Strict network allow-lists cannot prevent sophisticated data exfiltration from AI agents. Attackers bypass these filters using DNS tunneling or steganography to leak sensitive tokens. This failure proves that perimeter security is insufficient for autonomous systems. Practitioners must shift toward runtime monitoring and strict input-output validation to secure model environments.