How Infoblox uses its own DNS security platform to govern access to generative AI services across the enterprise
What Problem Are We Solving?
The rapid growth of AI, generative AI and chatbot platforms has created new security and governance challenges. While these tools can improve productivity, unmanaged access introduces risks including data leakage, intellectual property exposure and regulatory compliance concerns. Organizations need a consistent and scalable way to control AI usage without relying solely on endpoint-based controls.
Why DNS Is the Right Control Point
Infoblox Threat Defense™ provides visibility and policy enforcement at the DNS layer, allowing security teams to identify, monitor and block access to AI services before connections are established. Because DNS is involved in nearly every internet transaction, it serves as an effective and centralized enforcement point across the enterprise.
How We Implement It
- Blanket Security Policy: Threat Defense inspects all DNS queries originating from managed endpoints, on-premises DNS infrastructure and forwarding proxies.
- Application Filters: Built-in generative AI and AI chatbot application filters identify and control AI-related services.
- Custom Domain Lists: Custom lists provide additional coverage for AI services not included in default application categories.
- Threat Defense Endpoint: The endpoint agent is deployed across managed systems to ensure consistent visibility and enforcement.
- DNS Forwarding Proxy (DFP): DFP is deployed on NIOS and NIOS-X platforms to ensure enterprise-wide inspection of DNS traffic.
Policy Enforcement in Practice
To demonstrate the approach, Infoblox created a dedicated AI application filter and used it to block selected generative AI services, including DeepSeek. The filter is attached to a blanket security policy configured with a default redirect action and applied to the organization’s primary endpoint group.



Figure 1. Infoblox Threat Defense application filter
The same policy is enforced consistently across DNS Forwarding Proxy deployments, NIOS-X as a Service environments, external networks and Threat Defense-managed endpoint users, creating a unified governance model for AI access.
Key Takeaway
Infoblox actively uses Threat Defense to govern AI access at DNS scale within its own environment. This internal deployment demonstrates how organizations can use DNS-based security controls to enable AI governance, reduce risk and maintain visibility across rapidly evolving AI ecosystems.

