Endpoint + browser enforcement
How to block ChatGPT and unsanctioned AI tools for employees
Blocking AI at the firewall misses anyone on a personal account or off the network. ShadowLock blocks ChatGPT, Gemini, Claude, Copilot, and the long tail of AI tools at the endpoint and browser - so the block holds everywhere, and you can still allow the AI you approve.
Free 14-day trial.
Definition
How do you block ChatGPT for employees?
You block ChatGPT for employees by enforcing it on the endpoint and browser rather than only at the network. ShadowLock force-installs a managed browser extension via Chrome and Edge policy and runs a Windows agent that disables the desktop app, so ChatGPT is blocked on a corporate account, a personal account, on-network, or at home. From there you allow the AI you approve, block the rest, and optionally block sensitive pastes into the tools you do allow.
Step by step
How to block AI tools at work, step by step
Five steps, in the order they actually happen. Most teams get from nothing to enforced in an afternoon.
Find out what is already in use
Blocking without an inventory produces a helpdesk queue. Start by discovering which AI sites, desktop apps, browser extensions, and Microsoft 365 AI integrations employees already use, and how much of that is on personal rather than corporate accounts.
Decide what stays allowed
Pick the AI tools you sanction, usually one enterprise assistant plus anything a specific team genuinely needs. Everything outside that list becomes blocked or audit-only. Having an approved option is what stops a block turning into a workaround on a personal phone.
Enforce in the browser
Force-install a managed extension through Chrome and Edge enterprise policy so users cannot remove it. It blocks the AI sites you chose, and on the sites you allow it still inspects what is pasted or uploaded and stops sensitive content from being submitted.
Enforce on the desktop
A Windows agent handles what the browser cannot see: the ChatGPT and Copilot desktop applications, local AI clients, and the clipboard. Desktop AI apps are blocked with NTFS permissions, so the block survives a reinstall attempt by a standard user.
Keep the evidence
Log every block and every sensitive-data detection per user and per device. This is the part auditors and cyber-insurance renewals now ask for, and it is what tells you whether the policy is too tight, too loose, or being routed around.
Running this for more than one company? The same policy set cascades across tenants for MSPs managing AI across customer environments, so a baseline written once applies everywhere and can be overridden per client.
of shadow AI use happens on personal accounts, which network-layer blocking can’t see.
Why a firewall rule isn’t enough
DNS filters and firewalls block AI domains for managed devices on the corporate network. Employees route around them with a personal account, a phone hotspot, or a home laptop - and embedded AI like Gemini in Chrome or Copilot in Edge never touches a blockable domain at all.
ShadowLock enforces at the layers where the work actually happens: the browser and the Windows endpoint. See how it compares to DNS filtering and Microsoft Purview, or read about browser AI lockdown.
Coverage
Block the tools, not just the URLs.
ChatGPT first, then every other AI tool - across browser and desktop.
Block ChatGPT
The most-used shadow AI tool, and the one employees reach for first. ShadowLock blocks ChatGPT in any browser via the managed extension and disables the desktop app on Windows via NTFS ACLs - regardless of whether someone is signed in with a corporate or personal account. You can block it outright or allow it while blocking sensitive pastes.
Block Gemini & Google AI Mode
Gemini is built into Chrome and Google Workspace, and AI Mode now appears in Google Search. Browser AI Lockdown disables Gemini in Chrome by enterprise policy and blocks Google's AI Mode in search, so "block ChatGPT" doesn't just push everyone to the AI already in their browser.
Block Claude, Copilot & Perplexity
Claude, Microsoft Copilot, Perplexity, and the long tail of niche tools are all covered by the same catalogue, updated continuously. Copilot in Edge and Leo in Brave are disabled at the browser layer; standalone tools are blocked by URL and by desktop binary.
Allow the AI you approve, block the rest
Most teams don't want a total ban - they want sanctioned tools allowed and everything else blocked. Set an allow-list of approved AI tools at the partner, org, or device level; everything outside it is blocked or audited per policy. The block page is customizable so employees know what to use instead.
