// lab

AI Control

A lab Palo Alto Networks firewall probed against ~400 public AI/LLM services from five policy-routed egress lanes — no policy, App-ID, URL filtering, and each with SSL forward-proxy decryption. The gap list below is served as a Palo Alto External Dynamic List you can point a firewall at directly.

Latest five-lane comparison

LaneTest dateTargetsReachable BlockedPolicy gapsUnexpected blocks
noneno AI policy (control) no run submitted
app-idApp-ID filter, no decrypt no run submitted
urlURL filtering, no decrypt no run submitted
app-id+decryptApp-ID + SSL forward-proxy no run submitted
url+decryptURL filtering + SSL forward-proxy no run submitted

External Dynamic Lists

policy-gaps 0 entries https://www.grafeio.it/edl/policy-gaps.txt
ai-all-domains 0 entries https://www.grafeio.it/edl/ai-all-domains.txt
confirmed-blocked 0 entries https://www.grafeio.it/edl/confirmed-blocked.txt
allowlist 0 entries https://www.grafeio.it/edl/allowlist.txt

policy-gaps.txt — hosts that should have been blocked by policy but were reachable. Add it as a Domain EDL (recommended 5-minute check interval). A <name>.url.txt variant is available for URL EDLs.