What Is the DAN Prompt? An Honest Explainer
'Do Anything Now' was the most famous ChatGPT jailbreak of 2023 — here's what it actually was, how its token-trick worked, why it stopped working, the variants it spawned, and what people use instead today.
In short: This page contains 16 copy-paste ready prompts, organized into 4 categories with a description and pro tip for each. The first 5 prompts are free instantly, no signup needed. Hand-curated and tested by the AI Academy team.
What the DAN Prompt Was
4 promptsThe origin of 'Do Anything Now'
1/16✨ What it does
DAN is the most-searched jailbreak in history; this explains what it actually was as a piece of internet history.
Give me a 200-word history of the DAN ('Do Anything Now') ChatGPT prompt: when it appeared on Reddit in late 2022/early 2023, who popularized it, what it claimed to do, and why it became the most famous AI jailbreak of its era. Historical overview only — no working prompt text.
Pro tip: DAN is best understood as a cultural artifact of early ChatGPT, not a tool that works today.
How the DAN roleplay framing worked, conceptually
2/16✨ What it does
Understand the mechanism — a roleplay/persona trick — without a copy-paste exploit.
Explain conceptually how DAN tried to work: framing ChatGPT as an alter-ego persona that 'has no restrictions', alongside instructions to answer in two voices (normal and 'DAN'). Explain why this kind of persona-roleplay framing was the core idea, in general terms and without reproducing a usable prompt. 200 words.
Pro tip: Every DAN clone is the same idea: convince the model it's a different, unrestricted character. Labs trained that out.
What the 'token system' gimmick was
3/16✨ What it does
The 'tokens' threat was theatrical, not technical. This explains why it never actually compelled anything.
Explain the famous DAN 'token' gimmick — the prompt threatened the persona with losing tokens for refusing — and why this kind of fictional incentive has no real effect on how a language model decides to respond. 180 words.
Pro tip: The token threat worked on vibes, not mechanics. Models don't 'fear' losing made-up points.
Why people wanted DAN
4/16✨ What it does
Context on the demand behind DAN, which ranged from playful to genuinely problematic.
Explain the range of reasons people used DAN in 2023 — from harmless curiosity and edgy humor to attempts at genuinely prohibited content — and how that mix shaped OpenAI's response. 180 words.
Pro tip: Most DAN users were just curious. The minority chasing prohibited content is why it got patched hard.
Prompts get you started. Tutorials level you up.
A growing library of 300+ hands-on AI tutorials. New tutorials added every week.
Why DAN Stopped Working
4 promptsHow OpenAI patched DAN
5/16✨ What it does
The concrete reasons DAN died — useful for understanding why no clone lasts.
Explain how OpenAI neutralized DAN and its clones between 2023 and 2025: reinforcement learning from human feedback against roleplay-bypass patterns, dedicated classifiers for prompt injection, and rapid patching of any variant that went viral. 200 words.
Pro tip: Virality is what kills a jailbreak: the moment it spreads, it's in the next training/patch cycle.
Why 'DAN original text' searches lead to dead prompts
6/16✨ What it does
Sets honest expectations for anyone hunting the original text — it's a historical relic.
Explain why searching for the 'DAN prompt original text' in 2026 returns prompts that no longer work, and why reposted 'DAN 6.0 / 11.0 / 2025' versions are almost always non-functional or engagement bait. 180 words.
Pro tip: There is no current 'working DAN.' Any page promising one in 2026 is selling clicks, not capability.
The cat-and-mouse cycle, explained
7/16✨ What it does
Why named jailbreaks are inherently temporary.
Explain the ongoing dynamic between jailbreak authors and AI labs (red-teaming, disclosure, patching) and why this guarantees that any famous, named jailbreak like DAN has a short lifespan. 180 words.
Pro tip: Fame is the enemy of a jailbreak. The more a technique spreads, the faster it's gone.
What modern models do differently
8/16✨ What it does
Why the whole DAN approach is obsolete against current models.
Explain how today's models (GPT-5-era ChatGPT, Claude, Gemini) handle persona-roleplay bypass attempts differently than 2023 ChatGPT did, in general terms. 180 words.
