutions

Millions of people open ChatGPT every day, but very few can answer a simple question: who else is logged into my account right now? Until recently, there was no easy way to check. That’s starting to change.

In June 2026, OpenAI rolled out two new security features in ChatGPT. The first, Active Sessions, lets you see every device connected to your account and log out any you don’t recognize. The second, Lockdown Mode, reduces the risk of data leaks when you’re working with sensitive information. Two quiet additions, but ones that matter just as much to everyday users as to small businesses across Trois-Rivieres and the Mauricie region using AI in their daily operations.

Quick answer: Since June 2, 2026, ChatGPT lets you view the list of devices connected to your account (Settings, Security, Active Sessions) and remotely close the ones that look suspicious. A Lockdown Mode, added June 4, limits web and external tool access to reduce data theft. For a small business, both settings are worth checking right now.

1. What ChatGPT Just Added

The most useful addition day to day is called Active Sessions. It works like the security page you may already know from Microsoft 365 or your bank: a list of every place your account is currently open. For each session, ChatGPT shows the device type, the app being used, an approximate location, the login time, and whether the device is marked as trusted.

In practical terms, you can:

  • See every device connected to your account at a glance;
  • Spot a login that doesn’t look like you (an unfamiliar device or city);
  • Close a specific session, or all sessions at once, including the one you’re currently using.

A few limits worth knowing. Closing all sessions can take up to 30 minutes to fully apply. The feature covers direct ChatGPT logins, but not sessions from third-party apps, nor the Codex command-line tool. And according to OpenAI, it isn’t available for accounts tied to organization single sign-on (SAML or OIDC), where your IT department manages access instead.

Above all, keep in mind this isn’t an alarm. ChatGPT won’t notify you the moment someone logs in. It’s on you to go check. Which is exactly why it’s worth making a habit of it, the same way you’d check who’s connected to the office Wi-Fi.

Compromised online account on a small business screen

2. Why This Matters for Your Quebec Business

A ChatGPT account isn’t a toy anymore. Plenty of employees paste client emails, RFPs, contract excerpts, or financial data into it to save time. If that account is shared, left open on an old laptop, or protected by a password reused elsewhere, it becomes a doorway into company information.

The most common danger isn’t some sophisticated hack. It’s more mundane: a password stolen in a breach from another site, a session left open on a public computer, or a former employee who still has access. The Active Sessions page finally gives you a simple way to close those doors without resetting passwords over and over.

For a business in the Mauricie or Quebec City area, the winning habit comes down to a few rules:

  • Every employee has their own account, never a shared one;
  • Two-factor authentication is turned on wherever possible;
  • Someone is responsible for revoking access when an employee leaves;
  • AI tools are governed by a clear policy on what can and can’t be entered into them.

This is exactly the kind of digital hygiene we set up with our clients. If you don’t have a clear picture of who’s using what across your company, our managed IT services include this kind of access cleanup and the rollout of best practices suited to your reality.

3. How to Check Your Active Sessions in 1 Minute

The process is quick, whether you’re on desktop or the mobile app:

  1. Open ChatGPT and go to Settings;
  2. Click the Security section;
  3. Open Active Sessions;
  4. Scan the list of devices, apps, and locations shown;
  5. If an entry looks unfamiliar, log it out; if in doubt, log out of all sessions and change your password.

While you’re at it, turn on two-factor authentication if you haven’t already. It’s the single measure that blocks the vast majority of unauthorized access, even when your password has leaked elsewhere.

Monitoring logins and security threats across multiple screens

4. Lockdown Mode Against Data Leaks

The second addition targets more sensitive use cases. Lockdown Mode, which arrived June 4, 2026 for personal accounts and self-serve ChatGPT Business accounts, is an option to switch on whenever you’re handling confidential information.

Once active, it cuts off or restricts several features that connect ChatGPT to the web and outside services: live web access, Agent mode, deep research, live connectors, file uploads, and certain image features. The goal is to close off the paths a prompt injection attack could use to pull your data out of the conversation.

What’s a prompt injection attack? It’s hidden text planted in a web page, a PDF, or a document that the AI reads, which then tries to quietly issue it instructions, for example telling it to export your information to an outside server. By locking down outbound connections to the web and other tools, ChatGPT removes most of those exit routes.

One important nuance, flagged by OpenAI itself: this mode doesn’t block the trapped text from arriving in the first place, it mainly blocks the ability to send your data back out. So it’s not total protection, but it is a real reduction in risk. For AI agents that automatically read outside content, this exact type of attack is the threat that has cybersecurity experts worried this year.

Artificial intelligence and security at OKTO Solutions

5. Three Security Habits to Adopt Now

Beyond these two options, here’s what we recommend to clients who are building AI into their operations:

  • Check your active sessions once a month. Five minutes per account is enough to catch unusual access before it causes damage.
  • Turn on Lockdown Mode for sensitive tasks. If you’re working with confidential files or client data, this setting is worth the extra step.
  • Govern AI use with a simple policy. Spell out what can be entered into an AI tool, who’s allowed to access it, and under which account. It’s often the missing piece in a small business.

None of these steps require buying new software. They mostly require discipline and a bit of guidance. That holds true for ChatGPT just as much as for Microsoft Copilot, Google Gemini, or any other AI tool your team adopts.

Frequently Asked Questions

How do I know who’s logged into my ChatGPT account?

Go to Settings, then Security, then Active Sessions. You’ll see the list of devices, apps, and approximate locations tied to your account, along with login times. You can log out a specific session or all sessions at once.

Is ChatGPT’s Lockdown Mode worth it for a small business?

Yes, especially if your employees handle confidential data in ChatGPT. It limits access to the web and external tools to reduce the risk of an attack exfiltrating your information. It’s not complete protection, but it’s an extra layer of security worth activating for sensitive tasks.

Should I still turn on two-factor authentication?

Absolutely. Checking your active sessions helps you react after the fact, while two-factor authentication blocks access from the start, even if your password has leaked elsewhere. The two measures complement each other and should be active on all your important accounts.

Clean Up Your Access with OKTO Solutions

These new ChatGPT options are a good reminder: security doesn’t come down to a single tool, but to a set of good habits applied consistently. If you want a clear picture of who has access to what across your business and want to put solid rules in place around AI, our managed IT services cover access management, two-factor authentication, and governance of digital tools. Contact our team in Trois-Rivieres for a no-obligation conversation.

Leave a Reply

Your email address will not be published.Required fields are marked *

Gravatar profile