

If it was “easy to police now with AI,” then companies wouldn’t still regularly have issues with all kinds of code injection on their websites, since literally any security vendor would have implemented bulletproof AI protection for it already.
An AI model designed for moderation could probably block some things, but it would be no better than traditional mechanisms employed by large organizations who’s job it is to keep things secure, that still regularly fall victim to these kinds of vulnerabilities. Many of these organizations already use AI-powered tools to police their systems, and they know they’re not anywhere close to even being a full replacement, let alone foolproof.
“No no guys you don’t understand, robots.txt actually means just search engines, it totally doesn’t imply all automated systems!!!”