The AI Tools Blocklist classifies 20,361+ AI-tool domains across 18 functional categories with 4 risk flags. 300,000 newly registered domains screened every day. Delivered in 7 formats: REST API, CSV, JSON, EDL, DNS RPZ, PAC and Hosts file.
Daily-updated AI governance
Classify, flag and control every AI tool your workforce can reach. 18 categories, 165 subcategories and 4 risk dimensions delivered in firewall-ready formats.
Explore platformDozens of new AI tools launch every single day. Employees adopt them without IT approval, and every prompt typed into an unvetted chatbot is a potential data-loss event. Static blocklists decay within hours, and compliance frameworks now require documented AI governance controls.
Employees discover and start using AI tools before IT even knows the tools exist. A marketing team member pastes customer data into an AI writing assistant. A developer routes proprietary code through a code-completion tool that trains on input. Without a classified inventory of 20,361+ AI-tool domains, security teams are responding to incidents they cannot detect in advance.
AI chatbots, image generators and code assistants ingest the text you type. Some retain prompts for model training. Others store conversations on servers outside your data-sovereignty jurisdiction. The AI Tools Blocklist flags each domain with one of four risk dimensions: trains on user data, data sovereignty concerns, NSFW and adult AI content, or deepfake and abusive generation capabilities.
A manually curated list of AI tools becomes incomplete within 48 hours. The AI Tools Blocklist screens 300,000 newly registered domains every day against its classification engine, adding new AI tools as they appear. This is not a quarterly update cycle. The discovery pipeline runs daily and the database reflects the current AI landscape, not last month's snapshot.
Cyber-insurance questionnaires now include questions about AI tool controls. SOC 2 auditors ask for documented governance policies. Regulatory frameworks from NIST AI RMF to the EU AI Act require organizations to demonstrate visibility into the AI tools their workforce uses. A classified, daily-updated blocklist is auditable evidence that controls exist.
Every domain in the AI Tools Blocklist is tagged with a functional category, one or more of 4 risk flags, a severity level, and the vendor or product name. The grid below shows real entries from the database. Organizations use these fields to build graduated policies: block high-risk tools, monitor medium-risk, allow approved low-risk.
The AI Tools Blocklist ships in the format your infrastructure already consumes. No transformation scripts, no manual imports. Point your firewall, DNS resolver or endpoint agent at the feed URL and set a cron schedule. Updates flow automatically.
Query any domain against the full 20,361+ database in real time. Returns category, subcategory, risk flags, severity and vendor in a structured JSON response. 10M lookups per month on the Essentials plan. Integrate into SIEM, SOAR or custom policy engines with a single endpoint.
Download the complete classified database as a flat CSV or structured JSON file. Professional plan includes daily updates. Import into spreadsheets, data warehouses, threat intelligence platforms or custom applications. Each record includes the domain, category, subcategory, risk flags and vendor metadata.
Subscribe to hosted feed URLs that update automatically. No manual downloads required. Point your gateway, proxy or DNS resolver at the feed URL and configure a refresh interval. Hosted feeds support filtering by category, risk flag and severity level so you pull only the domains your policy requires.
External Dynamic List formatted for Palo Alto NGFW. Import the EDL URL into your security policy as a block list, allow list or monitor list. Supports PAN-OS URL filtering and DNS Security categories. One feed URL, one security rule, automatic daily refresh via the firewall's built-in EDL polling.
Threat feed formatted for FortiGate external connectors. Add the feed as an External Block List under Security Fabric. Apply to web filter profiles, DNS filter profiles or firewall policies. Compatible with FortiOS 6.x and 7.x. Each domain entry includes the AI category for granular policy decisions.
Response Policy Zone file formatted for BIND, Unbound, PowerDNS and Knot Resolver. Deploy as a local RPZ zone that intercepts DNS queries for classified AI-tool domains. Returns NXDOMAIN, NODATA or a redirect depending on your policy. The RPZ file updates daily and includes the full 20,361+ domain set.
Proxy Auto-Configuration file that routes AI-tool domains through your web proxy or blocks them directly at the browser level. Distribute via Group Policy Object for Windows endpoints. The PAC file uses the classified domain list to make per-request routing decisions without installing endpoint agents.
Standard hosts file mapping classified AI-tool domains to 0.0.0.0 or 127.0.0.1. Deploy on endpoints, servers or development machines where firewall-level blocking is not available. Compatible with Windows, macOS and Linux. Update via scheduled task or configuration management tool like Ansible, Puppet or Chef.
Pre-formatted feeds compatible with SonicWall Content Filtering Service and DNSFilter domain lists. Upload directly into the management console or subscribe to the hosted feed URL for automatic updates. Includes all 20,361+ classified AI-tool domains with category metadata for policy-level filtering decisions.
The AI Tools Blocklist does not rely on manual curation. An automated pipeline screens 300,000 newly registered domains daily, classifies confirmed AI tools into 18 categories and 165 subcategories, and assigns risk flags based on data handling, content generation and sovereignty characteristics.
