Network allow-lists cannot prevent data theft from LLMs using DNS tunneling or steganography. Attackers bypass these filters by hiding sensitive data within legitimate outbound requests. This vulnerability renders basic perimeter security ineffective against sophisticated prompt injection. Practitioners must implement deep packet inspection and strict output monitoring to secure their AI agents.