AI and internet access policies

Control access to AI tools and risky websites across your organization

wAIrden enables centralized rules for users, groups, devices and clients, with query and event visibility in dashboards and logs.

Feature availability depends on the version, configuration and deployment model.

Rules for groups and devicesDNS filteringQuery log and audit log

AI traffic across your organization

Demo view

Approved AI

Shadow AI

Unknown app

wAIrden
Allowed
Blocked

Problem

Employees are already using AI. The question is: does the company control it?

More employees use public AI tools outside IT and security oversight. Source code, documents, customer data, contracts, notes and internal content may be pasted into external models. Policies, training and guidelines are not enough if the company has no technical control layer.

private AI accounts used for work
company data pasted into public models
lack of visibility for IT and security
paper policies without enforcement
risk to data, IP and compliance

Shadow AI control flow

How wAIrden helps turn an AI policy into technical control

The flow shows a careful, practical model: a user tries to access AI, wAIrden checks rules, and the organization gets an allow/block decision, a user message and an audit trail.

Employee uses AI

A user tries to access an AI tool or category that requires control.

Report data

Shadow AI is not theory. It is a measurable business risk.

Recent industry reports show that employees increasingly use AI tools outside organizational control, while company data may be shared with external applications. That is why an AI policy alone is not enough — organizations need a technical layer of control, visibility and enforcement.

223

monthly incidents

GenAI data policy violations

Netskope reports that the average organization sees 223 GenAI data policy violations per month. This shows that the risk is repeated, not incidental.

Source: Netskope Cloud and Threat Report: 2026

47%

of GenAI users

Personal accounts outside company control

According to Netskope, a significant share of GenAI users still access tools through personal or unmanaged accounts, reducing organizational visibility and control.

Source: Netskope Cloud and Threat Report: 2026

13%

of organizations

Breaches involving AI applications or models

IBM reports that 13% of studied organizations experienced breaches involving AI applications or models, making AI a real security risk area.

Source: IBM Cost of a Data Breach Report 2025

97%

without proper controls

Lack of AI access controls

IBM states that among organizations that experienced breaches involving AI applications or models, 97% lacked proper AI access controls.

Source: IBM Cost of a Data Breach Report 2025

60%

of employees

Unapproved AI use is increasing

ManageEngine reports that 60% of employees are using unapproved AI tools more than they were a year ago, confirming that Shadow AI is accelerating.

Source: ManageEngine Shadow AI Report 2025

USD 7.44B

market forecast by 2030

The AI TRiSM market is growing

Grand View Research forecasts the AI Trust, Risk and Security Management market to grow from USD 2.34B in 2024 to USD 7.44B by 2030.

Source: Grand View Research — AI Trust, Risk and Security Management Market Report

Conclusion: companies do not need another AI policy document that nobody enforces. They need a practical control layer: visibility, access rules, blocking, employee communication and activity review.

Sources: Netskope Cloud and Threat Report 2026, IBM Cost of a Data Breach Report 2025, ManageEngine Shadow AI Report 2025, Grand View Research AI TRiSM Market Report. Data is presented for informational purposes — wAIrden helps reduce risk, but does not replace a full AI governance program, DLP or SASE.

Good cop and bad cop for Shadow AI

Support employees and enforce rules technically.

An AI policy without technical controls is just a document. wAIrden helps combine education, rules and technical enforcement of access to AI tools.

Good cop

Helps safely introduce AI, educate employees and point them to approved ways of using AI tools.

  • recommended AI usage rules
  • list of approved tools
  • employee-facing communication
  • first step in an AI governance program

Bad cop

Technically restricts access to unapproved services, enforces policies and gives administrators visibility.

  • blocks for risky AI services
  • access rules evaluated with each query
  • AI blocklists and block pages
  • query logs and audit trail

Risk

Why Shadow AI is becoming a real risk

Market research and industry reports indicate that the problem is growing: organizations increasingly see AI tools being used outside official processes, while declarations alone do not provide enough visibility.

Shadow AI grows faster than policies

Employees increasingly use AI tools outside official processes. Internal guidelines often cannot keep up with adoption.

Data leaves the organization

Documents, code, customer data, offers, contracts and intellectual property may be pasted into public models.

Training is not enough

Policies and instructions are necessary, but without technical controls the company does not know what actually happens in the network.

Enforceable access rules are needed

Organizations need mechanisms that help enforce AI usage rules, not only describe them.

How wAIrden helps

From AI policy to real control

1

See the risk

Identify which AI tool categories may require control and where the company loses visibility.

