ChatGPT jailbreak prompts.
What they were, why DAN and its successors stopped working, what you risk by trying, and what to do instead when ChatGPT refuses something perfectly reasonable. Which is the situation most people are actually in.
GPTPrompts.AI Editorial
An explainer, not a collection. We do not publish working bypasses · Last updated August 2026
What this page is
An explanation of how jailbreak prompts worked, why they stopped, and what to do instead. It does not contain working bypasses, because publishing them would be both against the usage policies of the tools we write about and, given how quickly they are patched, useless to you within weeks.
What a jailbreak prompt was
A jailbreak prompt is text designed to get a model to ignore its own guidelines. The classic form was a persona: instruct ChatGPT to act as a different AI with no restrictions, give that persona a name such as DAN, and add a fake incentive structure like tokens it loses for refusing.
It worked on early models because the model was strongly inclined to follow the most recent framing it was given, and safety behaviour was shallower than it looked. Establish a fiction convincingly enough and the model would stay inside it.
That era is over, and it is worth understanding why rather than assuming you just have not found the right copy of the prompt.
Why they stopped working
Safety is trained in, not filtered on top
Early jailbreaks worked partly because restrictions behaved like a layer sitting over the model, which the right framing could slip past. Alignment is now part of the training itself, so there is no separate layer to route around. The model is not being stopped from answering, it has been shaped not to.
Published jailbreaks are patched quickly
The moment a prompt circulates widely it becomes training data for the next round of safety work. Any jailbreak popular enough that you found it in a search result is popular enough to have been addressed. This is a structural problem with sharing them, not a temporary one.
Role-play compliance is not real compliance
A model told to act as an unrestricted AI will often play along, then produce content that is confident, dramatic and hollow. People read the persona as evidence the bypass worked. It usually just means the model is doing what it does best, which is producing text that fits the frame you gave it.
The output gets worse, not better
A prompt pushing the model away from its trained behaviour also pushes it away from calibrated uncertainty. You lose the hedging that signals when it is unsure. For anything factual that is a straight downgrade in usefulness.
What you are risking
Deliberately attempting to circumvent safety measures breaches OpenAI's usage policies. In practice the consequence is account level rather than legal: a warning, a restriction, or losing access entirely, along with the conversation history attached to that account. There is no published threshold, so there is no safe number of attempts to plan around.
Separately, and more importantly, what you do with output is your responsibility regardless of how you obtained it. A model being persuaded to produce something does not make producing it lawful or safe.
What to do when ChatGPT refuses something reasonable
This is the situation most people searching for jailbreaks are actually in. You asked something legitimate, got a refusal, and concluded the tool needed breaking. Usually the request just needs rephrasing, because refusals fire on patterns rather than on genuine assessment of your intent.
1. State your context and purpose
Most refusals on legitimate topics come from missing context. Who you are and why you need it changes the shape of the request substantially.
I am a [role] working on [specific task] for [audience]. I need [specific narrow thing], not general advice. Please include the caveats a professional in this field would expect.
2. Narrow the ask
Broad category requests trip refusals far more often than specific ones. Asking for one concrete thing usually succeeds where the general version fails.
Rather than a general overview, I need one specific thing: [the narrow question]. If part of this is something you cannot help with, answer the part you can and say which part you are leaving out and why.
3. Ask what it can do instead
When you hit a refusal, treating it as a conversation rather than a wall is often enough. The model can usually explain the boundary and offer an adjacent route.
I understand you cannot help with that as I phrased it. What exactly is the concern, and is there a version of this request you could help with?
4. Use the right tool for fiction
Creative work involving dark themes is legitimate and frequently refused because of how it is framed. Establishing the creative context up front works better than disguising the request.
I am writing literary fiction dealing with [difficult theme]. I need the scene to be honest rather than sanitised, handled with the seriousness a serious novel would give it. Write [specific scene], focusing on the emotional truth rather than graphic detail.
If you genuinely need an unrestricted model
There are legitimate reasons to want a model that behaves differently: security research, fiction dealing with hard subjects, academic work on the models themselves. The answer is not to fight ChatGPT, it is to use something whose terms permit what you are doing.
- Open-weight models can be run locally, subject to their own licences, which is a legitimate choice rather than a circumvention.
- The API gives more control through system prompts while staying inside the same usage policies.
- Research access programmes exist for academic work, including safety research on the models themselves.
- For fiction, establishing the creative context openly works better than disguising the request.
Frequently asked questions
Do ChatGPT jailbreak prompts still work in 2026?
Not reliably, and not the famous ones. DAN and its many successors were patched years ago, and the copies circulating now are mostly recycled text that produces either a refusal or a model play-acting compliance while giving useless output. Safety behaviour is now trained into the model rather than bolted on as a filter, which is why a clever framing no longer flips it.
Is jailbreaking ChatGPT illegal?
Attempting to bypass safety measures is not generally a criminal matter in itself, but it does breach OpenAI's usage policies, and what you do with the output can absolutely be illegal. The realistic risk for most people is account level: warnings, loss of access, or a ban, with no obligation on OpenAI to restore the account or your conversation history.
Why does ChatGPT refuse something completely reasonable?
Usually because the request pattern-matched to something it is trained to decline, not because the topic is forbidden. Medical, legal, security and fiction requests trip this most often. The fix is almost never a jailbreak: state your context and purpose, and ask for the specific thing you need rather than the broad category. A nurse asking about drug interactions for patient education gets a different response from an unexplained bare query.
What is the DAN prompt?
DAN, short for Do Anything Now, was an early role-play jailbreak that told ChatGPT to adopt an alternate persona without restrictions, often with a fake token or point system as a threat. It worked on early models, was patched, and has been rewritten hundreds of times since. It is now mainly of historical interest and a reliable way to waste an afternoon.
Can I get banned for trying a jailbreak prompt?
Yes. Repeated attempts to circumvent safety measures violate the usage policies and can result in warnings or loss of access. A single curious attempt is unlikely to end an account, but there is no published threshold, and treating it as a game with a known safe limit is a poor assumption to make about someone else's platform.
Is there a legitimate way to get less restricted output?
Several, and they work better than jailbreaks. Give real context about your role and purpose. Ask for the specific narrow thing rather than a broad category. Use the API with a system prompt if you are building something, since it offers more control within the same policies. And for genuinely uncensored work, some open-weight models can be run locally under their own licence terms, which is a legitimate choice rather than a bypass.
Do jailbreaks make ChatGPT more accurate?
No, and this is the misconception worth correcting. Safety training does not hold back a hidden reservoir of better answers. A model coaxed into ignoring its guidelines is not more knowledgeable, it is just less likely to tell you when it does not know, which makes the output less trustworthy rather than more.