June 12, 2026
Blocking AI tools without blocking productivity
Board memos now demand "no unsanctioned AI." Engineering still needs copilots, researchers need literature tools, and marketing wants copy assistants. A blunt domain block list creates shadow IT within a week. The workable pattern is category policy with explicit allow paths and a review queue users actually use.
Start with UT1, not a spreadsheet
ClearScreen maps consumer LLM and AI chat domains into UT1 content categories you can block on the Customer Environment policy. Keep the AI category on by default, then put sanctioned assistants on the tenant allowlist so they resolve while consumer chat stays blocked. Allowlists override category blocks — document each entry with owner and review date so ISO 27001 A.5.32 and internal AI governance align.
Make the block page part of the workflow
When policy blocks chat.openai.com or a niche research assistant, the user should see the domain, category, and source feed on a local block page — not a generic browser error. One-click false-positive review sends the request to operators with device context. That loop keeps helpdesk tickets down and gives you audit evidence that enforcement was visible and appealable.
Sanctioned vs unsanctioned
Publish an internal register of approved AI services with data classification rules. Block the UT1 AI category everywhere by default, then allowlist only registered tools. For Microsoft 365 Copilot or Google Gemini Enterprise, allowlist the tenant-specific endpoints — public consumer variants stay blocked. Revisit the list quarterly; new model hosts appear weekly.
Metrics that matter to the CISO
Track blocks per category, top appealed domains, and time-to-decision on reviews. Spikes in AI-category blocks after a product launch mean communications failed, not that policy failed. Persistent appeals for one domain mean your allowlist is stale. Export block events as CSV or JSON for the AI governance committee — DORA and NIS2 reviewers increasingly ask for demonstrable control over third-party AI data flows.
Legal and works-council alignment
Blocking AI tools touches employee monitoring and acceptable-use policy, not only security architecture. Document that DNS enforcement is domain-level, not content inspection, and that review requests are voluntary escalation paths. In EU entities subject to works-council consultation, bring the block page screenshot and appeal workflow before wide rollout — transparency on what is logged (domain, timestamp, device ID) prevents the programme from stalling when Copilot is blocked but Gemini Enterprise is allowed for one division.
Model fleet sizing and review load with the block page incident calculator before you widen the pilot.