Skip to content
Nullgen AI Blocker

BlogIT and security

How to block AI apps on managed phones and tablets with your MDM

The browser extension closed the shortcut on managed computers. Now the same policy reaches the phone. Nullgen’s mobile app blocks known AI apps and websites on iPhone and iPad, deploys through Intune, Jamf Pro, or Iru with nothing for the employee to tap, and lands every device in the dashboard you already use. Android is next.

The Nullgen team

10 min read

Most generative AI policies were written for the laptop. The browser extension blocks the prompt in Chrome, Edge, Firefox, and Safari on every managed computer, and that covers the working day for most people. It does not cover the phone in their pocket, where ChatGPT, Claude, Perplexity, and Grok are each a free app and a thumbprint away. A customer list pasted into an assistant from a phone is exactly as gone as one pasted from a desktop.

Nullgen AI Blocker for iPhone and iPad closes that gap on the devices your MDM manages. It blocks known AI apps and websites on the device, it deploys the way you deploy everything else, and the employee never sees an install prompt. This guide covers what the app does, how to push it with Intune, Jamf Pro, Iru, or any MDM that delivers managed app configuration, and what it does not cover. Android is coming soon on the same enrollment.

Where the phone slips past the policy

Shadow AI on mobile rarely looks like a breach. It looks like a sales rep summarizing a contract in the ChatGPT app between meetings, a support lead pasting a ticket thread into Claude to draft a reply, or an engineer photographing a whiteboard and asking an assistant to explain it. Each one is a normal workday task that moves confidential data to a third party your security review never covered.

The usual controls do not reach it. A web proxy sees the office network, not the cellular connection. App protection policies wrap the apps you push, not the assistant the person installed from the store. A written policy asks people to remember a rule at the exact moment the shortcut is most tempting. What worked on the computer, which is removing the option, is what the mobile app does on the phone.

  • Off the corporate network

    Cellular data and home Wi-Fi never touch your proxy or DNS filter, so the assistant loads as if no policy existed.

  • Consumer apps on a managed device

    App protection policies cover the apps you deploy. A consumer AI app installed from the store sits outside that wrapper.

  • Camera, share sheet, and paste

    Screenshots, photos of documents, and long-pressed text all reach an assistant in one tap, with no download for a DLP rule to catch.

What the app does on a managed device

A phone cannot run a browser extension, so the mobile app blocks the destination rather than the prompt. Once protection is on, the device cannot reach known AI destinations: chatgpt.com does not load in Safari or Chrome, and the ChatGPT app cannot connect. The same is true for Claude, Perplexity, Grok, Copilot, and the 70+ other AI tools in the catalog, and the list refreshes on its own without an app update.

Everything happens on the device. The app downloads the list of AI destinations and your policies and answers each lookup locally; it never uploads which sites or apps were used, and nothing anyone types leaves the phone. iOS shows the filter as a VPN configuration because that is the mechanism iOS provides for an app to filter, but no traffic is routed through Nullgen or any remote server.

Deploy it through the MDM you already run

The rollout is three items in your MDM, all generated for you on the Provisioning page of the Nullgen dashboard: the app itself, an app configuration that enrolls each device, and an optional configuration profile that turns protection on without a prompt. Here is the sequence.

  1. 1

    Generate an enrollment token

    In the dashboard, open Provisioning and choose the Mobile app tab. The token identifies your organization, and the page builds it into every payload below. The raw value is shown once, so store it in your MDM, not in a ticket.

  2. 2

    Assign the app as required

    Add Nullgen AI Blocker in Apple Business Manager under Apps and Books, assign licences to the devices, and push it as a required, managed app. iOS delivers managed app configuration only to apps the MDM installed, so this step is not optional.

  3. 3

    Attach the app configuration

    Choose your management tool on the Provisioning page and copy the property list into the app’s configuration policy. The identity fields use the placeholders your tool fills in automatically, so one policy covers every user, and each phone lands on the same person in the dashboard as their managed browser.

  4. 4

    Push the always-on profile

    Upload the generated VPN configuration profile as its own item, next to the app assignment. It installs the filter with no approval prompt, needs no supervision, and locks the Connect On Demand switch. Devices under User Enrollment do not receive it; they approve the VPN once instead.

  5. 5

    Apply the recommended restrictions

    Nullgen filters network destinations, so it cannot reach an assistant built into the operating system. The Provisioning page lists a Restrictions payload that turns off the Apple Intelligence features that generate text and images, and Private Browsing in Safari.

One launch of the app completes enrollment. From then on the device keeps itself current, refreshing the catalog and your policies on its own, and it appears on the Devices page assigned to the person who uses it. Allow nullgen.ai and cdn.nullgen.ai on outbound HTTPS; the Deployment for IT page on the Trust Center has the details. Nothing is re-issued when the desktop agents ship: the same enrollment token covers browsers, phones, and computers.

