AI Governance for K-12

AI Tools Blocklist for Schools

Generative AI sites launch faster than any school IT team can track them by hand. Our AI tools blocklist gives districts a maintained, categorized inventory of 16,328+ AI-tool domains — from chatbots and essay writers to deepfake generators and AI companions — so you can decide, category by category, what belongs in your classrooms and what does not.

16,328+AI-Tool Domains
18AI Categories
165+Subcategories
DailyUpdates
CIPA-Aligned Coverage
Daily Refreshes
18 Categories
CSV, DNS, EDL, PAC, API
Per-Group Policies
The difference

What changes when AI blocking is in place

Two years ago, an IT director could name the AI sites students used on one hand. Today a new essay writer, homework solver or character-chat app can appear on Monday and be circulating through a middle school by Friday. Blocking these tools one URL at a time is a race the district always loses.

Without AI Blocking

  • Staff discover new AI tools only after students are already using them
  • Blocking one URL at a time — a race the district always loses
  • No visibility into which AI categories students are accessing
  • Student data pasted into ungoverned AI tools is gone for good
  • Essay writers, paraphrasers and solvers undermine academic integrity
  • Deepfake, voice-cloning and companion tools enable harassment
  • AI image generators with weak guardrails can produce harmful content on demand
  • Every AI pilot requires a manual exception — a steady stream of urgent tickets

With AI Blocking

  • Continuously maintained dataset: every known AI-tool domain, sorted into 18 categories and 165+ subcategories, refreshed every day
  • Team shifts from hunting domains to making policy — deciding which categories serve instruction
  • Category-level reporting turns vague worry into numbers a district can act on
  • Blocking un-reviewed AI categories at the moment of the paste, not after the harm
  • Essay mills stay blocked regardless while AI pilots run smoothly
  • Deepfake and face-swap is a standing category, refreshed daily, blocked district-wide
  • Explainable blocks: a named subcategory added on a known date for every block
  • Open one subcategory for one group without manual exceptions
The policy fork

Block all AI, or selectively allow?

Both are defensible starting points, and both are easy to implement from the same list. The difference shows up months later, in classrooms and in your ticket queue.

Consideration Selectively Allow by Category Block All AI Outright
Classroom AI pilots & AP courses Open one subcategory for one group Every pilot needs a manual exception
Academic-integrity categories Essay mills stay blocked regardless Blocked
Safety categories (deepfake, companions) Blocked, with reporting per category Blocked
Teacher unblock requests Rare — policy already matches instruction A steady stream, each one urgent
Students learning AI literacy Possible under supervision Pushed to personal phones, unfiltered
Simplicity on day one Requires a short policy discussion first One rule, done
Many districts start with block-all in September and move to selective allowance by spring, once the curriculum office decides where AI belongs. Because the same 18-category structure supports both, that migration is a policy edit — not a new procurement.
What's inside

The AI categories a K-12 policy actually needs

Eighteen top-level categories cover the AI landscape. These are the ones that show up in school incident reports — each one independently blockable, so allowing a supervised chatbot never means allowing a face-swap site.

General Chatbots

Conversational assistants students reach for first. Some districts permit them for supervised use; the subcategory structure lets you allow specific kinds while keeping the rest closed.

Essay Writers & Paraphrasers

Tools that draft assignments or rewrite AI output to slip past detectors. The core of the academic-integrity problem — covered in depth on our AI cheating tools page.

Homework & Code Solvers

Photo-a-problem math apps and code generators that hand over finished answers. Useful in a few electives, corrosive everywhere homework is meant to be practice.

Image Generators

Text-to-image services with wildly uneven content controls. Fine for a supervised art unit on some campuses, a source of inappropriate imagery on others.

Deepfake & Face-Swap (200+)

More than 200 domains that place a real person's face into fabricated photos or video. In a school, these are harassment tools before they are anything else.

Voice Cloning (250+)

Over 250 services that mimic a voice from a short sample — a teacher's, a classmate's, a parent's. A category with almost no legitimate K-12 use case.

AI Companions & Character Chat (470+)

The largest safety category: 470+ companion and roleplay chat domains built for emotional attachment, with age controls that range from weak to absent. See our student-safety AI filtering page.

Writing & Productivity Aids

Grammar helpers, summarizers and study aids that sit in the gray zone. Subcategories separate the tutoring-style tools from the do-it-for-me tools so your policy can too.

…and Ten More Categories

Video generators, audio tools, developer platforms, AI search and other clusters — 18 categories and 165+ subcategories in all, so no AI tool lands in your network uncategorized.

One List, Four Policy Conversations

Filtering AI is not a verdict against the technology. Plenty of districts run supervised AI pilots and still block the majority of these domains, because four distinct risks sit behind unmanaged access — and only one of them is about cheating.

