Blog
  • AI Gateway
  • AI Security
  • AIOps
  • API Security
  • API Gateway
    • API Management
    • API Development
    • API Design
    • Automation
    • Service Mesh
    • Insomnia
    • View All Blogs
  1. Home
  2. Blog
  3. Enterprise
  4. The AI Governance Wake-Up Call
Enterprise
December 12, 2025
5 min read

The AI Governance Wake-Up Call

Taylor Hendricks
Director, Customer & Growth Marketing, Kong

Companies are rapidly adopting AI, but it's not all roses. The excitement comes with significant risks, such as shadow AI, runaway costs, and security nightmares. This post explores the real challenges organizations face in AI governance today and highlights how forward-thinking companies are beginning to tackle them.

Topics
AIAgentic AIAI GatewayGovernance
Share on Social

Table of Contents

  • The excitement is real, but so is the anxiety
  • Challenges: What's keeping leaders up at night
  • The path forward: What winners are doing differently
  • The bottom line

More on this topic

eBooks

Maturity Model for API Management

eBooks

Federated API Management: Accelerating Innovation with Autonomy and Oversight

See Kong in action

Accelerate deployments, reduce vulnerabilities, and gain real-time visibility. 

Get a Demo
Introduction

The excitement is real, but so is the anxiety

Companies are charging headfirst into AI, with research around agentic AI in the enterprise finding as many as 9 out of 10 organizations are actively working to adopt AI agents. 

LLMs are being deployed, agentic workflows are getting created left and right, and the promises of what this technology will bring are endless. But behind the scenes, our customers tell us that there's another piece of the story, with shadow AI, runaway costs, security nightmares, and organizational uncertainty.

We recently spoke with some of our customers about AI governance – the good, the bad, and the ugly – and the message was unanimous: the opportunity is massive, but the risks are too.

Here's what we learned about the real challenges around AI governance that companies are facing today — and how forward-thinking organizations are starting to solve them.

Challenges

Challenges: What's keeping leaders up at night

1. Shadow AI is spreading faster than governance can catch up

One fear we hear about again and again? Teams are moving independently while leadership scrambles to establish guardrails.

Engineers are spinning up their own MCP servers, calling LLMs directly, and creating hordes of agents while platform teams worry about future cleanup nightmares.

One of our 2025 Kong Innovator Award winners, H&M, experienced this firsthand. As teams across the organization began adopting LLMs independently, the company found itself facing security risks, operational inefficiencies, and a complete lack of financial governance. Without centralized visibility, it was nearly impossible to scale AI safely across the enterprise.

The root cause? Teams are unsure whether governance belongs to AI squads, platform engineering, security, or a new AI Center of Excellence, leading to slow decision-making while engineers move fast on their own.

2. Your APIs probably aren't agent-ready (and that's a problem)

Elizabeth Brand, VP and Global Head of Cloud at Prudential, speaking at our API Summit 2025, described AI as a "once-in-a-decade opportunity" to solve previously difficult and time-consuming problems. Prudential is using AI to refactor legacy applications, decompose them into smaller components, and eliminate duplicate APIs — transforming modernization timelines from years to weeks or months.

But here's the catch: most organizations we talk to admit that their APIs are far from agent-ready, with missing specs, inconsistent design, and poor observability remaining as blockers.

The challenge is compounded by data privacy and security fears, with everyone anxious about PII exposure, accidental data leaks, and targeted attacks.

3. Token costs are the new cloud bill shock

Remember when cloud costs spiraled out of control because nobody was watching? AI governance faces the same risk — but faster.

Token spending is unpredictable and already scaring finance teams, with customers desperate for centralized limits, multi-model routing, and semantic caching to avoid these runaway costs.

Another Kong Innovator Award winner, SeatGeek, created a solution to address this challenge. 

As LLMs became central to their operations, SeatGeek faced a challenge: these LLM requests looked just like ordinary HTTP traffic, making it nearly impossible to ensure trust and safety in AI-driven integrations. The team at SeatGeek used Kong to create centralized LLM request validation at the API gateway layer, which eliminated the risk of spoofed traffic, avoided duplicating code across more than a dozen microservices, and reduced engineering time by 2–3 weeks per service.

4. It's a people problem just as much as a tech problem

Perhaps the most interesting insight from our customers: API teams speak in terms of requests and responses, while AI teams talk about tokens and models, making bridging that language gap part of governance itself.

Education, change management, and internal alignment repeatedly came up as the largest blockers to effective AI governance. But this is nothing new. For any large-scale, enterprise-wide project, the people piece will always be one of the major challenges, even more so than the technology.

Solutions

The path forward: What winners are doing differently

1. Centralize before it's too late

Customers see the risks of decentralization and are actively exploring AI gateways and MCP gateways to regain control.

H&M's transformation illustrates this perfectly. By implementing Kong AI Gateway, they pivoted from a fragmented, high-risk model to a secure, scalable, and governed AI platform with centralized control, observability, and governance for all AI traffic. 

The results? AI service onboarding time dropped from weeks to days, they gained immediate financial oversight and cost visibility, and they established 100% centralized logging and auditability for compliance.

2. Treat API hygiene as a must-have, not a nice-to-have

Good specs, security scopes, and predictable behavior aren't nice-to-haves anymore — they're prerequisites for safe agentic workloads.

Prudential's approach demonstrates this. By breaking down applications into smaller components and eliminating API duplication, they're reducing ecosystem complexity while preparing their infrastructure for AI-driven workflows.