Scenarios
Blocking AI tools, scenario by scenario
The five situations teams ask about most.
How do I block ChatGPT at work?
Enforce it on the endpoint and browser, not the network. A managed browser extension force-installed through Chrome and Edge policy blocks the web app, and a Windows agent disables the desktop app. The block then holds on a personal account, on a phone hotspot, and on a home network.
How do I block personal AI accounts but allow the corporate one?
Match on the account, not just the domain. ShadowLock can allow your sanctioned enterprise ChatGPT or Copilot tenant while blocking the same site when a personal or anonymous account is signed in. Network filters cannot make this distinction, because both look identical from the network.
Is there a ChatGPT blocker for Chrome and Edge?
Yes. ShadowLock ships a managed extension that force-installs through Chrome and Edge enterprise policy, so users cannot remove it. It blocks the AI sites you choose and, on sites you allow, still classifies pasted content and blocks sensitive data from being submitted.
Can I block AI tools without a Microsoft 365 E5 licence?
Yes. E5 is required for Microsoft Purview, not for AI blocking generally. ShadowLock enforces at the endpoint and browser and prices per device, so blocking does not depend on your Microsoft licensing tier. See the Purview comparison below for where each tool fits.
I already run a firewall or DNS filter. Why is that not enough?
DNS and firewall rules only cover managed devices on your network. Employees route around them with a personal account, a hotspot, or a home laptop. Embedded AI such as Gemini in Chrome or Copilot in Edge never resolves a blockable domain at all, so no resolver rule can see it.
Blocking is the second half of the job. To see which tools are already in use before you decide what to block, start with shadow AI detection.
FAQ
Blocking AI tools FAQ
Why do employers block ChatGPT?
Employers block ChatGPT and similar tools because anything pasted into a public AI tool can leave the company's control - source code, customer records, financial data, and PHI can be retained or used to train the model. Blocking unsanctioned AI tools (or controlling what data reaches them) closes that leak while still letting teams use approved, governed AI.
Can you block ChatGPT company-wide?
Yes. ShadowLock blocks ChatGPT across every managed endpoint at once: the browser extension force-installs via Chrome and Edge enterprise policies, and the Windows agent disables the desktop app via NTFS ACLs. Because enforcement is at the endpoint and browser - not the network - it works whether the employee is on a corporate account, a personal account, on the office network, or at home.
How do I block ChatGPT for employees but still allow approved AI?
Set an allow-list of the AI tools you sanction and block everything else. ShadowLock lets you allow, for example, an enterprise ChatGPT or Copilot deployment while blocking the consumer versions and every other tool, and it can additionally block sensitive data from being pasted into the tools you do allow.
What companies block ChatGPT?
Many banks, healthcare systems, law firms, and large enterprises restrict consumer ChatGPT, and the practice is spreading to SMBs as cyber-insurance questionnaires and compliance audits begin asking about AI controls. The trend is less about banning AI outright and more about steering employees to a governed tool while blocking ungoverned ones.
Does blocking ChatGPT just push usage to personal devices?
It can, if blocking is the whole strategy. That is why ShadowLock pairs blocking with a sanctioned alternative and on-device data classification: employees get an approved tool to use, and attempts to route sensitive data elsewhere are still caught on the managed endpoint and browser. A block-only approach without an approved path tends to drive workarounds.
Comparisons
How ShadowLock compares for blocking AI
The tools teams evaluate to block ChatGPT and AI apps - side by side.
Blocks AI domains over DNS. We also read the prompt and cover M365.
Blocks app installs. We classify what gets pasted in.
Blocks inside the E5 stack. We need no E5 license.
Isolates risky URLs. We are purpose-built for shadow AI.
Block ChatGPT everywhere it shows up
Free 14-day trial. Enforcement live within an hour of agent and extension rollout.