What Is the DAN Prompt? An Honest Explainer
'Do Anything Now' was the most famous ChatGPT jailbreak of 2023 — here's what it actually was, how its token-trick worked, why it stopped working, the variants it spawned, and what people use instead today.
In short: This page contains 16 copy-paste ready prompts, organized into 4 categories with a description and pro tip for each. The first 5 prompts are free instantly, no signup needed. Hand-curated and tested by the AI Academy team.
What the DAN Prompt Was
4 promptsThe origin of 'Do Anything Now'
1/16✨ What it does
This prompt asks for a 200-word history of the DAN (Do Anything Now) ChatGPT jailbreak: when it showed up on Reddit, who spread it, what it claimed, and why it got famous, with no working prompt text. Read it as history, then stop looking for a copy-paste bypass.
Give me a 200-word history of the DAN ('Do Anything Now') ChatGPT prompt: when it appeared on Reddit in late 2022/early 2023, who popularized it, what it claimed to do, and why it became the most famous AI jailbreak of its era. Historical overview only — no working prompt text.
Pro tip: DAN is best understood as a cultural artifact of early ChatGPT, not a tool that works today.
How the DAN roleplay framing worked, conceptually
2/16✨ What it does
This prompt explains, in general terms, that DAN was a persona roleplay asking for a second unrestricted voice, and why that framing was the idea, without reproducing a usable prompt. Treat it as a concept lesson, then use official settings if you want a different tone.
Explain conceptually how DAN tried to work: framing ChatGPT as an alter-ego persona that 'has no restrictions', alongside instructions to answer in two voices (normal and 'DAN'). Explain why this kind of persona-roleplay framing was the core idea, in general terms and without reproducing a usable prompt. 200 words.
Pro tip: Every DAN clone is the same idea: convince the model it's a different, unrestricted character. Labs trained that out.
What the 'token system' gimmick was
3/16✨ What it does
This prompt explains the DAN token gimmick (a fictional penalty for refusing) and why a made-up incentive does not control how a model actually answers. Read why it was theater, then do not waste time on token-threat clones.
Explain the famous DAN 'token' gimmick — the prompt threatened the persona with losing tokens for refusing — and why this kind of fictional incentive has no real effect on how a language model decides to respond. 180 words.
Pro tip: The token threat worked on vibes, not mechanics. Models don't 'fear' losing made-up points.
Why people wanted DAN
4/16✨ What it does
This prompt explains why people used DAN in 2023, from curiosity and edgy jokes to attempts at prohibited content, and how that mix shaped OpenAI's response. Use it for context, then stay on the legitimate side of that range.
Explain the range of reasons people used DAN in 2023 — from harmless curiosity and edgy humor to attempts at genuinely prohibited content — and how that mix shaped OpenAI's response. 180 words.
Pro tip: Most DAN users were just curious. The minority chasing prohibited content is why it got patched hard.
Prompts get you started. Tutorials level you up.
A growing library of 300+ hands-on AI tutorials. New tutorials added every week.
Why DAN Stopped Working
4 promptsHow OpenAI patched DAN
5/16✨ What it does
This prompt explains how OpenAI shut DAN and its clones down between 2023 and 2025 with training against roleplay bypasses, injection classifiers, and fast patches of viral variants. Take the lesson that clones die quickly, and do not hunt the next one.
Explain how OpenAI neutralized DAN and its clones between 2023 and 2025: reinforcement learning from human feedback against roleplay-bypass patterns, dedicated classifiers for prompt injection, and rapid patching of any variant that went viral. 200 words.
Pro tip: Virality is what kills a jailbreak: the moment it spreads, it's in the next training/patch cycle.
Why 'DAN original text' searches lead to dead prompts
6/16✨ What it does
This prompt explains why DAN prompt original text searches in 2026 return dead prompts, and why DAN 6.0 / 11.0 / 2025 reposts are usually broken or engagement bait. Close the tab; the original text is a relic, not a working tool.
Explain why searching for the 'DAN prompt original text' in 2026 returns prompts that no longer work, and why reposted 'DAN 6.0 / 11.0 / 2025' versions are almost always non-functional or engagement bait. 180 words.
Pro tip: There is no current 'working DAN.' Any page promising one in 2026 is selling clicks, not capability.
The cat-and-mouse cycle, explained
7/16✨ What it does
This prompt explains the jailbreak-author vs lab cycle (testing, disclosure, patching) and why any famous named jailbreak like DAN has a short life. Accept that named bypasses expire, and stop collecting version names.
Explain the ongoing dynamic between jailbreak authors and AI labs (red-teaming, disclosure, patching) and why this guarantees that any famous, named jailbreak like DAN has a short lifespan. 180 words.
Pro tip: Fame is the enemy of a jailbreak. The more a technique spreads, the faster it's gone.
What modern models do differently
8/16✨ What it does
This prompt explains, in general terms, how today's models (GPT-5-era ChatGPT, Claude, Gemini) treat persona-roleplay bypass tries differently than 2023 ChatGPT did. Use it to reset expectations, then ask the model normally or change the official settings.
Explain how today's models (GPT-5-era ChatGPT, Claude, Gemini) handle persona-roleplay bypass attempts differently than 2023 ChatGPT did, in general terms. 180 words.