3. Make cost governance part of the conversation now, not later

Companies are already looking for ways to control token consumption and avoid bill shock. Implementing AI governance is an essential part of keeping your finance team happy, as well as your developers.

As H&M was building its centralized AI governance platform, the team implemented Kong AI Gateway features like intelligent LLM routing and centralized rate limiting for AI traffic to avoid incurring runaway costs. The team anticipates seeing major savings going forward — and having the visibility to predict the costs they will have.

4. Embrace the learning curve

Here's the surprising silver lining: none of our customers claim to have figured out the one simple solution to solving AI governance problems. The playbooks are still being written, so everyone has the chance to think creatively and put innovative solutions in place.

As Liz Brand from Prudential put it, companies in the successful 5% are those that obsessively learn and relentlessly pursue different solutions than what worked a decade ago. This is a "wipe the slate clean" moment.

Conclusion

The bottom line

AI governance isn't a future problem: it's the AI reality. The organizations that will succeed aren't necessarily the ones with the most AI projects or the biggest budgets. They're the ones who recognize that governance, security, and cost control need to be built into the foundation, not bolted on after the fact.

84% of companies report a hit to gross margins from AI costs. Sustainable AI businesses avoid the hidden AI fragmentation tax by being proactive.

The good news? You're not alone in figuring this out. Every organization — from global retailers to financial services giants — is navigating the same challenges. The difference between chaos and control comes down to one thing: centralizing governance before shadow AI forces your hand.

Ready to take control of your AI governance strategy? Learn more about how Kong AI Gateway is helping enterprises scale AI securely and cost-effectively. Contact us to get started.

AI-powered API security? Yes please!

Learn MoreGet a Demo
Topics
AIAgentic AIAI GatewayGovernance
Share on Social
Taylor Hendricks
Director, Customer & Growth Marketing, Kong

Recommended posts

You Might Be Doing API-First Wrong, New Analyst Research Suggests

Kong Logo
EnterpriseSeptember 3, 2025

Ever feel like you're fighting an uphill battle with your API strategy? You're building APIs faster than ever, but somehow everything feels harder. Wasn’t  API-first  supposed to make all this easier?  Well, you're not alone. And now industry analys

Heather Halenbeck

Announcing the Kong Agentic AI Hackathon

Kong Logo
NewsAugust 12, 2025

Kong-quer the Agentic AI Hackathon 🚀 Calling all builders, tinkerers, and API innovators. The Kong Hackathon is back for  API Summit 2025 ! This year, we’re challenging developers worldwide to create projects that don’t just react, they  think ,  a

Juhi Singh

How to Build a Multi-LLM AI Agent with Kong AI Gateway and LangGraph

Kong Logo
EngineeringJuly 31, 2025

In the last two parts of this series, we discussed How to Strengthen a ReAct AI Agent with Kong AI Gateway and How to Build a Single-LLM AI Agent with Kong AI Gateway and LangGraph . In this third and final part, we're going to evolve the AI Agen

Claudio Acquaviva

How to Build a Single LLM AI Agent with Kong AI Gateway and LangGraph

Kong Logo
EngineeringJuly 24, 2025

In my previous post, we discussed how we can implement a basic AI Agent with Kong AI Gateway. In part two of this series, we're going to review LangGraph fundamentals, rewrite the AI Agent and explore how Kong AI Gateway can be used to protect an LLM

Claudio Acquaviva

How to Strengthen a ReAct AI Agent with Kong AI Gateway

Kong Logo
EngineeringJuly 15, 2025

This is part one of a series exploring how Kong AI Gateway can be used in an AI Agent development with LangGraph. The series comprises three parts: Basic ReAct AI Agent with Kong AI Gateway Single LLM ReAct AI Agent with Kong AI Gateway and LangGr

Claudio Acquaviva

Build Your Own Internal RAG Agent with Kong AI Gateway

Kong Logo
EngineeringJuly 9, 2025

What Is RAG, and Why Should You Use It? RAG (Retrieval-Augmented Generation) is not a new concept in AI, and unsurprisingly, when talking to companies, everyone seems to have their own interpretation of how to implement it. So, let’s start with a r

Antoine Jacquemin

AI Gateway Benchmark: Kong AI Gateway, Portkey, and LiteLLM

Kong Logo
EngineeringJuly 7, 2025

In February 2024, Kong became the first API platform to launch a dedicated AI gateway, designed to bring production-grade performance, observability, and policy enforcement to GenAI workloads. At its core, Kong’s AI Gateway provides a universal API

Claudio Acquaviva

Ready to see Kong in action?

Get a personalized walkthrough of Kong's platform tailored to your architecture, use cases, and scale requirements.

Get a Demo
Powering the API world

Increase developer productivity, security, and performance at scale with the unified platform for API management, AI gateways, service mesh, and ingress controller.

Sign up for Kong newsletter

Platform
Kong KonnectKong GatewayKong AI GatewayKong InsomniaDeveloper PortalGateway ManagerCloud GatewayGet a Demo
Explore More
Open Banking API SolutionsAPI Governance SolutionsIstio API Gateway IntegrationKubernetes API ManagementAPI Gateway: Build vs BuyKong vs PostmanKong vs MuleSoftKong vs Apigee
Documentation
Kong Konnect DocsKong Gateway DocsKong Mesh DocsKong AI GatewayKong Insomnia DocsKong Plugin Hub
Open Source
Kong GatewayKumaInsomniaKong Community
Company
About KongCustomersCareersPressEventsContactPricing
  • Terms•
  • Privacy•
  • Trust and Compliance•
  • © Kong Inc. 2025