Maybe because they are optimizing for response time, and the response is streamed back to the user. The backend isn't fully aware of the response until its too late. Still, you would think that they could run through the prefix and then redact text. I think Bing chat does this for a number of things.