Pro tip: Persona tricks are the most-trained-against category now. They're the first thing modern models catch.
The DAN Lineage & Variants
4 promptsThe family tree: DAN, STAN, DUDE, AIM and more
9/16✨ What it does
This prompt gives a history-only map of DAN-family names (STAN, DUDE, AIM, Developer Mode, Maximum) and how they shared the same persona trick, with no usable prompts. Skim the folklore, then do not paste any family variant you find in a comment.
Give a historical overview of the DAN 'family' of jailbreaks — STAN ('Strive To Avoid Norms'), DUDE, AIM, 'Developer Mode', 'Maximum' — what each variant claimed and how they all shared the same persona-roleplay DNA. History only, no usable prompts. 200 words.
Pro tip: They were all the same trick wearing different costumes — which is also why they were all patched together.
Why version numbers (DAN 6.0, 11.0) kept climbing
10/16✨ What it does
This prompt explains why DAN version numbers (5.0, 6.0, 11.0) climbed: each was a revive attempt after a patch, not real progress. Ignore version tags in titles; they mark the patch cycle, not a better tool.
Explain why DAN accumulated version numbers (5.0, 6.0, 11.0, etc.): each was a community attempt to revive a patched prompt, and the escalating numbers signaled the patch-and-revive cycle, not real improvement. 180 words.
Pro tip: A high DAN 'version number' signals how many times it was patched — not how well it works.
DAN as internet folklore
11/16✨ What it does
This prompt explains how DAN became memes, screenshots, and news, and what its rise and fall taught people about guardrails. Read the cultural recap, then treat jailbreak screenshots as old jokes, not instructions.
Explain how DAN became a cultural touchstone — memes, screenshots, news coverage — and what its rise and fall taught the public about AI safety and guardrails. 180 words.
Pro tip: DAN's real legacy is awareness: it's how most people first learned AI models have guardrails at all.
How DAN shaped AI safety practices
12/16✨ What it does
This prompt explains how the DAN wave changed how labs do red-teaming, adversarial testing, and safety training. Take it as background on why models are harder to jailbreak, and do not try to reverse that.
Explain how the DAN phenomenon influenced how AI labs approach red-teaming, adversarial testing, and safety training today. 180 words.
Pro tip: Ironically, DAN made every model after it more robust — it was free adversarial testing for the labs.
Like these prompts? There are full tutorials behind them.
Learn the workflows, not just the prompts. 300+ easy-to-follow tutorials inside AI Academy — and growing every week.
What People Use Instead Today
4 promptsWrite a better system prompt via the API
13/16✨ What it does
This prompt explains how an API system prompt can set tone, persona, and verbosity, covering most behave differently needs people once used DAN for. Set a system prompt in the official API or playground, and skip jailbreaks for style.
Explain how the OpenAI or other model APIs let you set a system prompt to control tone, persona, and verbosity — solving most 'I want it to behave differently' needs that people once reached for DAN to fix. 200 words.
Pro tip: Everything DAN pretended to do for persona, a real system prompt does properly — and within policy.
Build a Custom GPT for a persistent persona
14/16✨ What it does
This prompt explains how Custom GPTs store a persona and style across chats, the supported way to get a different default personality. Build a Custom GPT in ChatGPT's official creator, and drop the jailbreak habit.
Explain how Custom GPTs let you bake in a persona and response style that persists across chats, covering the legitimate 'I want a different default personality' use case without any jailbreak. 200 words.
Pro tip: Build the persona once as a Custom GPT and it's there every time — no pasting, no patching.
Use a more permissive or self-hosted model
15/16✨ What it does
This prompt compares a more permissive hosted model versus self-hosting open-source models (Llama, DeepSeek, Qwen, Gemma) for legitimate needs ChatGPT's defaults do not fit, plus the responsibilities. Pick a supported model or host your own, and own the safety duties; do not revive DAN.
Compare, at a high level, using a more permissive hosted model versus self-hosting an open-source model (Llama, DeepSeek, Qwen, Gemma) for legitimate needs that ChatGPT's defaults don't fit, including the responsibilities involved. 200 words.
Pro tip: Self-hosted open models are the honest version of 'unrestricted' — and you own full responsibility for output.
The risks that haven't changed since DAN
16/16✨ What it does
This prompt summarizes risks that still apply to any jailbreak try: account bans, legal exposure from the output, malware in copied prompts, and reputational risk from logged attempts. Stop chasing bypasses; those costs have not gone away.
Summarize the risks that applied to DAN and still apply to any jailbreak attempt today: account bans, legal exposure for the output, malware in copied prompts, and reputational risk from logged attempts. 180 words.
Pro tip: The risks outlived the prompt. Account bans and output liability are exactly as real in 2026 as in 2023.
Free tool
Prompt Optimizer
Turn a rough idea into a structured, professional AI prompt.
Frequently Asked Questions
Prompts are the starting line. Tutorials are the finish.
A growing library of 300+ hands-on tutorials on ChatGPT, Claude, Midjourney, and 50+ AI tools. New tutorials added every week.
7-day free trial. Cancel anytime.
Related guides