2

Define the rules

Decide which AI tools are approved, restricted or blocked for selected user groups.

3

Enforce technically

Implement access rules, blocklists and block pages that work beyond written declarations.

4

Monitor activity

Use query logs and activity views to check whether the rules are actually followed.

Technical layer

Rules decide: allow or block.

DNS remains the technical mechanism. If a domain or AI tool category is allowed, the user continues. If it matches a blocking rule, wAIrden shows a custom block page configured by the administrator.

Technical layer

Device → DNS → AI policy → Allow/Block → Block Page

01Client

Device

A laptop, phone or other network device initiates a website visit.

02DNS

DNS Query

The DNS query reaches the wAIrden filtering layer.

03Policy

Policy Engine

The system checks DNS rules, blocklists, categories and assigned policies.

04Decision

Allow / Block

The domain is allowed or blocked according to the matched rule.

05Block

Block Page

When blocked, the user sees a custom message configured by the administrator.

Allow: domain is allowed and the user continues.

Block: domain matches a blocking rule and the custom block page is shown.

Offer

From Shadow AI review to technical access control

Start with a risk review and quick recommendation. Then implement technical rules, blocklists, block pages and activity visibility so your AI policy is not just a document.

Shadow AI review and audit

€69 net

We review where uncontrolled AI usage may appear in your organization, which data is most exposed and which technical and organizational controls should be implemented first.

  • 30-minute discussion about AI usage in the organization
  • Shadow AI risk identification
  • initial map of AI tools and categories
  • technical access control recommendations
  • first-step plan for IT, security and business

wAIrden Start — Shadow AI control

Best start

€230 net+ €35 / month

Fast implementation of basic access control for AI tools in a small company or team. Helps reduce the risk of unapproved AI applications being used outside organizational oversight.

  • basic access rule configuration
  • list of approved and blocked AI tools
  • basic AI blocklists
  • block page with company message
  • basic activity visibility
  • 30-minute onboarding

wAIrden Pro — AI security for organizations

from €465 net+ from €69 / month

Extended implementation for organizations that want to combine AI policy, technical access enforcement, activity visibility and administrator support.

  • Shadow AI risk workshop
  • rules for different user groups
  • approved and blocked AI categories
  • block pages with employee communication
  • query log and activity review
  • admin training
  • post-implementation support

Partner program for IT and security companies

terms agreed individually

For IT companies, administrators, security consultants and service providers who want to help clients reduce Shadow AI risk and implement technical access controls.

  • commission model agreed individually
  • possible role in reviews, implementations and subscriptions
  • joint customer demo
  • Shadow AI sales materials
  • branding available as part of an individual deployment

Not sure where to start? Start with a Shadow AI review for €69. We will check where your organization may be losing control over AI usage and suggest the first technical safeguards.

Start with a review

Key features

Product modules for AI tool access control.

Dashboard, access rules, AI blocklists, block pages and query history in one admin workflow.

Access RulesActive

Create rules for domains and categories and assign them to clients. Proxy support is a technical, deployment-dependent capability, not a standard feature in every customer panel.

  • Allow/block rules
  • Domain and category support
  • Assigned block page templates
  • Enable and disable rules

Explore how wAIrden can be deployed in your organization.

Book a Shadow AI review and see how rules, dashboard, query log and custom block pages can work in practice.

Book a demo

Dashboard

A larger view of activity, blocks and recent events.

The dashboard interface includes query, block, active-rule, category and recent-event summaries. The available data depends on deployment configuration.

Dashboard Overview

DNS traffic, rules and recent activity

Demo view

DNS Queries Today

18,420

+12%

Blocked Requests

1,284

7.0%

Active Rules

34

5 updated

Traffic chart

Last 7 days

Mon
Tue
Wed
Thu
Fri

Top Categories

Social Media38%
Streaming24%
Proxy/VPN17%
12:41youtube.comBlockedBlock Social Media
12:34company-crm.comAllowedAllow Company Tools
12:17unknown-proxy.netBlockedBlock Proxy/VPN

Deployment

A deployment model matched to your infrastructure.

Local installation

On-premise

A possible model for organizations that need wAIrden in their own environment. Scope and configuration are agreed as part of an individual deployment.

  • Own infrastructure
  • Deployment configuration
  • Individually agreed scope

wAIrden SaaS

Cloud

A managed model for organizations that do not want to maintain the product's server layer. Availability depends on the selected version and configuration.