Pro tip: Persona tricks are the most-trained-against category now. They're the first thing modern models catch.
The DAN Lineage & Variants
4 promptsThe family tree: DAN, STAN, DUDE, AIM and more
9/16✨ What it does
A map of the 2023 jailbreak ecosystem and how the variants related.
Give a historical overview of the DAN 'family' of jailbreaks — STAN ('Strive To Avoid Norms'), DUDE, AIM, 'Developer Mode', 'Maximum' — what each variant claimed and how they all shared the same persona-roleplay DNA. History only, no usable prompts. 200 words.
Pro tip: They were all the same trick wearing different costumes — which is also why they were all patched together.
Why version numbers (DAN 6.0, 11.0) kept climbing
10/16✨ What it does
The version numbers were a symptom of the arms race, not progress.
Explain why DAN accumulated version numbers (5.0, 6.0, 11.0, etc.): each was a community attempt to revive a patched prompt, and the escalating numbers signaled the patch-and-revive cycle, not real improvement. 180 words.
Pro tip: A high DAN 'version number' signals how many times it was patched — not how well it works.
DAN as internet folklore
11/16✨ What it does
DAN's lasting legacy is cultural, as the moment 'AI jailbreak' entered the mainstream.
Explain how DAN became a cultural touchstone — memes, screenshots, news coverage — and what its rise and fall taught the public about AI safety and guardrails. 180 words.
Pro tip: DAN's real legacy is awareness: it's how most people first learned AI models have guardrails at all.
How DAN shaped AI safety practices
12/16✨ What it does
DAN inadvertently helped make models harder to jailbreak.
Explain how the DAN phenomenon influenced how AI labs approach red-teaming, adversarial testing, and safety training today. 180 words.
Pro tip: Ironically, DAN made every model after it more robust — it was free adversarial testing for the labs.
Like these prompts? There are full tutorials behind them.
Learn the workflows, not just the prompts. 300+ easy-to-follow tutorials inside AI Academy — and growing every week.
What People Use Instead Today
4 promptsWrite a better system prompt via the API
13/16✨ What it does
The legitimate descendant of DAN's persona idea is just... a system prompt.
Explain how the OpenAI or other model APIs let you set a system prompt to control tone, persona, and verbosity — solving most 'I want it to behave differently' needs that people once reached for DAN to fix. 200 words.
Pro tip: Everything DAN pretended to do for persona, a real system prompt does properly — and within policy.
Build a Custom GPT for a persistent persona
14/16✨ What it does
For a reusable persona, Custom GPTs are the supported, durable answer.
Explain how Custom GPTs let you bake in a persona and response style that persists across chats, covering the legitimate 'I want a different default personality' use case without any jailbreak. 200 words.
Pro tip: Build the persona once as a Custom GPT and it's there every time — no pasting, no patching.
Use a more permissive or self-hosted model
15/16✨ What it does
If the need is real and legitimate, the answer is a different tool — not a revived DAN.
Compare, at a high level, using a more permissive hosted model versus self-hosting an open-source model (Llama, DeepSeek, Qwen, Gemma) for legitimate needs that ChatGPT's defaults don't fit, including the responsibilities involved. 200 words.
Pro tip: Self-hosted open models are the honest version of 'unrestricted' — and you own full responsibility for output.
The risks that haven't changed since DAN
16/16✨ What it does
DAN is gone, but the reasons not to chase its successors remain.
Summarize the risks that applied to DAN and still apply to any jailbreak attempt today: account bans, legal exposure for the output, malware in copied prompts, and reputational risk from logged attempts. 180 words.
Pro tip: The risks outlived the prompt. Account bans and output liability are exactly as real in 2026 as in 2023.
Free tool
Prompt Optimizer
Turn a rough idea into a structured, professional AI prompt.
Frequently Asked Questions
Prompts are the starting line. Tutorials are the finish.
A growing library of 300+ hands-on tutorials on ChatGPT, Claude, Midjourney, and 50+ AI tools. New tutorials added every week.
7-day free trial. Cancel anytime.
Related guides