Kong AI Gateway

Kong

Commercial

AI and MCP governance layer on Kong Gateway: multi-LLM routing, semantic caching, prompt guards, PII redaction and MCP OAuth.

Curated by Tiberiu ArvaVerified

Apache 2.0 core + Enterprise plugins

Strengths

  • Builds on existing Kong API gateway estates
  • Generates MCP servers from REST APIs
  • Token-based rate limiting and PII redaction

Practitioner note

Makes most sense if Kong already runs your API traffic, because AI and MCP policies reuse the same data plane and control plane. Budget for Enterprise: most advanced AI and MCP plugins are not in the OSS build.

Warning

Kong AI Gateway: Open core: Kong Gateway and six basic AI plugins (ai-proxy, ai-prompt-guard, ai-prompt-decorator, ai-prompt-template, ai-request/response-transformer) are Apache 2.0, but advanced plugins such as AI Proxy Advanced and the MCP gateway features need the paid AI Gateway Enterprise offering.

Governance posture

Reviewed 2026-09-30
YesData residency

Data planes run in customer infrastructure; Konnect control planes available in AU, EU, ME, US, IN and SG (beta) regions.

Source
YesDeployment model

Konnect SaaS control plane, self-hosted Kong Gateway Enterprise, or hybrid. (saas, self-hosted, hybrid)

Source
YesAudit logging

Structured AI audit logs record payloads, token usage, model, latency, cost and guardrail block/mask outcomes; MCP traffic logging captures sessions and tool calls.

Source
UnknownSOC 2

Kong's trust center (trust.konghq.com) is JavaScript-rendered, and its certifications could not be read from a primary source in this review.

UnknownISO 27001

Kong's trust center could not be read from a primary source in this review.

UnknownISO 42001

No ISO 42001 claim found in the Kong sources reviewed.

N/AEU AI Act

API/AI gateway infrastructure, not an AI system placed on the market; obligations rest with the deployer. (role: not-applicable)

YesLicense risk

Open core: Apache 2.0 gateway, with key AI and MCP plugins available only in AI Gateway Enterprise. (medium)

Source

EU AI Act obligations

Risk tier: Not applicable · as of 2026-08-23

Source-backed information mapped from Kong AI Gateway's tracked risk tier — not legal advice. Obligations depend on how your organisation deploys the system; see the full obligation reference and timeline.

This record's EU AI Act risk tier is marked not applicable, so no tier-specific obligations attach. Deployers embedding it in an AI system in scope of the Act should assess that system's own tier.

Explore the category

Compare this tool against the rest of its category and the cloud platform foundation layer.