Overview
The AI Infrastructure Threat List is a curated, regularly refreshed dataset of IP addresses, CIDR ranges, and domains associated with AI tools and services observed across enterprise environments. It is intended to help security teams identify, monitor, and control AI-related network traffic — whether the goal is policy enforcement, data loss prevention, or detection of unsanctioned tool use.
The list covers tools across the following categories:
- General-purpose AI assistants (ChatGPT, Claude, Gemini, Grok)
- AI coding assistants (GitHub Copilot, Cursor, Amazon Q Developer, Tabnine)
- Vibe-coding and app-builder tools (Vercel v0, Lovable, Bolt.new, Replit)
- AI search and research tools (Perplexity, NotebookLM)
- Voice and audio AI (ElevenLabs, Deepgram, AssemblyAI)
- AI video and avatar tools (HeyGen, Synthesia, Midjourney, Runway)
- Chinese-domiciled AI tools (DeepSeek, Baidu ERNIE, Alibaba Qwen, ByteDance Doubao, and others)
- Autonomous AI agents (OpenClaw / Moltbot / Clawdbot)
Each indicator carries a risk score and a comment field with service attribution. The list is refreshed on a regular cadence (typically weekly); the freshness of each indicator is visible in the comment field.
What is included
Each indicator has three fields:
| Field | Example | Description |
|---|---|---|
| Entity | api.deepseek.com |
The network indicator: a domain name, a single IP address (/32), or a CIDR range. One indicator per row. |
| Risk Score | 99 | Reflects the threat intelligence risk score. May be low for AI tools since the risk is on policy, compliance, and data exposure vs cyber attacks. |
| Comment | Anthropic, Verified 2026-09-16, Live JSON |
Three comma-separated parts: service provider, verification date (YYYY-MM-DD), and association method. See comment format below. |
Comment field format
The comment field encodes three pieces of information in a single string, separated by a comma:
- Service provider — The company or product associated with the indicator (e.g., Anthropic, OpenAI, ByteDance / Doubao).
-
Verification date — The date the indicator was confirmed as associated with that service (ISO format: YYYY-MM-DD). For Live JSON entries, this reflects the vendor's own
creationTime. - Association method — How the indicator was attributed to the service. See association method values below.
Examples:
| Comment value | Meaning |
|---|---|
Anthropic, Verified 2026-09-16, Live JSON |
ClaudeBot IP pulled directly from claude.com/crawling/bots.json on that date |
OpenAI, Verified 2026-09-16, Live JSON |
GPTBot CIDR from openai.com/gptbot.json — updated automatically each refresh cycle |
ElevenLabs, Verified 2026-09-16, Official docs |
Static egress IP documented in ElevenLabs IP allowlisting page |
Perplexity AI, Verified 2025-02-07, Live JSON |
PerplexityBot IP; date reflects vendor JSON creationTime, not refresh date |
High-Flyer (DeepSeek), Verified 2026-09-16, Community / OSINT |
Domain confirmed via BGP, WHOIS, and public security research |
Vercel, Verified 2026-09-16, BGP / WHOIS |
CIDR block confirmed via AS number and routing registry lookup |
Association method values
-
Live JSON
Pulled directly from a vendor-published, machine-readable IP feed (e.g.openai.com/gptbot.json,claude.com/crawling/bots.json). Highest confidence. Updated automatically on each refresh cycle. The verification date reflects thecreationTimein the vendor's JSON. -
Official docs
Documented by the vendor in a security, trust, or network configuration page. Stable but manually verified rather than machine-pulled. Includes static egress IPs that vendors publish outside of a JSON feed. -
BGP / WHOIS
Attributed to the vendor via BGP routing registry and WHOIS records. Used where a vendor owns an ASN but does not publish a formal IP list. -
Community / OSINT
Derived from public security research, third-party network intelligence, or community investigation. Medium confidence. Treat with more caution in active blocking rules than Live JSON or Official docs entries. Revalidate before use if the verification date is older than 90 days.
How to retrieve
- Access within the Recorded Future application at the following links:
- Download via API using the List API:
- AI Infrastructure: https://api.recordedfuture.com/list/report:BSMV2G4/entities
- Chinese AI Infrastructure: https://api.recordedfuture.com/list/report:BSlDgZZ/entities
Recommended retrieval time is daily. The files are updated ~weekly so retrieving daily will reduce a long lag between publish and retrieval without unnecessary data processing.
How to use
The list is designed to be imported directly into security tooling or used as a reference for manual policy configuration. The three fields map to common SIEM, firewall, and TIP ingestion formats.
Firewall and proxy enforcement
Import the Entity field into a next-generation firewall (NGFW), Secure Web Gateway (SWG), or SASE platform. Use SNI-based or DNS-based filtering for domains rather than IP-only rules — many AI services use shared CDN infrastructure where IP blocking creates collateral damage. IP and CIDR entries with a Live JSON or Official docs association method can supplement domain rules with confidence.
