Sora Yazılım
Network security, server and software solutions from Türkiye

Generative AI Usage Policy: 4 Firewall Control Options

In short: There are four ways to control generative AI use with a firewall: block it entirely, allow only approved services, combine identity-based access with DLP and logging, or extend the same rules to branches and remote staff through SASE. For most organisations, a balanced generative AI usage policy pairs an approved-service list with DLP and logging.

What is shadow AI, and how much of it can a firewall see?

Shadow AI is the use of generative AI services for work without the IT team's approval. A firewall sees only the part of that use that crosses the corporate network or a tunnel the organisation manages; a chatbot opened on a personal phone over mobile data stays out of view.

The real risk is what gets pasted into the prompt. The UK's National Cyber Security Centre (NCSC) notes that queries sent to public large language models (LLMs) are visible to and stored by the provider, and advises against including sensitive information. Germany's BSI lists the lack of confidentiality of entered data as a distinct risk. A usage policy therefore has to answer "which data may go to which service", not only "which sites are allowed".

How do the four generative AI usage policy options compare?

Each step up in control depth adds prerequisites: blocking is the simplest, while the identity and DLP model needs the most preparation. The table maps the techniques in the "AI protection" section of the FortiOS 7.6.5 guide to each option.

OptionFortiGate featureStrengthWeakness
1. Block entirelyWeb filter AI category or application control Generative AI category set to BlockFast to deploy; stops data leaving the corporate network for these servicesMay push use to unseen devices
2. Approved-service listCategory block plus an application override; inline CASB tenant controlKeeps the contracted service availableList needs upkeep; inline CASB needs proxy-based inspection
3. Identity + DLP + loggingUser-group policies, DLP profile, monitor loggingShows who uses what; stops sensitive termsDeep inspection required; DLP not foolproof; logs are sensitive
4. Extend via SASEApplication Control With Inline-CASB and DLP in FortiSASESame rules off-siteEndpoint client and a second management layer

Is blocking ChatGPT at the firewall enough?

Blocking works as a stopgap until an approved alternative exists; it is not enough as a permanent policy. The quickest route is to block FortiGuard's Artificial Intelligence Technology category (category 100 in the CLI) in a web filter profile, as Fortinet's GenAI web filter page describes; the category also appears in the 7.4.3 and 7.2.8 guides.

A finer route is to block the Generative AI category (category 36) in FortiGate application control, which according to Fortinet goes beyond URL matching and identifies traffic with GenAI signatures. The guide notes that application categories may differ between versions and models; confirm each target URL's category with the FortiGuard Web Filter Lookup.

Caution: An unexplained ban can shift use to devices outside the network. Announce the block together with the reason and a timeline for the approved alternative.

How do you set up an approved-service list and restrict it to corporate accounts?

An approved-service list keeps the AI services the organisation has assessed and contracted available, and closes the rest. NIST AI 600-1 (July 2024) likewise suggests inventorying generative AI systems (GV-1.6-001) and establishing approved GAI service provider lists (GV-6.1-007).

On FortiGate, the first layer is a category block with an application-level override for the approved app. The second is inline CASB (cloud access security broker): per the FortiOS 7.6.5 guide, it applies actions to activities such as upload, download and share, and tenant control allows only accounts from specific domains to log in. Fortinet's tenant example is for Microsoft; for services without a predefined entry, administrators can define custom SaaS applications.

Caution: Inline CASB requires proxy-based inspection with a deep inspection profile and is not supported on FortiGate models with 2 GB RAM or less.

How do identity-based access, DLP and logging work together?

This model opens AI to selected groups, inspects prompts with DLP (data loss prevention) and records usage. Our suggested order is visibility first, restriction second:

  1. Start by monitoring. Set the Generative AI category to Monitor and apply it to a policy with deep inspection. Per the FortiOS 7.6.5 page, logs can include AI user, model, data centre location, use case and prompt fields.
  2. Define groups. FortiOS user groups draw on local accounts, RADIUS/LDAP servers or FSSO and can be used in firewall policies. Write one policy for allowed groups and a block for everyone else.
  3. Add DLP rules. Fortinet's example builds a dictionary, sensor and profile with both message and file rules for HTTP-POST, on a proxy-based policy with deep inspection. Fill the dictionary with terms specific to you, such as client names and project codes.
  4. Consider QUIC. The FortiSASE example blocks QUIC so the OpenAI server falls back to TLS 1.3; the FortiOS example also uses an application control profile in which QUIC is blocked.
  5. Protect the logs. Logs that contain prompt text are sensitive data in their own right; restrict access and set retention in the written policy.

