AI Tools Blocklist
Home AI Tools Database Taxonomy Pricing
Solutions
Enterprise IT & CISO Education Firewall Admins Shadow AI Prevention REST API Customer Login
Download Free Sample
Security Risk Categories

High-Risk AI Tools Blocklist

Our 18-category taxonomy tells you what an AI tool does. The security risk layer tells you what it puts at risk — classifying AI destinations by data sovereignty, abusive purpose, and whether they train on the data your users submit. Because a model is not a domain, we classify what can actually be enforced at the firewall and DNS layer: the destination.

See Risk Categories Pricing
20,183+AI Domains Screened
4Risk Categories
DailyRe-Scan Cadence
Two Classification Axes

Purpose Tells You What It Does.
Risk Tells You What It Costs You.

“AI tool” is not a risk verdict — Canva is an AI tool, and so is an uncensored chatbot that trains on every prompt. Functional categories answer policy questions like “should designers use image generators?”. Risk categories answer security questions like “which of the 20,183+ AI destinations on our network sends data somewhere we cannot accept?”. You need both axes to write a defensible AI policy.

Axis 1 — Function

18 Functional Categories

Text & Language, Image & Visual, Code & Development, Agents & Automation, and 14 more — with subcategories for granular acceptable-use policies. Included with every plan. Browse the taxonomy →

Axis 2 — Security Risk

4 Risk Categories

An overlay on the same domain inventory, flagging destinations by data-sovereignty exposure, abusive purpose, and train-on-your-data terms — so you can block by risk posture without blocking your users’ sanctioned tools.

The Risk Categories

Four Ways an AI Destination Becomes a Liability

Data Sovereignty Risk

AI services whose ownership, hosting, or legal jurisdiction places submitted data under foreign data-access laws that many organizations — and a growing number of regulators and state bans — cannot accept.

  • Corporate ownership & jurisdiction analysis
  • Hosting-infrastructure geolocation
  • Privacy-policy data-transfer clauses
Included

Abusive-Purpose AI

Destinations whose advertised purpose is abuse: deepfake and “nudify” generators, uncensored / jailbroken chatbots, voice-cloning for impersonation, and AI tooling marketed for phishing and fraud.

  • Classified from the site’s own marketing & features
  • Continuously discovered by the daily pipeline
  • Recommended block for every organization
Included

NSFW & Adult AI

AI porn generators, adult chatbots and explicit “AI companion” platforms built for fictional adult content. Distinct from abusive-purpose AI — no real person is targeted — but unambiguously unsuitable for schools and most workplaces, and one of the fastest-growing corners of the AI web.

  • Separate flag — filter independently of abuse
  • Essential for K-12, CIPA & workplace policy
  • Continuously discovered by the daily pipeline
Included

Trains on Your Data

Tools whose consumer or free tiers use submitted content for model training under their own Terms of Service — the classic shadow-AI leak channel: an employee pastes source code or client records into a free chatbot, and it becomes training data.

  • ToS & privacy-policy clause extraction
  • Training-use, retention & opt-out terms
  • Re-checked as vendors change their terms
Included
Methodology

How We Classify Risk at Scale

A model is not observable from outside a website — but a service’s legal terms, ownership, hosting, and advertised purpose are. Our risk layer is built from those observable signals, across the same 20,183+ domain inventory that powers the functional taxonomy.

1

Policy Document Retrieval

Automated collection of Terms of Service, privacy policies, and data-processing addenda for every AI destination in the inventory.

2

LLM Clause Analysis

Large-language-model extraction of the clauses that matter: training-use rights, retention, data transfers, jurisdiction, and opt-out mechanics — normalized into structured risk attributes.

3

Ownership & Hosting Enrichment

Corporate registration, parent-company jurisdiction, and hosting-infrastructure signals combined into the data-sovereignty assessment.

4

Review & Continuous Re-Scan

High-impact flags are human-reviewed before release, and the pipeline re-checks terms on an ongoing basis — a vendor’s ToS change can move a domain in or out of a risk category.

Delivery

Risk Cuts in Your Filter’s Native Format

Each risk category is delivered as a separate feed cut, in the same hosted-endpoint formats as the main blocklist — point your firewall or DNS filter at a stable URL and updates flow automatically.

EDLPalo Alto, Fortinet & compatible External Dynamic Lists
SonicWallDynamic External Address Group / Botnet List plain FQDN feed
DNSFilterImport bundle pre-chunked to the 2,000-domain CSV cap
hosts / PAC / CSV / JSONPlus REST API on Professional and above
Recommended deployment: most organizations get the strongest posture from block-all-AI by default, allowlist sanctioned tools per policy — with the full 20,183+ domain list as the default-deny base. Risk categories are for the selective case: keeping approved AI usable while guaranteeing that abusive, sovereignty-risk, or train-on-your-data destinations stay blocked — including inside your allowlist review process.
Availability

Get the Risk Categories

All three risk categories are delivered as an add-on to the Professional plan and included in OEM & Enterprise licensing, in every hosted-endpoint format above. MSPs: multi-tenant terms are available — tell us your fleet size.

Request Risk Category Access

Tell us which risk categories you need (sovereignty, abusive-purpose, trains-on-data), your filtering stack (firewall, DNS filter, proxy), and how many sites or endpoints you cover.