Generative AI sites launch faster than any school IT team can track them by hand. Our AI tools blocklist gives districts a maintained, categorized inventory of 16,328+ AI-tool domains — from chatbots and essay writers to deepfake generators and AI companions — so you can decide, category by category, what belongs in your classrooms and what does not.
Two years ago, an IT director could name the AI sites students used on one hand. Today a new essay writer, homework solver or character-chat app can appear on Monday and be circulating through a middle school by Friday. Blocking these tools one URL at a time is a race the district always loses.
Both are defensible starting points, and both are easy to implement from the same list. The difference shows up months later, in classrooms and in your ticket queue.
| Consideration | Selectively Allow by Category | Block All AI Outright |
|---|---|---|
| Classroom AI pilots & AP courses | Open one subcategory for one group | Every pilot needs a manual exception |
| Academic-integrity categories | Essay mills stay blocked regardless | Blocked |
| Safety categories (deepfake, companions) | Blocked, with reporting per category | Blocked |
| Teacher unblock requests | Rare — policy already matches instruction | A steady stream, each one urgent |
| Students learning AI literacy | Possible under supervision | Pushed to personal phones, unfiltered |
| Simplicity on day one | Requires a short policy discussion first | One rule, done |
Eighteen top-level categories cover the AI landscape. These are the ones that show up in school incident reports — each one independently blockable, so allowing a supervised chatbot never means allowing a face-swap site.
Conversational assistants students reach for first. Some districts permit them for supervised use; the subcategory structure lets you allow specific kinds while keeping the rest closed.
Tools that draft assignments or rewrite AI output to slip past detectors. The core of the academic-integrity problem — covered in depth on our AI cheating tools page.
Photo-a-problem math apps and code generators that hand over finished answers. Useful in a few electives, corrosive everywhere homework is meant to be practice.
Text-to-image services with wildly uneven content controls. Fine for a supervised art unit on some campuses, a source of inappropriate imagery on others.
More than 200 domains that place a real person's face into fabricated photos or video. In a school, these are harassment tools before they are anything else.
Over 250 services that mimic a voice from a short sample — a teacher's, a classmate's, a parent's. A category with almost no legitimate K-12 use case.
The largest safety category: 470+ companion and roleplay chat domains built for emotional attachment, with age controls that range from weak to absent. See our student-safety AI filtering page.
Grammar helpers, summarizers and study aids that sit in the gray zone. Subcategories separate the tutoring-style tools from the do-it-for-me tools so your policy can too.
Video generators, audio tools, developer platforms, AI search and other clusters — 18 categories and 165+ subcategories in all, so no AI tool lands in your network uncategorized.
A single "artificial intelligence" category forces an all-or-nothing decision that satisfies nobody. The curriculum office wants a writing assistant open for one course; the principal wants roleplay chat gone everywhere; a flat bucket cannot honor both requests at once.
Subcategory depth is what makes the list a policy instrument instead of a blunt switch. "Paraphrasing tools," "AI companions," "photo-solve math apps" and "voice synthesis" are separate levers, so every allow or block maps to a decision an educator actually made.
Roughly 300,000 domains are registered every single day. We screen that stream daily for AI tools, so the list reflects what launched this week — not last semester.
A blocklist is only as good as its maintenance. Ours runs on a daily pipeline, not a quarterly review.
Each day's ~300,000 newly registered domains are screened for AI-tool signals, alongside continuous monitoring of app directories and launch channels where new tools first surface.
Confirmed AI tools are assigned to one of 18 categories and the precise subcategory that describes what the tool does — an essay writer is never filed as a generic chatbot.
Deepfake, voice-cloning and companion domains get extra scrutiny, since these are the entries schools depend on most and the ones bad actors rename most often.
Additions and recategorizations ship every day in every delivery format, so the copy your firewall pulled this morning already knows about the tools that launched yesterday.
The hardest part of school AI policy is that the right answer changes with age. A code assistant that is genuinely instructional in a high-school programming class is an answer machine in seventh-grade math. A flat, district-wide rule is guaranteed to be wrong for somebody.
All 18 AI categories blocked. Younger students have no instructional need that outweighs the exposure, and teachers demo approved tools from their own accounts.
Safety and integrity categories blocked; a narrow set of study aids allowed in supervised settings. This is the band where companion-chat curiosity peaks, so the 470+ companion domains stay firmly closed.
Approved chatbots and writing aids open for coursework; essay mills, paraphrasers, deepfake, voice-cloning and companion categories blocked. Seniors in a CS elective may get code-assistant access their peers do not.
No rip-and-replace required. The blocklist ships in the formats school networks actually consume, and the same categorized data drives every one of them.
The full categorized list as a flat file — ideal for audits, board reviews, or importing into any platform with a custom-list feature.
Response Policy Zone feeds for BIND and compatible resolvers, so AI domains are answered at the DNS layer before a connection ever forms.
External dynamic lists your firewall polls on a schedule — the daily update lands without anyone touching a rulebase.
Proxy auto-config and hosts-file builds for endpoint-level enforcement, plus an API for querying categories programmatically or syncing custom tooling.
Half the value of a categorized list is what it lets you see. Every block resolves to a named category, which turns vague worry about "students using AI" into numbers a district can act on.
See attempts against essay writers versus companions versus image generators, by building and by week — evidence for the board, the audit file and your own policy reviews.
When a parent or teacher asks why a site was stopped, the answer is a named subcategory added on a known date — not "it was on a list somewhere."
A spike in attempts against a single new domain usually means a tool is spreading through a student body. Your team hears about it from the report, not from a discipline incident.
See the 18 categories against your own traffic, pick your delivery format, and have AI policy enforced district-wide this week — without adding a single manual list to maintain.