AI Security
The control blocks the tool and leaves the threat alone
Blocking github.com at the firewall stops nobody and costs your engineers an hour a day. Here is how to tell a control that manages risk from one that manages appearances, and what to replace the theater with.
September 19, 2026 · 6 min read

A practitioner complaint I keep seeing, in slightly different words every time: a meaningful share of the controls in place are theater. The example that comes up most is blocking github.com at the firewall because it hosts malware, with no sanctioned alternative offered, in an organization full of engineers who need packages.
I want to take that complaint seriously rather than dismiss it as grumbling, because the people making it are usually right, and because the pattern has a specific shape you can learn to recognize.
The test
A control is theater when it satisfies all three of these:
It blocks a tool rather than a behavior. It offers no sanctioned path to the legitimate work it interrupted. And nobody can name the specific threat it stops, only a category it sounds related to.
That third one is the sharpest test. Ask the owner of a control what precise sequence of events it prevents. A real control has an answer with actors and steps in it. Theater has an answer that is a noun phrase: malware, data loss, AI risk. If the answer is a category rather than a sequence, you are looking at a control that was adopted for how it reads in a policy document.
Three that fail the test, and what the threat actually was
Blocking the code host. The stated threat is malware on a public repository. The actual threat, for almost every organization, is not a developer browsing a repository page. It is a malicious or compromised package pulled into a build and executed by CI with credentials attached. The block never touched that path, because the package came through the registry, not the website. Meanwhile every engineer now routes around it through a phone or a personal machine, which moves the activity somewhere with no logging at all.
The replacement is a private registry or proxy with dependency scanning, lockfiles, and a policy on transitive dependencies, plus build credentials scoped so a malicious postinstall script cannot reach production. That is more work than a firewall rule. It is also the only version that addresses the thing you were worried about.
Ninety-day password rotation with no compromise signal. The stated threat is a stolen password staying valid. The actual result, documented well enough that NIST changed its guidance, is that forced periodic rotation pushes people toward predictable variations and written-down passwords, which is a net loss. The threat it was aimed at is better handled by phishing-resistant MFA and by rotating on evidence of compromise rather than on a calendar.
Annual click-through security awareness training as the control for phishing. The stated threat is employees clicking links. The control is a video watched at 2x on the last day of the compliance window. Nobody believes it changes behavior, including the people who administer it. The replacement is making the click survivable: phishing-resistant authentication so a harvested credential is not enough, and a reporting path that is fast and blameless so the ten minutes after a click are useful instead of spent deciding whether to admit it.
Notice the pattern in all three. The theater version regulates a person. The working version changes the system so the person's mistake does not matter as much.
The AI version of this is arriving now
Everything above is the old form. The new form is showing up in AI governance and it follows the identical shape.
Banning ChatGPT at the network edge while a meaningful fraction of staff have phones is the github.com rule wearing new clothes. It does not stop the paste. It relocates the paste to a device you cannot see, and it destroys the one thing you had, which was visibility into what people were doing and why.
An acceptable-use policy that says do not put confidential data in AI tools, with no sanctioned tool that does the job, is the same failure. The work still has to get done. You have expressed a preference, not implemented a control.
And a vendor questionnaire that asks whether a supplier uses AI, without asking what data goes to the model, whether there is a signed agreement behind it, what the retention window is, or whether the session is logged, produces a yes or no in a file and tells you nothing that would change a decision.
The working versions look like the ones above. Give people a sanctioned tool that is fast enough to actually use, because a governed tool nobody uses governs nothing. Put the control at the data layer and the identity layer where it sees what the network cannot. And ask vendors the four contract questions that separate a managed risk from an unmanaged one, rather than asking whether AI is present.
Why theater survives
It is worth being honest about why these controls persist, because the answer is not stupidity.
Theater is legible. A firewall rule, a rotation policy, and a training completion rate all produce a number you can put in a board deck and an auditor's folder. The replacements produce operational work whose success looks like nothing happening. When the person choosing controls is measured on demonstrable action, theater is the rational choice. It is cheap, it is fast, and it is reportable.
The cost is real but it lands on somebody else. Engineers lose an hour a day to workarounds. Clinicians route around the sanctioned path. And the organization loses the honest signal about what people are doing, which is the input every future decision needs. That cost never shows up next to the control that caused it.
If you want less theater, change what gets reported. A control inventory where each row names the specific sequence it interrupts, what legitimate work it blocks, and what the sanctioned alternative is will kill more theater than any amount of arguing, because most theater cannot survive having those three columns filled in.
The one question
When someone proposes a control, ask what a motivated person with a deadline does after it ships.
If the answer is that they do the work a different way that you cannot see, you have not reduced risk. You have reduced visibility, and you have paid for it in goodwill with the exact people whose honest reporting you will need the next time something actually goes wrong.