Blocking AI assistants outright rarely holds, because people need them to do their work. The exposure is not the tool, it is the account. A user signed in with a personal account is on the same site, using the same interface, but outside the retention, audit, and data handling terms the organization negotiated.

DefensX now enforces which organizations and workspaces can be used. Under Settings → SaaS Restrictions, access can be limited to your own tenants by entering the Allowed Organization IDs for Claude, found on its Settings → Account page, and the Allowed Workspace IDs for ChatGPT Enterprise, found on its Admin Settings page. Users signing in from anywhere else are prevented from doing so, while the service itself stays available.
For configuration details, see the SaaS Restrictions knowledge base article.