Filter by Chinese AI vs all AI to determine if you want to block or monitor only a subset. The service provider in the Comment field lets you build per-vendor policies rather than a flat rule set.
SIEM detection and alerting
Import the list as a lookup table or watchlist in your SIEM (Splunk, Microsoft Sentinel, Google Chronicle, Elastic, etc.). Match the Entity field against DNS query logs, proxy logs, or NetFlow records. When an alert fires, the Comment field provides immediate triage context: the service provider identifies the AI tool, the verification date indicates how current the attribution is, and the association method signals confidence level.
High-signal detection rules to build:
- Connections to high-risk entities from endpoints without a documented business justification
- First-time connections to any AI tool entity from a service account or server — AI traffic from non-user endpoints is anomalous in most environments
- High-volume outbound data to vibe-coding deployment domains (
vercel.app,lovable.app,replit.app) from development machines - Any connection to autonomous agent domains (
openclaw.ai,clawhub.com,moltbot.com) — treat as a potential credential exfiltration event
Network Detection and Response (NDR)
Use CIDR entries with a Live JSON or Official docs association method as feed inputs for your NDR platform. CIDR match attributes flows to a specific AI vendor even when TLS inspection is unavailable. The service provider in the Comment field populates attribution labels in your flow data. API calls to vendor endpoints from non-user endpoints are high-signal events worth separate alert rules.
Data Loss Prevention (DLP)
Use domain entries to configure DLP inspection policies for traffic to AI tool endpoints. Outbound POST requests carry prompt content that may include sensitive data. For high-risk entries, data transiting to Chinese-domiciled services is subject to PRC law regardless of content type. For Community / OSINT entries, check the verification date — entries older than 90 days should be revalidated before inclusion in DLP policy.
Shadow IT discovery
Run the full entity list against 30–90 days of historical DNS and proxy logs before enforcing policy. Segment results by service provider and risk score to prioritize. Vibe-coding deployment domains and Chinese AI tools are the most commonly undiscovered categories in a baseline pass.
Cautions and limitations
IP blocking alone is insufficient
Many AI tools use shared CDN infrastructure (Cloudflare, AWS CloudFront). Their traffic resolves to anycast IPs shared by thousands of unrelated services. Domain-level filtering via SNI inspection or DNS controls is the primary control; IP and CIDR rules from Live JSON or Official docs sources supplement but do not replace it.
Treat the verification date as a freshness signal
For Live JSON entries, the date reflects the vendor's own creationTime. For Official docs and Community / OSINT entries, it reflects manual verification. Entries older than 90 days — particularly Community / OSINT — should be revalidated before use in active blocking rules. IP assignments and CDN providers do change.
Wildcard deployment domains require contextual controls
Several domains (vercel.app, lovable.app, replit.app, bolt.host) are also used by legitimate non-AI applications. Blocking at the domain level will affect unrelated services. Use endpoint context — source process, user account, and data volume — to distinguish AI-generated shadow IT deployments from sanctioned applications.
Chinese AI tools require layered controls
Most Chinese-domiciled AI tools serve global traffic through Cloudflare or regional cloud providers, making IP-only detection unreliable. Combine domain blocking (SNI or DNS) with GeoIP rules targeting the AS numbers of Chinese cloud providers: AS38627 (Baidu), AS45102 (Alibaba Cloud), AS132203 (Tencent Cloud), AS139070 (ByteDance). These AS numbers also carry legitimate non-AI traffic.
Autonomous agents require endpoint controls
OpenClaw and similar tools run locally on user machines. Domain blocking prevents installation and skill downloads but does not stop an already-installed instance. Endpoint detection is required: process names referencing openclaw, clawdbot, or moltbot; Node.js processes on port 18789; new files in ~/.moltbot/skills/. CVE-2026-25253 (CVSS 8.8) exposes stored AI API credentials — treat any detected instance as a credential compromise event.
Community / OSINT entries carry less certainty
Before using a Community / OSINT CIDR in an active blocking rule, validate ownership via reverse DNS, TLS certificate inspection, or BGP/WHOIS lookup. A false positive in a blocking rule can disrupt unrelated services sharing the same infrastructure.
Proxy and gateway domains mask underlying providers
Several entities act as proxies to multiple AI providers. Vercel's AI Gateway (sdk.vercel.ai) routes to OpenAI, Anthropic, and Google from a single endpoint. Poe (poe.com) aggregates Claude, GPT, Gemini, and Mistral. A single connection to these entities may represent calls to any number of underlying providers. Apply policy at the proxy domain level with that context in mind.
This list is a point-in-time snapshot. The verification date in the Comment field is the primary freshness signal — treat Community / OSINT entries past 90 days as candidates for revalidation before use in active rules.