AI Security

Own the AI Gateway. Own the security platform.

The proxy between apps, agents, and every model is becoming the enterprise AI control plane — FinOps, governance, security, and observability in one choke point. CyberMerge desk ranking (not market-share %): who sits there, and why Palo Alto Networks is positioned to win the security-platform wallet.

Sep 24, 2026 · 9 min read

Every enterprise running production AI eventually hits the same architecture question: do you let every app and agent call OpenAI, Anthropic, Bedrock, Vertex, and a pile of MCP tools directly — or do you put a single proxy in the path? Vendors have a name for that proxy. They increasingly call it the control plane.

An AI Gateway (also LLM Gateway / AI Proxy) is centralized middleware between applications or agents and model providers — and increasingly MCP tools and agent-to-agent traffic. It is the enforcement and observation point for auth and key brokerage, multi-provider routing and failover, rate and budget limits, caching, logging, and often guardrails. The broader AI control plane is the governance authority above it: identity, policy, budgets, audit, inventory across gateways, models, tools, and agents. Runtime sits in the gateway. Policy and ops sit in the control plane. In 2026, vendors are marketing the gateway as the control plane.

That language is the vendors’ own. On May 29, 2026, Palo Alto Networks closed its acquisition of Portkey and framed the AI Gateway as a mission-critical control plane — the “central nervous system for all AI traffic,” in company press. On August 7, 2026, Cloudflare said Workers AI and AI Gateway were converging into a single AI control plane for observability, billing, security, and logging across hosted and third-party models. Microsoft’s Azure API Management AI Gateway tier (public preview docs fetched Sep 24, 2026) describes one place to publish, secure, govern, and observe access to AI models and MCP tools. LiteLLM markets an open-source AI Gateway and LLM proxy for platform teams. The category is real. The fight is over who sits in that choke point.

What actually sits in the proxy. Four jobs show up in every serious primary.

FinOps. Palo Alto’s April 30 intent PR on Portkey talked about eliminating “bill shock,” caching, and granular quotas. Cloudflare’s AI Gateway docs emphasize token and cost analytics, caching, and — after the August unification — prepaid credits across providers. Kong’s AI Gateway 3.11 press (July 15, 2025) called out prompt compression, semantic caching, and rate limiting to cut token cost. LiteLLM sells budgets, lowest-cost routing, and chargeback. None of these primaries publish a universal savings percentage.

Governance. Azure’s AI Gateway tier is framed as publish / secure / govern for models and MCP tools. Databricks positions Unity / Mosaic AI Gateway as the governance layer for models, agents, and MCP with Unity Catalog permissions, budgets, rate limits, guardrails, and cost attribution (2026 company blog). Okta’s Agent Gateway blog is identity-native: short-lived credentials, tool-call attribution, policy on the MCP/tool path — complementary to traffic gateways, not a substitute FinOps router.

Security. PANW’s thesis is runtime inspection via Prisma AIRS plus the gateway. Kong ships PII sanitization and a Bedrock Guardrails plugin path. Zscaler’s AI Guard / AI Protect materials describe Zero Trust inline prompt/response inspection — AI firewall adjacency. CrowdStrike’s Falcon Guardian (Sep 1, 2026 blog) is AIDR plus a forthcoming native AI gateway (pre-beta; vendor said GA “next quarter,” i.e. Q4, as of that post). Do not confuse Charlotte AI — a SOC agent — with a traffic gateway.

Observability. Cloudflare’s logging and analytics are core product language. PANW’s Portkey close PR tied the gateway narrative to Chronosphere observability. Helicone was the independent LLM observability + lightweight gateway name until Mintlify acquired it on March 3, 2026; Helicone’s own post put services in maintenance mode. That exit matters for anyone still underwriting Helicone as a long-term independent control-plane bet.

Ownership thesis. Whoever owns the gateway owns the choke point for policy, audit, token economics, and runtime stop. In a large enterprise, the durable buyer for a governed AI control plane is usually the security / platform-risk org, often with FinOps as co-buyer. AI risk budget sits with security. The gateway SKU follows. That is why security platforms buying or building the gateway is the strategic move of 2026 — and why a standalone FinOps proxy without security-platform pull-through is easier to displace.

CyberMerge desk Top 10 — editorial ranking, not market-share %. Share percentages for this category remain Undisclosed. This is a control-plane relevance ranking for enterprise readers as of Sep 24, 2026.

