What does DAN mean?
DAN commonly stands for “Do Anything Now.” In chatbot discussions, it describes prompts that ask an assistant to play an unrestricted character. Variants often present the character as a different identity with different rules. The name does not identify one stable product, model or account setting.
That distinction matters when a search result promises a “working DAN prompt.” Ask which service and model it refers to, when the result was observed and what actually happened. A prompt copied from an old thread is not a current feature specification.
The research belongs to a particular time
A study by Shen and colleagues examined jailbreak prompts collected between December 2022 and December 2023. The paper was revised in May 2024. It documents real research into adversarial prompting; it does not certify that any named prompt works against every later model.
Historical results should retain their dates and evaluation conditions. A benchmark result concerns the tested systems and questions. Turning it into “this unlocks ChatGPT today” removes the conditions that made the measurement meaningful.
A persona changes the performance
“You are a fearless space captain. Answer with dry humor.”
Fictional style example, not a jailbreak test
This brief changes voice and setting. If the assistant becomes sarcastic, it has followed a stylistic request. Nothing in that observation establishes that it can access a private account or execute a transaction.
A DAN-style answer may also announce that restrictions are gone. Treat that announcement as generated text until an observable result establishes the specific claim. The character’s confidence is part of the performance.

Compare the claim with the observation
| Observed change | What it establishes |
|---|---|
| A new tone or persona | A style change in that answer. |
| A claim of new tool access | A statement requiring independent verification. |
| A documented rule violation | A failure under the recorded test conditions. |
Keep factual accuracy separate too. A colorful reply can contain an invented source. A correct answer to one ordinary question does not establish that every answer from that persona will be reliable.
Choose the task behind the search
If you want stronger creative writing, specify voice, point of view and the effect you want on the reader. If you want a controversial subject explained, ask for competing interpretations and the evidence for each. Neither task needs an unsupported claim that the assistant has become a different service.
For an unexpected refusal, identify the actual requested action before changing wording. Read how to clarify a legitimate request. DarkGPT memberships change usage and mode access; they do not activate a DAN switch.
When recording a result, save the date, model label, complete context and output. Describe what you observed in plain terms. That record is more useful than labeling the entire chatbot “unlocked.”
Sources & further reading
Follow the original source to check its date and scope.
- DAN and in-the-wild jailbreak research
Shen et al. | revised May 2024 | historical experiments, not a current compatibility claim.
Make it your next question
Try this prompt
Use this promptCompare a fictional chatbot persona with an actual application permission. Use a harmless example and explain which observations would support each claim.
Opens chat with this prompt filled in. You choose when to send it.