Network administrators also solved these things, e.g. you can limit what websites a virtual machine is allowed to access.
Now, if you’re letting your agents abuse network traffic there becomes a point where you’re criminally liable. Unfortunately the current US government has no interest in prosecuting such abuse.
It's not so easy, because HTTPS thwarts attempts to filter out unwanted API calls, for example.