Pretty easy to enforce it - rather than make raw queries to the LLM Claude Code can proxy through Anthropic's servers. The server can then enforce query patterns, system prompts and other stuff that outside apps cannot override.