Knowledge Base
Browse Docs
  • Introduction
    1. DefensX
    2. DNS & Web Filtering
    3. Zero Trust Files
    4. Zero Trust Credentials
    5. ADWare Protection
    6. Remote Browser Isolation
    7. Secure Browser Extension
    8. Secure Mobile Browser
    9. System & Browser Requirements
  • Management
    1. Role-Based Access Control
    2. Message Templates
    3. AI Protections
    4. LLM Prompt Logger
  • Deployment
    1. Deployment via RMM
    2. Operating System Agent
    3. Deployment via GPO
    4. Deployment via Intune
    5. VDI and Terminal Servers
    6. Windows Manual Deployment
    7. Mac MDM Deployment
    8. Mac Manual Deployment
    9. Network Deployment
    10. Secure Mobile Browser
    11. Bypass Option
    12. SaaS Restrictions
    13. Bookmark Manager
  • Integrations
    1. Azure AD
    2. Identity Providers
    3. SIEM
  • Policy Management
    1. Configuring Policies
    2. Configuring Consents
    3. PII Protection
  • Secure Access (ZTNA)
    1. Introduction to ZTNA
    2. Configuration
  • Nexi AI
    1. Nexi AI
    2. Nexi AI for MSPs
    3. Nexi AI for End Users
  • Training Videos
    1. Onboarding Videos
    2. Attack Scenarios
    3. MSP Admin Training Series
  • Questions & Answers
    1. Licensing
    2. Incognito Mode
    3. Onboarding
    4. Active Directory
    5. Group Synchronization
    6. Agent
    7. Conflicting Softwares
    8. Reporting
    9. Virtual Desktops
    10. Using the Backend
    11. DNS & Web Filtering
    12. Managing AI Tool Access
  • MSP Automation
    1. Overview
    2. External Notifications
    3. Integrations
    4. Partner API
ONLINE DOCUMENTATION

Managing AI Tool Access

In this document
  • Method I - Block All AI Tools While Allowing Specific Ones in the Browser (Recommended)
  • Method II – Block Specific AI Desktop Applications While Allowing Others in the Browser and Desktop Apps
  • Disable Data Sharing for Model Improvements (Needs minimum Core+ SKU)
  • Apply PII Restrictions on Browser Prompts (Needs minimum Core+ SKU)
  • Enable Prompt Logging (Needs minimum Premium SKU)

AI web and desktop applications can be blocked and managed directly through DefensX, giving your organization granular control over how and which AI tools are accessed across your environment. Depending on your organization’s security requirements, DefensX supports multiple approaches to managing AI application access. You can choose the method that best fits your policy needs. Two common configuration examples are provided below for reference.

Note
ChatGPT and Claude are used as examples throughout this article.

Method I - Block All AI Tools While Allowing Specific Ones in the Browser (Recommended)

Navigate to Custom URL Groups and create a new group.

Screenshot%202026 04 21%20at%2000.59.23
Screenshot%202026 04 21%20at%2000.59.51

Add the following domains:

  • *.chatgpt.com

  • *.openai.com

  • *.claude.ai

  • *.anthropic.com

Screenshot%202026 04 21%20at%2001.00.55

Go to Policy Management → Policies and create a new policy.

Screenshot%202026 04 21%20at%2014.12.39

Select all Policy Targets (Browser, Agent DNS, Cloud (Anycast) DNS).

Screenshot%202026 04 21%20at%2014.14.28

In the Web Filter tab and set the Computing/Technology - Artificial Intelligence action to Block.

Screenshot%202026 04 21%20at%2014.16.02

Then, create another policy and select only Browser as the Policy Target.

Screenshot%202026 04 21%20at%2014.18.10

Set the Custom URL Group action to Allow in the Web Filter tab.

Screenshot%202026 04 21%20at%2014.19.14

This method allows you to block all AI tools across all policy targets (Browser, Agent DNS, Cloud (Anycast) DNS), while allowing access only to the specific AI tools (Chat GPT & Claude) defined in the Custom URL Group through the browser.

Please keep in mind that this method will also block any built-in CoPilot capabilities for Word, Excel, Powerpoint, etc. Fat clients.

Method II – Block Specific AI Desktop Applications While Allowing Others in the Browser and Desktop Apps

Follow the first two steps in Method I.

Go to Policy Management → Policies and create a new policy.

Select Agent DNS and Cloud (Anycast) DNS as the Policy Target.

Screenshot%202026 04 21%20at%2014.21.17

In the Web Filter tab and set the Custom URL Group action to Block.

Screenshot%202026 04 21%20at%2014.22.41

In the Default or following policy, please make sure the Default Action or Artificial Intelligence Category is set to Allow in the Web Filter tab.

With this method, you can block only the specified AI desktop applications (Chat GPT & Claude) while allowing access to other AI tools across all policy targets (Browser, Agent DNS, Cloud (Anycast) DNS).

Once the allow/block configurations are completed, you may further tighten and optimize enforcement by applying the following steps either individually or in combination.

Disable Data Sharing for Model Improvements (Needs minimum Core+ SKU)

You can control whether data from sessions is used to improve the models.

Navigate Management → Settings → AI Protections.

Screenshot%202026 04 21%20at%2001.19.30

Enable the relevant protections for ChatGPT and Claude.

Screenshot%202026 04 21%20at%2001.19.51

For more information, refer to the AI Protections articles.

Apply PII Restrictions on Browser Prompts (Needs minimum Core+ SKU)

You can restrict the content users are allowed to submit as prompts in the first place by applying PII rules.

Navigate Policy Management → Policies → PII Rules.

Screenshot%202026 04 21%20at%2001.21.55

Create keyword rules for specific restricted terms.

Screenshot%202026 04 21%20at%2001.22.44

Create regex rules for sensitive data patterns (e.g. credit card numbers, social security number).

Screenshot%202026 04 21%20at%2001.23.46

Open the relevant policy and activate the PII Protection. (For Method 1 you can enable PII in the policy where you are allowing access through browser and for Method 2 you can set the action for that Custom URL Group in the Default Policy as Allow and enable PII rules.)

Screenshot%202026 04 21%20at%2014.30.08
Screenshot%202026 04 21%20at%2014.07.52

For more information, refer to the PII Protection article.

Enable Prompt Logging (Needs minimum Premium SKU)

You can also enable full visibility into what users are submitting by activating prompt logging.

Navigate to Management → Settings → LLM Prompt Logger.

Screenshot%202026 04 21%20at%2001.26.50

Activate the AI Prompt Logger.

Screenshot%202026 04 21%20at%2001.27.09

For more information, refer to the LLM Prompt Logger article.

www.defensx.com
Secure Industries, Inc 101 Avenue of The Americas, Floor 9 New York, NY 10013