Blog
  • AI Gateway
  • AI Security
  • AIOps
  • API Security
  • API Gateway
|
    • API Management
    • API Development
    • API Design
    • Automation
    • Service Mesh
    • Insomnia
    • View All Blogs
  1. Home
  2. Blog
  3. Enterprise
  4. Kong AI Gateway and the EU AI Act: Compliance Without the Rewrites
Enterprise
November 26, 2025
4 min read

Kong AI Gateway and the EU AI Act: Compliance Without the Rewrites

Jordi Fernandez Moledo
Principal Architect, Kong

The EU AI Act is here, and for many enterprises, it represents a massive coordination challenge. As the world’s first comprehensive AI law, it mandates strict governance on transparency, risk management, and data quality.

For platform engineers and architects, the immediate question is operational: How do we comply with these new regulations without forcing every developer to rewrite their applications?

If you leave compliance to individual application teams, you risk fragmentation — different logging standards, inconsistent guardrails, and "shadow AI" usage that exposes the organization to fines. The answer lies in centralization. By positioning Kong AI Gateway as your AI control plane, you can enforce the EU AI Act’s requirements globally, acting as a "trust layer" that governs all AI traffic regardless of the underlying model or application.

Here's how Kong helps you map directly to the key articles of the EU AI Act.

Topics
AIAI GatewayGovernance
Share on Social

Table of Contents

  • Data Governance & PII Protection (Article 10)
  • Logging & Traceability (Articles 12 & 26)
  • Risk Management & Guardrails (Articles 9 & 15)
  • Transparency (Article 50)
  • Human Oversight (Articles 14 & 26)
  • The "No Rewrite" Compliance Strategy

More on this topic

Webinars

Building The API Platform For Platform Builders: Where Kong Goes Next

Webinars

Drive real AI value with state of the art AI infrastructure

See Kong in action

Accelerate deployments, reduce vulnerabilities, and gain real-time visibility. 

Get a Demo
Article 10

Data Governance & PII Protection (Article 10)

The Requirement: Article 10 of the EU AI Act mandates strict data governance for high-risk AI systems. This includes error detection, bias monitoring, and arguably most critically for enterprise use — ensuring that sensitive personal data (PII) is not improperly processed or leaked into public models.

The Kong Solution: Instead of asking developers to manually sanitize inputs in every Python script or Java app, you can enforce data governance at the gateway level before the request ever leaves your perimeter.

  • AI PII Sanitizer: Automatically detects and redacts entities like names, SSNs, and emails from prompts before they reach the LLM.
  • Prompt Guard and Response Guard: Enforce a hard boundary on what data enters and exits your organization, preventing "data leakage" that could violate Article 10’s governance standards.
  • Cloud Integrations: Kong integrates with AWS Bedrock Guardrails, AI Azure Content Safety, and Google Cloud Model Armor capabilities to provide a defense-in-depth strategy.
Articles 12 & 26

Logging & Traceability (Articles 12 & 26)

The Requirement: Article 12 requires high-risk AI systems to have automatic recording of events (logs) to ensure traceability of the system's functioning. Furthermore, Article 26 (Obligations of Deployers) requires enterprises to monitor these systems and keep logs for at least six months.

The Kong Solution: Fragmented logs are a compliance nightmare. Kong standardizes logging across all your AI traffic.

  • AI Proxy Advanced: Captures comprehensive logs of every prompt, response, latency metric, and model used. This creates the "paper trail" required by auditors to prove conformity.
  • AI Semantic Cache: Beyond performance, caching provides a deterministic record of exactly what inputs produced what outputs, further aiding in traceability.
  • Unified Format: Whether a team is using OpenAI, Anthropic, or a self-hosted Llama 3, Kong logs the interaction in a consistent format, making post-market monitoring (Article 72) feasible.

Articles 9 & 15

Risk Management & Guardrails (Articles 9 & 15)

The Requirement: Article 9 requires a continuous "risk management system" to identify and mitigate risks to health, safety, and fundamental rights. Article 15 demands that systems achieve appropriate levels of accuracy, robustness, and cybersecurity.

The Kong Solution: Kong acts as the enforcement point for your risk management policies.

  • Centralized Guardrails: You can implement policies that block hallucinations, toxic content, or jailbreak attempts at the gateway. If a prompt violates your risk policy, it is rejected by Kong, never reaching the model.
  • LLM-as-a-Judge: You can use a smaller, faster model to "judge" the output of a larger model for compliance and safety before sending it back to the user, automating the risk mitigation loop.
  • Cybersecurity: By centralizing AI access, Kong protects against model denial-of-service (DoS) and credential leakage, directly addressing the cybersecurity mandates of Article 15.
Article 50

Transparency (Article 50)

The Requirement: Article 50 (formerly Article 52 in drafts) enforces transparency obligations. Users must be informed when they are interacting with an AI system (like a chatbot) and deepfakes or synthetic content must be clearly marked.

The Kong Solution: Transparency requires visibility. You cannot disclose what you do not track.