The quietest risk is data. When a student pastes an essay about their family, their health or their address into a random AI site, that text leaves the district's control entirely, landing with an operator who never signed a student-data agreement. No acceptable-use policy retrieves it afterward.

Board asks: "Are the face-swap sites from the news blocked here?"
Yes — deepfake and face-swap is a standing category, refreshed daily, blocked district-wide.

Why districts filter AI at all

A single "artificial intelligence" category forces an all-or-nothing decision that satisfies nobody. The curriculum office wants a writing assistant open for one course; the principal wants roleplay chat gone everywhere; a flat bucket cannot honor both requests at once.

Subcategory depth is what makes the list a policy instrument instead of a blunt switch. "Paraphrasing tools," "AI companions," "photo-solve math apps" and "voice synthesis" are separate levers, so every allow or block maps to a decision an educator actually made.

Kept current, every day

Built from the firehose of new domain registrations

Roughly 300,000 domains are registered every single day. We screen that stream daily for AI tools, so the list reflects what launched this week — not last semester.

~300kNew Domains Screened Daily
16,328+AI-Tool Domains Listed
165+Subcategories for Precision
24hUpdate Cycle
Behind the list

How the blocklist stays ahead of new AI tools

A blocklist is only as good as its maintenance. Ours runs on a daily pipeline, not a quarterly review.

1

Screen New Registrations

Each day's ~300,000 newly registered domains are screened for AI-tool signals, alongside continuous monitoring of app directories and launch channels where new tools first surface.

2

Classify Into Categories

Confirmed AI tools are assigned to one of 18 categories and the precise subcategory that describes what the tool does — an essay writer is never filed as a generic chatbot.

3

Review High-Risk Entries

Deepfake, voice-cloning and companion domains get extra scrutiny, since these are the entries schools depend on most and the ones bad actors rename most often.

4

Publish Daily Update

Additions and recategorizations ship every day in every delivery format, so the copy your firewall pulled this morning already knows about the tools that launched yesterday.

Age-appropriate rules

One list, different rules for a nine-year-old and a senior

The hardest part of school AI policy is that the right answer changes with age. A code assistant that is genuinely instructional in a high-school programming class is an answer machine in seventh-grade math. A flat, district-wide rule is guaranteed to be wrong for somebody.

Elementary (K-5)

All 18 AI categories blocked. Younger students have no instructional need that outweighs the exposure, and teachers demo approved tools from their own accounts.

Middle School (6-8)

Safety and integrity categories blocked; a narrow set of study aids allowed in supervised settings. This is the band where companion-chat curiosity peaks, so the 470+ companion domains stay firmly closed.

High School (9-12)

Approved chatbots and writing aids open for coursework; essay mills, paraphrasers, deepfake, voice-cloning and companion categories blocked. Seniors in a CS elective may get code-assistant access their peers do not.

  • Apply categories per grade band, building or user group
  • Grant course-level exceptions without opening a category district-wide
  • Tighten or relax a band's posture in one policy edit as your AI stance matures
Because every domain on the list carries a category and subcategory, the same dataset can enforce three different postures across three grade bands without anyone maintaining three lists. The policy layer decides; the blocklist just keeps the map of the AI landscape accurate underneath it.
Deployment

Formats that fit the stack you already run

No rip-and-replace required. The blocklist ships in the formats school networks actually consume, and the same categorized data drives every one of them.

CSV

The full categorized list as a flat file — ideal for audits, board reviews, or importing into any platform with a custom-list feature.

DNS Blocklist / RPZ

Response Policy Zone feeds for BIND and compatible resolvers, so AI domains are answered at the DNS layer before a connection ever forms.

EDL for Firewalls

External dynamic lists your firewall polls on a schedule — the daily update lands without anyone touching a rulebase.

PAC / Hosts & API

Proxy auto-config and hosts-file builds for endpoint-level enforcement, plus an API for querying categories programmatically or syncing custom tooling.

Districts running 1:1 programs typically pair the DNS or PAC delivery with device-level policy so the list follows Chromebooks home — our Chromebook & 1:1 device filtering page covers that setup, and our malware & phishing protection page shows the same delivery pipes carrying security categories.
Beyond blocking

Visibility your board and auditors will actually ask for

Half the value of a categorized list is what it lets you see. Every block resolves to a named category, which turns vague worry about "students using AI" into numbers a district can act on.

Category-Level Reporting

See attempts against essay writers versus companions versus image generators, by building and by week — evidence for the board, the audit file and your own policy reviews.

Explainable Blocks

When a parent or teacher asks why a site was stopped, the answer is a named subcategory added on a known date — not "it was on a list somewhere."

Early Warning

A spike in attempts against a single new domain usually means a tool is spreading through a student body. Your team hears about it from the report, not from a discipline incident.