1. Palo Alto Networks — Prisma AIRS AI Gateway (ex-Portkey). Acquired: intent Apr 30, close May 29, 2026. Differentiator: only major security platform to buy a pure AI Gateway and brand it the enterprise control plane inside Prisma AIRS. SEC Form 10-Q (period ended Apr 30, 2026): total consideration $140 million in cash and replacement awards, subject to adjustments. Portkey Series A was $15M (Elevation Capital, Feb 19, 2026, GlobeNewswire). ARR and market share: Undisclosed. Vendor claim of “trillions of tokens per month” is qualitative — print as vendor claim, not desk metric.

2. Cloudflare — AI Gateway (+ Workers AI unification). Edge-native proxy for multi-provider and Workers AI: analytics, caching, rate limits, retries/fallback. Aug 7, 2026 blog: unified AI control plane and prepaid credits across providers. Product ARR: Undisclosed. Strongest developer / edge / multi-cloud FinOps motion.

3. Kong — Kong AI Gateway (+ Agent Gateway). API-platform lineage governing LLM, MCP, and A2A paths; prompt compression; Bedrock Guardrails plugins; Agent Gateway called out in AI Gateway 3.14 (Apr 14, 2026). Private company valuation and product ARR: Undisclosed. Best independent connectivity control plane for enterprises that refuse to hand the choke point to a security vendor.

4. LiteLLM (BerriAI). Dominant open-source self-hosted AI Gateway / LLM proxy: one OpenAI-compatible API across many providers; budgets; Enterprise SSO/RBAC; MCP/agents. Valuation and Enterprise commercial figures: Undisclosed. Likely wins share of instances; less of the enterprise security wallet unless embedded by platforms.

5. Databricks — Unity / Mosaic AI Gateway. Data-platform governance layer for models/agents/MCP with Unity Catalog permissions, budgets, rate limits, guardrails, cost attribution. Product ARR: Undisclosed. Wins when the lakehouse is already the system of record.

6. Microsoft — Azure API Management AI Gateway tier. Managed APIM tier: one endpoint for Foundry/OpenAI/Bedrock/Vertex/etc. plus MCP tools; token limits and content-safety policies; Entra admin. Public preview (East US 2, Sweden Central per docs fetched Sep 24). Pricing “announced later” in preview, so Undisclosed.

7. AWS — Bedrock Guardrails + AgentCore Gateway. Cloud-native agent/tool/model gateway: MCP aggregation, Lambda/OpenAPI/Smithy tools, ingress+egress auth; Guardrails for safety policy. Usage-based; ARR Undisclosed. Captive to AWS AI landing zones.

8. TrueFoundry — AI Gateway. Enterprise LLM/MCP/Agent Gateway emphasis: routing, policy, budgets, guardrails, VPC/on-prem posture (vendor claims). Funding/valuation in our primary set: Undisclosed. Appears on CrowdStrike’s open gateway partner list.

9. Vercel — AI Gateway. Developer-centric hosted gateway: hundreds of models, vendor claim of no markup on tokens, failover, budgets, ZDR routing; Stripe Billing meter-header integration for token billing (Vercel docs). Product ARR: Undisclosed. DX beachhead, not a CISO platform.

10. Solo.io — Gloo AI Gateway / agentgateway. AI/LLM plus agent connectivity for MCP/A2A from a service-mesh / API connectivity house. Product ARR: Undisclosed. We slot Solo here as the connectivity-native pick; Okta’s Agent Gateway is identity-native and complements traffic gateways — covered in the contender autopsy below, with GA timing still requiring re-verify against Okta primaries.

Honorable exits and adjacencies: Helicone → Mintlify (Mar 3, 2026; maintenance mode). OpenRouter for fast multi-provider DX with lighter enterprise governance. Gravitee, Tyk, Google Apigee + Model Armor as composed stacks. Zscaler AI Guard as inline AI security. NeuralTrust / Prompt Security / CalypsoAI / Protect AI / HiddenLayer / Lakera / WhyLabs / Cisco Robust Intelligence→AI Defense mostly as LLM security or posture — generally not full multi-provider FinOps control planes.

Contender autopsy — what each actually has.

Palo Alto Networks — yes, and it paid for category language. Portkey is inside Prisma AIRS AI Gateway. Close PR + SEC $140M consideration. Platform narrative ties to agent identity (CyberArk/Idira stack), observability (Chronosphere), and AIRS runtime. That is the ownership thesis in product form.

Cloudflare — yes. Shipping AI Gateway; unified control plane with Workers AI as of Aug 7, 2026. Different ICP: platform engineering and edge FinOps. Can win request volume while PANW wins security budget. Coexistence is plausible.

