Blocking AI is not knowing what it is doing
Blocking AI is easy. Knowing what it is doing is another matter — and it is the second one that lets you allow it.
Every company knows what it spends on software. Almost none knows what was asked: which data left, about which client, in which tool nobody approved.
That is why so many companies only know how to forbid. It is not rigour. It is blindness — if you cannot see what is happening, you have no safe way to authorise anything. All you can do is close the door.
Blocking and inspecting are different things
Worth separating the two, because they are usually sold under the same name:
Blocking ≠ inspecting. Barring direct AI traffic is easy (firewall, by domain). Reading the content (the prompt) only happens when the call goes through the gateway.
Blocking is saying no to an address. It is cheap, it is quick, and the corporate firewall already does it — the "AI" category tends to come ready out of the box.
Inspecting is of another nature. It requires the request to pass through a point of your own, because that is where the content exists. Outside it, you can see that somebody talked to a machine. You cannot see what they said.
What blocking does not tell you
Whoever only blocked knows one thing: that they stopped it.
They do not know what was being asked before. They do not know what is still being asked through whatever path stayed open — and one always does: the personal phone, the system with AI built in that does not announce itself as AI, the free account opened with a personal e-mail in five minutes.
And there is a side effect nobody counts: blocking does not make the need disappear, it makes it disappear from view. Whoever needed to get something done still needs to. The difference is that now they do it outside, with no rule and no record — which is exactly the scenario blocking existed to prevent.
Before switching on logging comes the paperwork
Here the order matters more than the technique, and this is the part usually skipped:
Logging the use of a corporate tool is a legitimate act of management provided there is prior notice — which depends on the communication and the signed terms, not on the technique. Switch logging on only after them.
It is not a formality. It is what separates two things that look alike from the outside: a company that agreed with its people what gets recorded, and a company that watches without saying so.
The first has an agreement. The second has a problem — and the problem is not a technical one.
What fixes it is short: a written notice, signed terms, and the rule stated in language people actually understand. What is recorded, what for, who looks, and what nobody looks at. It takes an afternoon. Doing it in the reverse order costs the team's trust, and that one does not come back with an apology.
What gets recorded is the request, not the person
It is worth saying what this is not.
It is not reading anybody's life. What passes through the governed point is what was asked of the company's tool, about the company's work — the same way corporate e-mail belongs to the company, and nobody has found that strange for a long time.
The goal is not to catch someone. It is to be able to answer two questions that today have no answer: has client data already left this building? and what can we safely allow?
The second is the one that matters. Visibility is not there to tighten things. It is there to let you open them — and almost every AI ban in place today is a ban for lack of knowing, not a decision made.
The closing question
If a client asked you today how you use AI with their data, would there be a written answer?
Not an opinion, nor a "we don't use it for that". An answer you could show them.