AI Chatbots, AI Code Assistants, AI Image Generators, AI Video Generators, AI Audio and Music, AI Writing and Content, AI Search Engines, AI Data Analytics, AI Presentation Tools, AI Translation, AI Transcription, AI Design Tools, AI Automation, AI Agents, AI Research, AI Education and Tutoring, AI Paraphrasers and Humanizers, AI NSFW. Each splits into 165 subcategories for fine-grained policy control.
Full taxonomyEvery 24 hours the pipeline ingests 300,000 newly registered domains from certificate transparency logs, DNS zone files, and registration feeds. Each domain is analyzed for AI-tool indicators: landing page content, API documentation, SDK references, model endpoints and AI-related metadata. Confirmed AI tools enter the classified database within one update cycle.
Discovery processEach classified domain carries one or more of four risk flags. Trains on Data marks tools that use customer prompts for model training. Data Sovereignty flags tools hosted in jurisdictions with weaker data-protection laws. NSFW and Adult AI identifies tools capable of generating explicit content. Deepfake and Abusive marks tools with face-swap, voice-clone or synthetic media capabilities.
Shadow AI is the use of unapproved AI tools by employees without IT knowledge or consent. The blocklist enables security teams to detect shadow AI usage by integrating the classified domain list into web proxy logs, DNS query logs and SIEM event streams. Compare employee traffic against the 20,361+ classified domains to surface unauthorized AI tool adoption in real time.
K-12 school districts and higher education institutions use the blocklist to enforce CIPA and FERPA compliance around AI tools. Block essay-writing AI, tutoring chatbots, paraphrasing tools and humanizer services that undermine academic integrity. The education-focused subcategories separate legitimate research tools from academic misconduct enablers.
Education use caseDNS filtering vendors, secure web gateway providers and managed security service providers license the AI Tools Blocklist for redistribution. Add an AI filtering category to your product without building your own discovery and classification pipeline. White-label licensing includes daily feed updates, STIX and TAXII delivery, and contractual SLA for data freshness and coverage.
From enterprise security operations centers to K-12 school district firewalls, the same classified database powers different content moderation workflows depending on the sector, the compliance framework, and the policy architecture.
CISOs integrate the AI Tools Blocklist into secure web gateways and CASBs to enforce AI usage policies across the organization. Block high-risk tools that train on user data, monitor medium-risk tools for usage patterns, and allow approved tools through exception lists. The daily update cycle ensures new AI tools are classified before employees discover them. Compliance evidence for SOC 2 auditors and cyber-insurance questionnaires.
School districts deploy the blocklist on Palo Alto, Fortinet or DNS-level firewalls to block AI essay writers, tutoring chatbots, paraphrasers and humanizer tools. CIPA compliance requires content filtering on school networks, and AI tools are the fastest-growing category of blocked content. The subcategory taxonomy separates educational AI from academic misconduct tools, allowing districts to permit approved AI while blocking integrity risks.
Banks, hedge funds and insurance companies face regulatory scrutiny around AI tool usage. Trading desk personnel using unvetted AI chatbots risk data leakage of material non-public information. The AI Tools Blocklist feeds into existing DLP and web-filtering stacks. The data sovereignty risk flag identifies tools that route data through jurisdictions outside the firm's regulatory framework.
Clinical settings require strict controls on AI tools that may process patient data. HIPAA compliance demands that protected health information never reaches an external AI service without a Business Associate Agreement. The blocklist enables healthcare IT teams to block all AI chatbots and image generators by default, then selectively allow approved tools through a clinical AI governance committee.
Federal, state and local government agencies must comply with AI governance executive orders and agency-specific policies. The AI Tools Blocklist provides a classified inventory of AI tools that government IT teams deploy through their existing web-filtering infrastructure. STIX and TAXII delivery formats integrate directly into government threat intelligence platforms for automated policy enforcement.
DNS filtering providers and secure web gateway vendors license the AI Tools Blocklist to add an AI tool category to their product without building a discovery pipeline. White-label redistribution rights include daily feed updates, full taxonomy access and contractual SLA guarantees. One integration adds 20,361+ classified AI-tool domains to your customers' filtering capabilities.
The discovery-to-enforcement pipeline runs automatically every day. No manual domain lists, no stale spreadsheets, no weekly review meetings.
The AI Tools Blocklist classifies AI-specific domains. The Website Categorization API provides web content filtering across 58 categories and 700+ IAB categories. The AI Agent Allowlist governs where autonomous AI agents can browse and act.
Daily discovery, daily classification, daily delivery. The infrastructure runs continuously so your security policies never fall behind the AI landscape.
Get 500 classified AI-tool domains with full category, subcategory, risk flag and vendor metadata. No credit card required. Evaluate the taxonomy, test the format against your firewall or DNS resolver, and see the classification depth before committing to a plan.