Skip to content
CWS
CorovaAboutContact
Book a Call
All articles
Industry Insights

Banning the Chatbot Created Twelve Copies of It

A domain goes onto a block list, the proxy denies it, and the desktop installer stops downloading from that host. The blocked request count falls week after week, and the Friday report shows it falling. The count measures one domain, and the work behind that traffic moves onto paths the counter sits outside.

CWSAugust 14, 20266 min read

The block was the answer available that week

The decision arrives with something behind it. A customer's security review lands with a question about where staff input goes, or counsel reads a set of consumer terms and goes quiet. Somebody needs a response inside the week, and a block is the response that fits inside a week.

It is also cheap and it holds up in the room where it is made. The domain goes on the deny list, so the proxy refuses it and the installer stops downloading from that host. By Friday there is a report showing blocked requests, and over the following weeks that number comes down.

The number coming down is a true statement about the path you closed, which was one of several the estate offers. The demand behind the traffic came from the work and the date attached to it, and both of those sat exactly where they were on the day the block went in.

So the demand finds the next available path, and an estate of any size offers several.

  • A client installed before the block, still running on every machine that already has it
  • A personal account on a personal phone, on a phone network, with the document photographed or pasted in by hand
  • An extension installed from a browser store, holding permission to read the contents of every page it runs on
  • A model feature inside an application the organization already approved, already holding the same data
  • A free tier reached on a second domain that nobody thought to add to the block list
  • A script somebody wrote that calls a model API directly, with the key sitting next to it in the repository

You closed the copy you had an administrator for

Look at what the blocked tool had attached to it. Where it entered through procurement, it brought an agreement, a tenant, an administrator somebody appointed, a sign-in path through your identity provider and a data processing term a lawyer read.

That list describes an instrument. Every item on it is a place where your organization can see something, change something or stop something. The list is a description of your own position in relation to the product, and that is all it describes.

Now look at where the usage went. A personal account runs on consumer terms between the vendor and the individual, and your organization is not a party to them. An extension's permissions were accepted by the person who installed it, inside a browser profile nobody administers. A script's key belongs to whoever created it.

Follow that through and the shape of the outcome is predictable. The governed copy goes quiet on the day of the block, and several ungoverned arrangements come up around it, each carrying a piece of the work.

  • An administrator who can change a retention setting for everybody at once
  • A sign-in path you can revoke on the day somebody leaves
  • A log that answers a question from counsel with names and timestamps
  • A named contact at a company that has signed something with your company
The copy you blocked was the copy you had an administrator for. Everything that replaced it belongs to an individual.

A ban turns a governance problem into a discovery problem

Before the block, the problem had a shape. One named system, one owner, a configuration to argue about, a retention period to pick. That work is slow and political, and all of it happens against something you can point at.

After the block, the first question is which systems exist, and that question is harder than any configuration argument, because the population has to be established before anything true can be said about it. Counting what replaced the blocked tool is itself unreliable, because part of what replaced it produces nothing to count.

One property of the block deserves naming here. Its telemetry reports on the path it closed, so the weekly report is a description of that closure. Residue is still worth pulling, and it will find some of what moved.

The rest is reachable by asking people, and the yield depends on what those people expect to happen to them when they answer. A prohibition is a poor backdrop for that conversation, because the honest answer is now an admission.

The difficulty has a mechanism worth stating plainly. Enumerating AI usage draws on a small number of evidence sources, and displacement removes them one at a time.

  • A personal device on a phone network puts the traffic outside every network you monitor
  • A free tier keeps the spend below expense records and purchase orders
  • A personal account keeps the sign-in outside your identity provider
  • Content pasted in on a phone leaves its trace on a device outside your endpoint estate
A prohibition converts a configuration argument into a census. Budget for the census in the same meeting that signs off the block.

What a block should leave on the record

A block is a governance decision, and it travels on a change ticket, which records what was done. A year later somebody asks why the domain is denied, and the answer is that it has always been denied.

Published frameworks help here at a narrow level. SAIL 2.0, the Secure AI Lifecycle Framework CWS contributed to, puts the identification of AI systems early in the sequence, and a prohibition is precisely what disturbs that step. ISO/IEC 42001 asks an auditor to see the decision, who took it and when it was last reviewed. Where the EU AI Act applies, counsel makes a role determination per system, which requires the system to be in view.

So write the block down properly while it is still the current answer.

  • The reason, in a sentence somebody is able to disagree with
  • The person who owns the decision, by name and role
  • A review date close enough that the review happens
  • The sanctioned option people are expected to use in the meantime, with its limits written down
  • What the organization will look at to judge whether the block is holding, agreed before the first report

Making the sanctioned path the easy one, and what that costs

Here is where CWS stops reporting and starts arguing. A prohibition holds only where the sanctioned option does the work people were reaching for at the moment they reached. Short of that, the block keeps producing displacement, and it gets quieter over time as people find arrangements that attract no attention.

Good enough is a claim about capability, and the way to settle it is to look at what people were doing. The team that pasted a fifty page contract in needs something that takes a fifty page contract. The person who reached for it at eleven at night needs it without a form in front of it. A tier that covers most of the work sends the remainder back out, and the remainder is what the tier stopped short of: the long document, the unusual format, the request that needed the larger model. Sensitive material travels in exactly those shapes.

Then there is the cost, and this is where the argument gets honest. A block is a firewall rule and a change ticket. What makes a block hold is a license tier that does the work, bought for the whole population doing it, plus a configured data boundary, an owner, a support route, and something that tells people what is permitted in terms they can apply. That is a budget line and a named team, and the comparison the room gets offered is between a block and nothing.

Bringing the displaced usage back is the last piece, and the ban made it harder. Somebody who moved to a personal account has been outside the policy for months, and declaring it now means volunteering for a conversation about those months. An amnesty covering whatever is declared inside a stated window is what gets the declarations, and it has to be announced before the first conversation, because it cannot be withdrawn halfway through.

The original block stands as a reasonable act. It was the answer available in the week it was needed, and holding actions are part of running a security function. The cost lands later, when it stays in place as the whole plan and becomes a discovery problem somebody inherits. So take the replacement to whoever approved the block, as funded work with a list attached.

  • A license tier that handles the work people were doing, for the whole population doing it
  • A configured data boundary, with somebody named against the configuration
  • A route into the sanctioned option that takes minutes for the cases the default already covers
  • A short intake for the cases it does not cover, carrying a decision date
  • A declared amnesty window for anyone bringing usage back, announced before the first conversation
A block costs a firewall rule and a change ticket. Making a block hold costs a budget line, an owner and a configuration somebody has to defend.

Sources

  • SAIL 2.0, the Secure AI Lifecycle Framework, which CWS contributed to
  • ISO/IEC 42001, AI management system standard
  • EU AI Act
  • Prohibition read as a holding action, and the cost of a sanctioned replacement: CWS opinion, open to challenge.