Caution: Fortinet's DLP page says chatbot interfaces vary so much that the approach "may not be completely foolproof", and recommends restricting access for stronger protection. Treat DLP as a second layer. The FortiOS 8.0.0 guide adds that the FortiView AI widgets need local disk logging; FortiAnalyzer and FortiGate Cloud are not supported as their data source.

If you want to assess which model fits your current FortiGate policies, deep inspection set-up and licences, talk to us. Get a Quote

How do you extend the same policy to branches and remote staff?

Off-site users only fall under the same rules if their traffic still passes an inspection point: a tunnel to the corporate firewall or a cloud-delivered SASE (Secure Access Service Edge) service. The FortiSASE 7.4.0 guide describes Allow, Monitor and Block actions per category and per-application overrides; Fortinet's FortiSASE DLP example is verified on an endpoint running FortiClient and registered with FortiSASE.

We cover branch connectivity in our FortiSASE for branches article and application-level access in our ZTNA guide; product details are on our FortiSASE page. Practical note: domain lists go stale; Fortinet's FortiOS DLP example uses chat.openai.com, while the FortiSASE example uses chatgpt.com.

Which option suits which organisation?

Three criteria drive the choice: data sensitivity, where users work, and whether an approved service exists. The decision matrix turns these into a starting option.

Organisation profileData sensitivityStart withNext step
No approved service; handles health or HR dataHigh1 + monitoringMove to 2 and 3 once a service is chosen
Office-based SMB with a corporate AI subscriptionMedium2Add 3 for sensitive teams
Teams handling source code, bids or client listsHigh3Keep the dictionary current with each team
Multi-branch or remote-heavy organisationVaries4Map office and SASE rules in one policy document
No deep SSL inspection yetAny1 as a bridgeCertificate rollout, exemptions, announcement

Answer three questions before using the matrix:

  1. Which data types must never enter a prompt? If there is no written list, start there.
  2. Is there an approved service under contract? If not, option 1 is only a temporary bridge.
  3. How many users work outside the firewall's view? If many, plan option 4 from the start.

What prerequisites should be in place first?

Options 2, 3 and 4 share one prerequisite, visibility into encrypted traffic, followed by identity, ownership and communication:

  • Deep SSL inspection: According to Fortinet, FortiGate decrypts, inspects and re-encrypts sessions, so its CA certificate must be trusted on clients (Active Directory Group Policy can distribute it). Categories such as banking can be exempted for privacy.
  • Identity source: groups must reach FortiGate via LDAP, RADIUS or FSSO; IP-only rules cannot deliver identity-based access.
  • Version and contracts: the "AI protection" section appears in FortiOS 7.6.4 and later guides; plan any upgrade with the checks in our FortiOS upgrade guide. Fortinet states that GenAI database updates require a valid contract and that inline CASB definitions fall under the basic firmware and updates contract; tie these dates to your FortiGate licence renewal calendar.
  • Owners and communication: IT security, legal and data protection contact, HR and business units; a short usage policy and a block page that links to the approved alternative.
  • The firewall itself: an inspecting device becomes a central control point; keep it patched using our firewall vulnerability and patch management guide.

If your team cannot sustain set-up and rule upkeep, our firewall maintenance and management service can take it on within the scope defined in the contract; device options are on our FortiGate page.

What should businesses in Türkiye consider under KVKK?

For organisations operating in Türkiye, the Personal Data Protection Authority (KVKK) published its Generative AI and Personal Data Protection Guide (Publication No. 113) in November 2025. It names the exposure of personal data and sensitive corporate information shared in prompts as an important security issue. Where personal data is transferred abroad through a provider based outside Türkiye, the guide says the transfer must comply with Article 9 of Law No. 6698 and the related regulation; as examples of Article 12 measures it lists staff awareness, multi-factor authentication and secure retention of logs.

Firewall controls contribute to these measures but do not meet the obligations on their own. Logging prompt text is itself data processing and a form of employee monitoring; decide on notice, retention and access with your legal adviser. This section is not legal advice; KVKK's official texts are authoritative.

FAQ

Which FortiGate feature blocks ChatGPT?

