Gartner now grades API gateways on AI traffic. I built one for clinical AI a year ago.
By Eric St-Pierre · Written with AI assistance, reviewed and verified by the author
- AI Security
- Agentic AI
- AI Guardrails
- Model Context Protocol
- Healthcare
A year ago I built an AI gateway for clinical models. Gartner's 2026 API management report now puts AI gateways first. Here is what held up and what I would change.
What changed
A year ago, at ISC2 Security Congress 2025, I presented a design to protect AI models in healthcare. A gateway sits in front of the model. A policy engine scores the risk of each request. A second model checks the first. The full design is on our Labs page: Twin Gatekeeper.
On September 28, 2026, Gartner published its Magic Quadrant for API Management. It rates 17 vendors, and the first trend it lists is AI: "The adoption of LLMs and generative AI is turning API gateways into AI traffic mediators." So I went back to my design to see what held up.
What the report actually says
- AI gateways and the Model Context Protocol (MCP, a standard way for AI agents to call tools) come first in a list of five trends. The other four are managing many gateways from one place, AI agents as API consumers, token cost control, and market consolidation.
- AI is still optional. The required features are a portal, a gateway, policy management, governance and life cycle management. AI gateway and MCP support are listed as optional.
- Healthcare gets little attention. Gartner notes that Kong "does not offer vertical-focused features or tailored solutions for specific industries." Boomi offers healthcare accelerators, but Gartner adds that it "may not meet all specialized requirements." Most other industry notes point to banking.
A note on Kong: I used Kong's open-source gateway in my build. Gartner rated Kong's commercial products, which I did not use. No vendor named here pays Medoya or reviewed this post.
What it means for an engineering team
What I got right: one gateway for every model call. In my design, every request to the model went through the gateway, and the policy engine scored its risk and chose which checks to run. In May, six national cyber agencies recommended a central policy decision point for each request. Our policy layer played that role.
What I got right: cost per user and per agent. My design tracked token use at the gateway, so AI cost could be traced to a user or an agent. AI bills grow fast and are hard to explain, and Gartner now lists token cost control as a trend.
What I missed: AI agents as users. In my design, agents and tools sat behind the gateway, as things the model used. Gartner now describes agents as API consumers with their own identities and protocols. Today I would give each agent its own identity and limits in the policy engine.
What I missed: MCP. My design had no MCP. Today AI agents call tools through MCP, and Gartner lists MCP support as part of the top trend. I would send an agent's MCP tool calls through the same gateway as its model calls, so one policy sees both.
A gateway does not read meaning. In my design, the gateway handled access, rate limits and token use. Spotting an instruction hidden in an MRI image, the attack shown in a 2025 study, was the job of the checker model in the guardrail layer. When a vendor offers in-line guardrails, ask what they inspect: text only, or also images and audio.
Healthcare policy is still your work. A gateway enforces rules. It does not decide which data may leave the network, how risky an outside image is, or who may see what. In my project, that was most of the work. My own coverage table also left gaps that no gateway closes: supply chain risks and weaknesses in the vector database.
If your AI calls don't go through one place, you can't secure them, and you can't explain the bill.
What is still unsettled
Will AI support become a requirement? For now, a vendor can be in this market without AI gateway or MCP support. If you need them, check.
How do you test a guardrail? There is no agreed test. My own design was shown in a live demo, not measured against a benchmark.
How much AI use is governed today? Kong's AI Governance Gap report says 99% of organizations have no AI-specific governance controls. The figure comes from Kong's own traffic and the method is not public, so read it as a vendor's view.
Sources
- Gartner. Magic Quadrant for API Management. ID G00841473, September 28, 2026.
- Medoya Labs. Twin Gatekeeper: a three-layer AI gateway for clinical LLMs. Reference architecture presented at ISC2 Security Congress 2025.
- Australian Signals Directorate's Australian Cyber Security Centre, with CISA, NSA, the Canadian Centre for Cyber Security, NCSC-NZ and NCSC-UK. Careful adoption of agentic AI services. Joint guidance, May 1, 2026.
- Clusmann, J., et al. Prompt injection attacks on vision language models in oncology. Nature Communications 16, 1239 (2025). doi:10.1038/s41467-024-55631-x.
- Commentary. Kong. The AI Governance Gap: Enterprise AI Consumption & Market Report. 2026. Retrieved October 5, 2026.