  • Model Independence: Kong abstracts the underlying model. If you need to swap a model because it fails a transparency or compliance check, you can do so at the gateway without changing application code.
  • Header Injection & Decoration: Kong can inject system messages or headers that force models to self-identify or append disclaimers to responses, ensuring that the "I am an AI" disclosure required by Article 50 is consistently applied across all chatbots in your fleet.
Articles 14 & 26

Human Oversight (Articles 14 & 26)

The Requirement: Article 14 requires that AI systems be designed for effective human oversight. Article 26 places the burden on the deployer (the enterprise) to assign human oversight and monitor the system for anomalies.

The Kong Solution: Kong empowers the "humans in the loop" (Platform Engineers and Compliance Officers) with the tools they need to oversee the system.

  • AI RAG Injector: By forcing AI models to use your vetted enterprise data (Retrieval Augmented Generation) rather than their internal training data, you drastically reduce hallucinations and ensure the system remains "under control."
  • AI Prompt Decorator: Enforce "system prompts" that set behavioral boundaries (e.g., "You are a helpful assistant for Acme Corp, do not provide financial advice") globally. This ensures that no individual developer can bypass the oversight instructions defined by your compliance team.
Conclusion

The "No Rewrite" Compliance Strategy

The EU AI Act is not just a checklist; it’s a mandate for governance. Trying to bolt this governance onto every single microservice is a recipe for failure.

Kong AI Gateway offers a cleaner path: governance at the edge. By centralizing your AI traffic, you can solve for data protection, logging, risk, and transparency in one place. You get to be compliant with the EU AI Act, and your developers get to keep coding without rewriting their apps.

AI-powered API security? Yes please!

Learn MoreGet a Demo
Topics
AIAI GatewayGovernance
Share on Social
Jordi Fernandez Moledo
Principal Architect, Kong

Recommended posts

The AI Governance Wake-Up Call

Kong Logo
EnterpriseDecember 12, 2025

Companies are charging headfirst into AI, with research around agentic AI in the enterprise finding as many as 9 out of 10 organizations are actively working to adopt AI agents.  LLMs are being deployed, agentic workflows are getting created left

Taylor Hendricks

Consistently Hallucination-Proof Your LLMs with Automated RAG

Kong Logo
EnterpriseApril 2, 2025

AI is quickly transforming the way businesses operate, turning what was once futuristic into everyday reality. However, we're still in the early innings of AI, and there are still several key limitations with AI that organizations should remain awa

Adam Jiroun

PII Sanitization Needed for LLMs and Agentic AI is Now Easier to Build

Kong Logo
EnterpriseApril 2, 2025

LLMs are powerful, but not inherently privacy-aware LLMs operate as highly capable, non-deterministic pattern matchers. But they come with two significant privacy challenges: They don’t automatically distinguish between sensitive and non-sensitive

Alex Drag

AI Guardrails: Ensure Safe, Responsible, Cost-Effective AI Integration

Kong Logo
EngineeringAugust 25, 2025

Why AI guardrails matter It's natural to consider the necessity of guardrails for your sophisticated AI implementations. The truth is, much like any powerful technology, AI requires a set of protective measures to ensure its reliability and integrit

Jason Matis

The Observability Gap: Why API and AI Monitoring Must Converge Now

Kong Logo
EnterpriseSeptember 25, 2025

The convergence reality Organizations are gradually realizing that API and AI observability aren't two separate problems; they're intertwined and require unified solutions. Without waiting on engineering, it's hard to answer simple questions like "

Alex Drag

Streamline AI Usage with Token Rate-Limiting & Tiered Access in Kong

Kong Logo
EngineeringMay 6, 2025

As organizations continue to adopt AI-driven applications, managing usage and costs becomes more critical. Large language models (LLMs), such as those provided by OpenAI, Google, Anthropic, and Mistral, can incur significant expenses when overused.

Jason Matis

Securing, Observing, and Governing MCP Servers with Kong AI Gateway

Kong Logo
Product ReleasesApril 24, 2025

The explosion of AI-native applications is upon us. With each new week, massive innovations are being made in how AI-centric applications are being built. There are a variety of tools developers need to consider, be it supplying live contextual data

Greg Peranich

Ready to see Kong in action?

Get a personalized walkthrough of Kong's platform tailored to your architecture, use cases, and scale requirements.

Get a Demo
Powering the API world

Increase developer productivity, security, and performance at scale with the unified platform for API management, AI gateways, service mesh, and ingress controller.

Sign up for Kong newsletter

    • Platform
    • Kong Konnect
    • Kong Gateway
    • Kong AI Gateway
    • Kong Insomnia
    • Developer Portal
    • Gateway Manager
    • Cloud Gateway
    • Get a Demo
    • Explore More
    • Open Banking API Solutions
    • API Governance Solutions
    • Istio API Gateway Integration
    • Kubernetes API Management
    • API Gateway: Build vs Buy
    • Kong vs Postman
    • Kong vs MuleSoft
    • Kong vs Apigee
    • Documentation
    • Kong Konnect Docs
    • Kong Gateway Docs
    • Kong Mesh Docs
    • Kong AI Gateway
    • Kong Insomnia Docs
    • Kong Plugin Hub
    • Open Source
    • Kong Gateway
    • Kuma
    • Insomnia
    • Kong Community
    • Company
    • About Kong
    • Customers
    • Careers
    • Press
    • Events
    • Contact
    • Pricing
  • Terms
  • Privacy
  • Trust and Compliance
  • © Kong Inc. 2025