Azure API Management AI gateway
Microsoft
AI gateway policies in Azure API Management for LLM, MCP and A2A APIs: token limits, semantic caching, content safety and load balancing.
Curated by Tiberiu ArvaVerified
Strengths
- Per-consumer token limits and quotas
- PTU-aware priority load balancing
- Foundry integration for models, agents, tools
Practitioner note
The natural choice for Azure OpenAI / Foundry estates that already run APIM, especially to spread PTU and pay-as-you-go capacity across many apps. Check that the policies you need are available in your APIM tier, and note that semantic caching needs Azure Managed Redis or another RediSearch-compatible cache.
Warning
Governance posture
Reviewed 2026-09-30Instances deploy to chosen Azure regions; the self-hosted gateway (Developer/Premium) keeps traffic in customer environments, but it still sends config, heartbeat and optional telemetry traffic to Azure.
SourceManaged Azure service; the containerized self-hosted gateway enables hybrid and multicloud data planes. (saas, hybrid)
SourceLogs prompts, completions and token usage to Azure Monitor / Application Insights, with a built-in token dashboard.
SourceAzure is covered by the Azure SOC 2 Type 2 attestation; per-service scope is in the audit report.
SourceAzure is covered by the Azure ISO/IEC 27001:2022 certificate; per-service scope is in the certificate.
SourceISO 42001 scope for API Management not confirmed in the sources reviewed.
API gateway infrastructure, not an AI system placed on the market; obligations rest with the deployer and model providers. (role: not-applicable)
Proprietary Azure service; policies are APIM-specific, so there is Azure lock-in. (medium)
SourceEU AI Act obligations
Risk tier: Not applicable · as of 2026-08-23Source-backed information mapped from Azure API Management AI gateway's tracked risk tier — not legal advice. Obligations depend on how your organisation deploys the system; see the full obligation reference and timeline.
This record's EU AI Act risk tier is marked not applicable, so no tier-specific obligations attach. Deployers embedding it in an AI system in scope of the Act should assess that system's own tier.
Explore the category
Compare this tool against the rest of its category and the cloud platform foundation layer.
Return to the category grid to compare governance posture across every tracked tool.
Review Microsoft Foundry, Amazon Bedrock, and Gemini Enterprise Agent Platform as the foundation layer.
Track releases, deprecations, license changes, and other market movements.