What employees see

The design goal was the same as the extension’s: remove the shortcut without surveillance and without a daily reminder that a control exists.

  • Nothing to install or approve

    The app arrives from the MDM, and with the profile in place protection is on before anyone opens it. iOS shows its standard VPN indicator while the filter is active.

  • Blocked tools simply do not load

    There is no warning page to argue with. The site does not load and the app cannot connect, in every browser and in the app itself.

  • A way to ask

    When something blocked is needed for work, the person picks the tool and a duration inside the app and adds a note. Approvers decide in the dashboard and the change syncs to the phone.

Exceptions without a help-desk ticket

A block with no exit becomes a workaround. Nullgen’s answer is the same on the phone as on the computer: access requests routed to the people who should decide, with a time limit. A request for Perplexity for the afternoon reaches the approver you assigned, the approval unblocks the device the moment it is granted, and the block returns on its own when the time is up.

Protection on. Known AI apps and websites are blocked on the device, with nothing inside the app to turn it off.
Requests from phones land in the same queue as requests from browsers. Approve for fifteen minutes, an afternoon, or permanently.
  • Owner, Admin, Approver, and Viewer roles, so a team lead can approve requests without administering users or devices.

  • Allow and deny policies per person or for the whole organization, using the same catalog on phones and browsers.

  • Every approval has a duration and expires on its own; a one-hour exception is exactly one hour.

  • Phones, tablets, and browsers sit side by side on the Devices page, assigned to the same people.

What it does not block, and what to do about it

Nullgen blocks known AI apps and websites, and the list keeps growing. Some AI features, though, live inside a larger app the phone needs for other things, and blocking those would break search, mail, or messaging. The app leaves them alone. Your MDM can remove those apps entirely where the policy calls for it.

  • Gemini inside the Google app and Search

    The dedicated Gemini website is blocked. The Gemini app and Gemini in Search share Google’s main websites, so blocking them would break Search.

  • Copilot inside Office, Bing, and Edge

    The Copilot website is blocked; the version built into Microsoft apps is not.

  • Meta AI inside Instagram, WhatsApp, and Facebook

    The Meta AI website is blocked; the assistant inside those apps is not.

Two more boundaries worth stating plainly. The app protects devices your MDM manages; a personal phone that is not enrolled is out of scope, and devices under User Enrollment approve the VPN once because Apple does not deliver the profile to them. And the app filters network destinations, so an assistant built into the operating system is a job for your Restrictions payload, not for Nullgen.

Android is next

The Android app will block the same catalog the same way, pushed through managed Google Play as a force-installed app with a managed configuration. It will use the enrollment token you already have, and the Provisioning page will carry its payloads when it ships. Subscribe to the newsletter and we will let you know.

Key takeaways

  • The phone is where an AI policy written for the laptop stops working: off the network, outside app protection, and one tap from a paste.

  • On managed iPhones and iPads the app blocks the destination: known AI apps and websites do not load, and there is no off switch.

  • Deployment is three MDM items generated on the Provisioning page: the required app, the app configuration, and the always-on profile.

  • Blocking happens on the device. Nothing anyone types or browses is sent to Nullgen.

  • AI inside apps the phone needs for other things is not blocked; use your MDM restrictions for those. Android is coming soon.

Frequently asked questions

  • Does it work on employees’ personal phones?

    It works on devices your MDM manages. Under Apple’s User Enrollment for personal devices the app and its configuration still deploy, but Apple does not deliver the VPN profile, so the person approves the filter once. Phones that are not enrolled are out of scope.

  • Is any traffic routed through Nullgen?

    No. The app answers lookups on the device. It downloads the list of AI destinations and your policies and uploads nothing about which sites or apps were used.

  • Do the devices need to be supervised?

    No. The VPN configuration profile installs without supervision and without an approval prompt. Supervision only matters for Apple’s Always On VPN, which Nullgen does not require.

  • How is it priced?

    The mobile app is included with Enterprise at $10 per seat per month. A person is one seat, and their phone, tablet, and browsers link to it, up to six devices per person. Enterprise starts with a 30-day trial with no card.

  • When does Android ship?

    Soon, on the same enrollment token. We do not announce dates; subscribe to the newsletter for the release note.

Further reading

  1. Apple, Apple Platform Deployment guide
  2. Microsoft Learn, “App configuration policies for Microsoft Intune”
  3. Android Developers, “Set up managed configurations”

Pilot it on ten phones this month

Start a 30-day Enterprise trial with no card, generate an enrollment token, and assign the app to a pilot group in your MDM. The free extension covers the computers while you decide.