Compliance

Where AI filtering meets CIPA, E-Rate and student data

CIPA & E-Rate Obligations

  • CIPA obligates E-Rate-funded schools to run a technology protection measure against obscene material, child sexual abuse material and content harmful to minors, and to monitor minors' online activity
  • Generative AI complicates that certification in a way static websites never did: an image generator with weak guardrails can produce harmful-to-minors content on demand, on a domain no traditional category list has flagged
  • A categorized AI tools blocklist turns that question into a records exercise — show which AI categories are blocked, when each domain was added, and that the list updates daily
  • The same explainable, category-level evidence you already produce for adult content and gambling — our plain-English CIPA guide walks through the full obligation

Student-Data Privacy

  • Student-data laws and district DPAs assume the district knows where student information flows
  • Ungoverned AI tools break that assumption silently: a thirteen-year-old pasting a personal narrative into a free chatbot has just exported student data to a vendor nobody vetted
  • Blocking un-reviewed AI categories is currently the only enforcement mechanism that operates at the moment of the paste, rather than after the harm
  • Districts that put the blocklist in place before writing their formal AI policy consistently report the easier rollout, because enforcement questions are already answered by the time the committee meets
None of this requires hostility to AI. It requires the same posture districts already take toward every other classroom technology: reviewed tools in, unreviewed tools out, and a list that keeps up with the pace at which "out" multiplies.
Precision

Why 165+ subcategories, not one big "AI" bucket

A single "artificial intelligence" category forces an all-or-nothing decision that satisfies nobody. The curriculum office wants a writing assistant open for one course; the principal wants roleplay chat gone everywhere; a flat bucket cannot honor both requests at once.
When your acceptable-use policy names a practice, there is a subcategory that enforces it. "Paraphrasing tools," "AI companions," "photo-solve math apps" and "voice synthesis" are separate levers, so every allow or block maps to a decision an educator actually made.
The blocklist is bundled with our web filtering software for schools, but it also stands on its own. Districts plug it into the firewalls, DNS resolvers and filtering platforms they already run, in whichever format their stack prefers.
Policies apply per user group, so staff can be exempted from student-facing rules entirely or given a wider allowance. Most districts block student access to unreviewed categories while leaving teacher accounts open to approved tools, then revisit each term as the curriculum office approves more.
Questions

AI blocklist questions we hear from districts

How many AI tools does the blocklist actually cover?
The list currently tracks 16,328+ AI-tool domains, organized into 18 categories and more than 165 subcategories. Coverage grows daily because we screen roughly 300,000 newly registered domains every day for AI-tool signals. The subcategory depth is what makes selective policies possible — you block "essay writers," not just "AI."
Can we allow ChatGPT-style chatbots but block essay-writing sites?
Yes — that is the most common configuration we see. General chatbots and essay writers are separate categories, so a district can permit supervised chatbot access for certain grade bands while keeping essay mills, paraphrasers and homework solvers blocked for everyone. The academic-integrity page covers how districts draw that line.
What formats can we deploy it in?
CSV for import and audit, DNS blocklist/RPZ for resolvers, EDL for firewalls that poll external lists, PAC and hosts files for endpoint enforcement, and an API for custom integrations. All formats carry the same daily-updated data, so mixing them — RPZ on campus, PAC on take-home devices — keeps policy consistent.
How fast do brand-new AI tools get added?
New domain registrations are screened daily, and confirmed tools ship in the next daily update — typically within a day or two of a tool becoming reachable. That matters most for the high-churn categories like deepfake and companion chat, where operators launch replacement domains quickly after takedowns or press attention.
Does this replace our web filter?
No, it extends it. Your general filter handles the broad web — adult content, gambling, malware — while the AI blocklist adds depth in the one area growing too fast for general categorization. It comes bundled with our school web filtering, or plugs into whatever filtering, DNS or firewall stack you already run.
Will blocking AI categories interfere with teachers using AI?
Policies apply per user group, so staff can be exempted from student-facing rules entirely or given a wider allowance. Most districts block student access to unreviewed categories while leaving teacher accounts open to approved tools, then revisit each term as the curriculum office approves more.
What happens when a blocked tool gets approved for classroom use?
You move it, you don't fight the list. An allow rule for that domain or subcategory takes precedence for the groups you choose, while the daily updates keep flowing underneath. Districts usually route approvals through their existing instructional-technology review, then reflect the decision as a one-line policy change.
Is an AI blocklist required for CIPA compliance?
CIPA does not name AI tools specifically — it requires blocking obscene material, child sexual abuse material and content harmful to minors, plus monitoring and student education. But AI image and companion sites can generate exactly the content those rules target, so districts increasingly treat AI coverage as part of demonstrating their filter works as certified. It strengthens the compliance story rather than being a separate mandate.

Put a maintained AI blocklist behind your policy

See the 18 categories against your own traffic, pick your delivery format, and have AI policy enforced district-wide this week — without adding a single manual list to maintain.

Talk to Us See Pricing