There are two built-in routes: block FortiGuard's Artificial Intelligence Technology category (category 100) in a web filter profile, or the Generative AI category (category 36) in application control. Fortinet recommends confirming each target URL's category with the FortiGuard Web Filter Lookup. To keep access open but stop sensitive content, use a DLP profile instead.

Can AI use be controlled without deep SSL inspection?

Partly. According to Fortinet, some Generative AI signatures require deep inspection and some do not; the signature's Requirements field shows which. Extended log fields such as model and prompt, and inline CASB, require deep inspection, and Fortinet's DLP examples are built on it. Complete the certificate rollout before planning granular control.

Does DLP always catch sensitive data in prompts?

No. Because web-based chatbots vary widely, Fortinet recommends combining message-based and file-based DLP rules and warns that the method may not be foolproof. DLP is only as good as its dictionary: update organisation-specific terms regularly and consider fully restricting access for the most sensitive teams.

How can remote workers' AI use be controlled?

Their traffic must pass an inspection point: a tunnel to the corporate FortiGate, or a cloud service such as FortiSASE applying the same application control and DLP profiles. Fortinet's FortiSASE example uses FortiClient on the endpoint. To assess which route fits your environment, contact us.

Which FortiOS version do these features need?

The "AI protection" section appears in the FortiOS 7.6.4, 7.6.5, 7.6.6 and 8.0.0 administration guides; the 7.4.8 and 7.6.0–7.6.3 guides only include a DLP keyword-blocking example. The AI web filter category is also documented in the 7.2.8 and 7.4.3 guides. Check your model's release notes for definitive support.

Conclusion

  • Blocking is fast, but it is not a lasting generative AI usage policy.
  • An approved-service list with tenant control separates corporate from personal accounts.
  • Identity, DLP and logging give the most visibility but need deep SSL inspection and log governance.
  • Branches and remote staff need the same profile via SASE or a tunnel.

Sora Yazılım provides selection, supply, installation and managed services for Fortinet products, and can design an AI control policy around your existing FortiGate set-up with you.

Get a Quote · WhatsApp: WhatsApp Support · Phone: +90 544 785 21 87 · Email: talep@sorayazilim.com

Sources

  1. AI protection — Fortinet, FortiOS 7.6.5. docs.fortinet.com (accessed 7 October 2026)
  2. Protecting GenAI access using web filter — Fortinet, FortiOS 7.6.5. docs.fortinet.com (accessed 7 October 2026)
  3. Protecting GenAI access using application control — Fortinet, FortiOS 7.6.5. docs.fortinet.com (accessed 7 October 2026)
  4. Protecting GenAI access using application control — Fortinet, FortiOS 8.0.0. docs.fortinet.com (accessed 7 October 2026)
  5. Protecting GenAI Access using DLP — Fortinet, FortiOS 7.6.5. docs.fortinet.com (accessed 7 October 2026)
  6. Inline CASB — Fortinet, FortiOS 7.6.5. docs.fortinet.com (accessed 7 October 2026)
  7. Deep inspection — Fortinet, FortiOS 7.6.5. docs.fortinet.com (accessed 7 October 2026)
  8. Application Control With Inline-CASB — Fortinet, FortiSASE 7.4.0. docs.fortinet.com (accessed 7 October 2026)
  9. Blocking access to LLM applications using keywords and FQDN example — Fortinet, FortiSASE 7.4.0. docs.fortinet.com (accessed 7 October 2026)
  10. NIST AI 600-1, Generative Artificial Intelligence Profile — NIST, July 2024. nvlpubs.nist.gov (accessed 7 October 2026)
  11. ChatGPT and large language models: what's the risk? — NCSC, 14 March 2023, updated 12 March 2025. ncsc.gov.uk (accessed 7 October 2026)
  12. Üretken Yapay Zekâ ve Kişisel Verilerin Korunması Rehberi (Generative AI and Personal Data Protection Guide) — KVKK, Publication No. 113, November 2025. kvkk.gov.tr (accessed 7 October 2026)
  13. Generative KI-Modelle: Chancen und Risiken für Industrie und Behörden — BSI, version 2.0, 17 January 2025. bsi.bund.de (accessed 7 October 2026)

How this article was prepared

Prepared by: Sora Yazılım Team. This article was prepared with AI assistance; technical information was checked against the manufacturer and official sources linked in the article as of 7 October 2026.

Related articles

Need help with the topics in this post?

Schedule a free discovery call with Sora Yazılım — we'll propose a concrete roadmap.

WhatsApp Support