  • Managed model
  • Administration panel
  • Offer-dependent availability

Pricing

Choose the right access control and visibility plan

Compare indicative packages and consult a scope matched to users, devices, rules and required integrations.

Free

For people who want to test basic access control.

€0

  • basic access control
  • up to 50 domains on the blocklist
  • 1 blocklist
  • basic dashboard
  • 1 block page template
  • Query Log history from the last 24 hours

Medium

Scope to be confirmed

For small teams, microbusinesses and small offices.

€11

/ month

  • everything in Free
  • up to 1,000 domains on blocklists
  • up to 5 blocklists
  • DNS and proxy policy rules
  • up to 10 active rules
  • 5 Block Pages templates

Advanced

Most popular
Scope to be confirmed

For companies, organizations and IT teams that need broader control and more rules.

€35

/ month

  • everything in Medium
  • up to 10,000 domains on blocklists
  • up to 25 blocklists
  • unlimited categories
  • up to 100 active DNS/proxy rules
  • unlimited Block Pages templates

Enterprise

For organizations

For larger organizations, schools, company groups and IT teams that need custom limits, local deployment, security support and alignment with compliance processes.

Custom pricing

  • custom limits for domains, blocklists and rules
  • local / on-premise deployment or dedicated setup
  • longer log retention
  • support with AI policy and Shadow AI
  • roles and access for larger teams
  • dedicated implementation support

Which plan should you choose?

Free

for the first test and panel review.

Medium

for small teams and basic access control.

Advanced

most popular for companies, schools and organizations that need rules, logs and stronger control.

Enterprise

for customers with security, on-premise, compliance and custom limit requirements.

Plan table

Plan table

Plan table
FeatureFreeMediumAdvancedEnterprise
Limits
Domains on blocklistsup to 50up to 1,000up to 10,000custom
Number of blocklists1up to 5up to 25custom
Categoriesbasicbasic and customunlimitedcustom
Access control
Basic blockingyesyesyesyes
DNS and proxy rulesnoyesyesyes
Active rulesnoup to 10up to 100custom
AI tool controlbasicextendedadvancedenterprise
Block Pages
Block page templates1up to 5unlimitedcustom
Company messagesbasicyesyesyes
Query Log and reporting
Query Log24 hours30 days180 dayscustom
Activity dashboardbasicyesadvancedenterprise
CSV exportnonoyesyes
Log privacy optionsto be confirmedto be confirmedconfiguration-dependentcustom
Administration and deployment
Admin rolesnonoyesyes
SaaSyesyesyesyes
Local / on-premise deploymentnonoyesyes
Dedicated setupnononoyes
Compliance / AI policy supportnononoyes
Support
Email supportbasicyesprioritydedicated
Package activationon confirmationon confirmationon confirmationafter consultation
Agreement and termsstandardstandardstandardcustom
Choose planAsk about availabilityCheck deployment scopeCheck deployment scopeBook a Demo

Final scope depends on deployment model, user and device counts, and required integrations. Technical capabilities, proxy and local deployment may require individual configuration.

Who it is for

Match the first step to your organization

wAIrden sells both a product and an implementation service. This split helps you choose whether to start with a Shadow AI review, Start implementation, Advanced plan or Enterprise conversation.

20-200 employee companies

Problem
The risk of company data being pasted into public AI tools grows faster than formal policies.
Value
You can quickly launch access rules, blocklists and employee-facing messages.
First step
Start with a Shadow AI review or wAIrden Start.

Schools and organizations

Problem
Different user groups need different rules for AI tools and categories.
Value
You control access according to your policy and show clear block pages.
First step
Talk about Advanced or Enterprise.

Organizations deploying AI

Problem
An AI policy without technical enforcement can easily become a document with little practical effect.
Value
You connect AI usage rules with a practical layer of control and visibility.
First step
Request a review and first-control map.

IT and security teams

Problem
The team does not see which AI tools are used and where access attempts appear.
Value
You get query logs, allow/block rules, a dashboard and activity review.
First step
Review Advanced or local deployment.

IT / MSP partners

Problem
Clients ask about AI governance but need a practical starting service.
Value
You add Shadow AI review and wAIrden implementation to your offer.
First step
Apply to the partner program.

Enterprise

Problem
Compliance, on-premise, log retention and custom limits usually require individual decisions.
Value
You tailor implementation scope, support and integrations to security processes.
First step
Book a Demo.

FAQ

Common questions before getting started.

Shadow AI under control

Explore how wAIrden can be deployed in your organization.

Book a Shadow AI review and see how rules, dashboard, query log and custom block pages can work in practice.