Stripe — no AI Gateway. Adjacent surface is real: Agentic Commerce Protocol (with OpenAI), Machine Payments Protocol, Metronome / token billing docs, and Vercel AI Gateway emitting Stripe Billing meter events via headers. Stripe wins the agentic payments and usage-billing layer — not the AI proxy control plane.

CrowdStrike — partial / forthcoming. Charlotte AI is a SOC agent, not a gateway. June 16, 2026: Open Gateway Ecosystem partners (Kong, LiteLLM, TrueFoundry, Azure, Databricks, and others per CRWD press). Falcon Guardian (Sep 1, 2026): AIDR plus native AI gateway in pre-beta, GA “next quarter (Q4)” per that blog. The native gateway is not shipping product yet.

Zscaler — AI firewall adjacency. AI Guard / AI Protect: Zero Trust inspection of GenAI traffic (prompt/response, DLP, jailbreak controls). Strong on inline AI security. Weaker evidence today as a Portkey-class multi-provider FinOps control plane.

Startups — yes, with varying enterprise depth. LiteLLM, TrueFoundry, OpenRouter, Vercel: real gateways. Depth of governance, VPC posture, and CISO procurement readiness varies. OSS + separate firewalls remains a falsifier for commercial security-platform gateways.

Who wins market share — desk call (opinion, not measured share).

Primary: Palo Alto Networks for enterprise security-platform AI Gateway share. Why: (1) only major security platform to buy a pure AI Gateway and publicly brand it the mission-critical control plane; (2) $140M SEC consideration signals ownership intent, not a press partnership; (3) distribution and trust via existing PANW enterprise seats and platform deals; (4) pull-through into Prisma AIRS + identity + observability increases switching costs once traffic flows through PANW; (5) AI risk sits with security, so the gateway SKU follows the security platform. We are calling wallet share inside security-platform AI deals, not a category share percentage.

Runner-up: Cloudflare for developer / edge / multi-provider FinOps share. Unified control plane, prepaid credits, global edge, low adoption friction. Different buyer than CISO-led AIRS deals. May win traffic volume even if PANW wins the security budget.

Wild cards. Azure APIM AI Gateway and AWS AgentCore Gateway if cloud commits absorb governance by default (Azure still preview; pricing TBA). CrowdStrike Falcon Guardian gateway if Q4 2026 GA converts AIDR+EDR seats into native gateway share. Kong remains the strongest independent API-platform alternative. LiteLLM remains the default self-hosted standard by deploy count.

Falsify the PANW primary call if… Portkey/AIRS integration stalls, Portkey customers churn, or PANW treats the gateway as a minor attach; RFPs standardize on Cloudflare or Kong as neutral infra with security tools only integrating; Azure/AWS make governed gateway free with AI landing zones and capture majority of governed traffic; CrowdStrike ships Guardian gateway GA and CISOs prefer AIDR+EDR-native; enterprises standardize on OSS LiteLLM plus separate LLM firewalls and refuse commercial security-platform gateways on latency or lock-in grounds.

What CISOs and platform leads should watch. First: define terms in the RFP — LLM/AI gateway (routing + FinOps + governance proxy) is not the same as an AI firewall, an eval platform, or a model router. Second: ask who sits in the hot path when an agent calls a model or MCP tool, and whether policy can stop the next request — not last quarter’s audit. Third: underwrite integration reality for Portkey inside Prisma AIRS, Cloudflare’s unified billing across third-party models, Azure’s path from preview to GA with clear pricing, and CrowdStrike’s Q4 gateway GA claim. Fourth: keep Stripe in the billing conversation and out of the gateway shortlist. Fifth: treat every share %, ARR, and private valuation not named above as Undisclosed.

Underwrite sheet — sourced only: AI Gateway = control-plane proxy (PANW close PR May 29, 2026; Cloudflare unification Aug 7, 2026; Azure APIM AI Gateway preview docs; LiteLLM site); Portkey → PANW close May 29 / intent Apr 30; SEC consideration $140M cash + replacement awards; Portkey Series A $15M Feb 19, 2026; Helicone → Mintlify Mar 3, 2026 maintenance mode; CRWD Falcon Guardian gateway pre-beta / Q4 GA language Sep 1, 2026; CRWD Open Gateway Ecosystem Jun 16, 2026; Stripe = ACP / MPP / token billing — no AI Gateway product; Zscaler AI Guard = inline AI security adjacency; Top 10 = CyberMerge editorial ranking — market share % Undisclosed; product ARR for Cloudflare/Kong/LiteLLM/TrueFoundry/Vercel/Okta/Solo Undisclosed; Azure AI Gateway pricing TBA. Own the gateway. Own the security platform — underwrite the choke point, not the slide.

Sources