// lab
AI Control
A lab Palo Alto Networks firewall probed against ~400 public AI/LLM services from five policy-routed egress lanes — no policy, App-ID, URL filtering, and each with SSL forward-proxy decryption. The gap list below is served as a Palo Alto External Dynamic List you can point a firewall at directly.
Latest five-lane comparison
| Lane | Test date | Targets | Reachable | Blocked | Policy gaps | Unexpected blocks |
|---|---|---|---|---|---|---|
| noneno AI policy (control) | no run submitted | |||||
| app-idApp-ID filter, no decrypt | no run submitted | |||||
| urlURL filtering, no decrypt | no run submitted | |||||
| app-id+decryptApp-ID + SSL forward-proxy | no run submitted | |||||
| url+decryptURL filtering + SSL forward-proxy | no run submitted | |||||
External Dynamic Lists
policy-gaps
0 entries
https://www.grafeio.it/edl/policy-gaps.txt
ai-all-domains
0 entries
https://www.grafeio.it/edl/ai-all-domains.txt
confirmed-blocked
0 entries
https://www.grafeio.it/edl/confirmed-blocked.txt
allowlist
0 entries
https://www.grafeio.it/edl/allowlist.txt
policy-gaps.txt — hosts that should have been blocked by policy but were
reachable. Add it as a Domain EDL (recommended 5-minute check interval). A
<name>.url.txt variant is available for URL EDLs.