You’re trying to access a legitimate AI tool. Your internet provider stops you. Their message? “This site has been blocked for your own protection.”
That’s not a dystopian scenario. It’s happening right now. SFR, a major French ISP, is blocking opencode.ai – a perfectly legitimate AI coding assistant – and redirecting users to a page that says exactly that. The worst part? If you ask why, you get silence.
“When your ISP decides what’s dangerous, you’re not protected – you’re silenced.”
This isn’t just a French ISP problem. Comments on Hacker News reveal that other providers are also failing to load the site. One user reported that even after changing DNS, the page wouldn’t open. Another pointed out that multiple security services, including VirusTotal, flag the domain as malicious. So the block is likely coming from centralized threat intelligence feeds – the same opaque, automated systems that power most ISP security filters.
Here’s the contradiction: these feeds are designed to protect you from malware, phishing, and scams. But they operate with zero transparency. A single automated flag from a third-party service can cut off your access to an entire tool, with no appeal process, no human review, and no explanation beyond a generic safety message. You’re supposed to trust that the system knows better than you.
Except it doesn’t. OpenCode.ai is a legitimate AI development platform used by thousands of developers. It’s not hosting malware. It’s not phishing. But because some automated scanner – with no context, no accountability, and no due process – decided it’s suspicious, entire networks treat it as a threat.
This is the hidden censorship of the modern internet. Not a government ban, not a court order. Just a silent, automated decision that erases a digital tool from your reach. And the more we rely on these centralized threat feeds, the more fragile our access becomes.
“The internet isn’t free when a single algorithm can decide what you can’t see.”
Let’s be clear: I’m not arguing against security. Malware is real, phishing is real, and ISPs have a role to play. But the current system is a one-way ratchet. Once a domain is flagged, it’s nearly impossible to get unblocked. And the providers hiding behind the ‘protection’ narrative face no consequences for overblocking. They’re not incentivized to be accurate – they’re incentivized to be cautious.
So what can you do? First, don’t assume the block is justified. Second, use alternative DNS or VPNs – but that’s a band-aid, not a fix. Third, push for transparency. Ask your ISP which threat feed they use. Demand a human review process. If a tool like opencode.ai is blocked, someone should be able to say why.
This isn’t about one AI tool. It’s about the principle of an open internet. When automated systems can arbitrarily cut you off from legitimate resources, and hide behind a ‘for your own good’ message, we’ve traded freedom for a false sense of safety.
“Protection without accountability is just control.”
The next time your browser shows a block page, don’t click away. Ask yourself: who decided this was dangerous? And why should I trust them?
FAQ
Q: But isn't blocking malicious domains a good thing for security?
A: In theory, yes. But the problem is false positives from opaque automated systems. Legitimate tools like opencode.ai get blocked with no recourse, and ISPs have no incentive to be accurate—only cautious. That's not security, it's censorship by default.
Q: What's the practical implication for me as a user?
A: You can't trust that a block is justified. If a site you need gets flagged, you have to work around it (VPN, alternative DNS) instead of challenging the decision. For developers relying on AI tools, this is a productivity killer. For the rest of us, it's a reminder that the internet is more fragile than we think.
Q: Isn't the contrarian take that the threat feeds are actually correct and opencode.ai might be malicious?
A: It's possible, but the evidence points otherwise. OpenCode is a well-known platform used by developers. The real issue is that we have no way to verify. The system lacks transparency, and that's the danger—even if this particular block were justified, the process is broken. We need decentralized trust models, not black-box blacklists.