REGISTER NOW FOR THE KONG AGENTIC ERA WORLD TOUR GOVERN A2A TRAFFIC WITH KONG'S NEW AGENT GATEWAY WHY GARTNER’S “CONTEXT MESH” CHANGES EVERYTHING DON’T MISS API + AI SUMMIT 2026 SEPT 30 – OCT 1
  • [Why Kong](/company/why-kong)Why Kong
    • Explore the unified API Platform
        • BUILD APIs
        • [
          Kong Insomnia](/products/kong-insomnia)
          Kong Insomnia
        • [
          API Design](/products/kong-insomnia/api-design)
          API Design
        • [
          API Mocking](/products/kong-insomnia/api-mocking)
          API Mocking
        • [
          API Testing and Debugging](/products/kong-insomnia/api-testing-and-debugging)
          API Testing and Debugging
        • [
          MCP Client](/products/kong-insomnia/mcp-client)
          MCP Client
        • RUN APIs
        • [
          API Gateway](/products/kong-gateway)
          API Gateway
        • [
          Context Mesh](/products/kong-konnect/features/context-mesh)
          Context Mesh
        • [
          AI Gateway](/products/kong-ai-gateway)
          AI Gateway
        • [
          Event Gateway](/products/event-gateway)
          Event Gateway
        • [
          Kubernetes Operator](/products/kong-gateway-operator)
          Kubernetes Operator
        • [
          Service Mesh](/products/kong-mesh)
          Service Mesh
        • [
          Ingress Controller](/products/kong-ingress-controller)
          Ingress Controller
        • [
          Runtime Management](/products/kong-konnect/features/runtime-management)
          Runtime Management
        • DISCOVER APIs
        • [
          Developer Portal](/products/kong-konnect/features/developer-portal)
          Developer Portal
        • [
          Service Catalog](/products/kong-konnect/features/api-service-catalog)
          Service Catalog
        • [
          MCP Registry](/products/mcp-registry)
          MCP Registry
        • GOVERN APIs
        • [
          Metering and Billing](/products/kong-konnect/features/usage-based-metering-and-billing)
          Metering and Billing
        • [
          APIOps and Automation](/products/apiops-automation)
          APIOps and Automation
        • [
          API Observability](/products/kong-konnect/features/api-observability)
          API Observability
        • [Why Kong?](/company/why-kong)Why Kong?
      • CLOUD
      • [Cloud API Gateways](/products/kong-konnect/features/dedicated-cloud-gateways)Cloud API Gateways
      • [Need a self-hosted or hybrid option?](/products/kong-enterprise)Need a self-hosted or hybrid option?
      • COMPARE
      • [Considering AI Gateway alternatives? ](/performance-comparison/ai-gateway-alternatives)Considering AI Gateway alternatives?
      • [Kong vs. Postman](/performance-comparison/kong-vs-postman)Kong vs. Postman
      • [Kong vs. MuleSoft](/performance-comparison/kong-vs-mulesoft)Kong vs. MuleSoft
      • [Kong vs. Apigee](/performance-comparison/kong-vs-apigee)Kong vs. Apigee
      • [Kong vs. IBM](/performance-comparison/ibm-api-connect-vs-kong)Kong vs. IBM
      • GET STARTED
      • [Sign Up for Kong Konnect](/products/kong-konnect/register)Sign Up for Kong Konnect
      • [Documentation](https://developer.konghq.com/)Documentation
      • FOR PLATFORM TEAMS
      • [Developer Platform](/solutions/building-developer-platform)Developer Platform
      • [Kubernetes and Microservices](/solutions/build-on-kubernetes)Kubernetes and Microservices
      • [Observability](/solutions/observability)Observability
      • [Service Mesh Connectivity ](/solutions/service-mesh-connectivity)Service Mesh Connectivity
      • [Kafka Event Streaming](/solutions/kafka-stream-api-management)Kafka Event Streaming
      • FOR EXECUTIVES
      • [AI Connectivity](/ai-connectivity)AI Connectivity
      • [Open Banking](/solutions/open-banking)Open Banking
      • [Legacy Migration](/solutions/legacy-api-management-migration)Legacy Migration
      • [Platform Cost Reduction](/solutions/api-platform-consolidation)Platform Cost Reduction
      • [Kafka Cost Optimization](/solutions/reduce-kafka-cost)Kafka Cost Optimization
      • [API Monetization](/solutions/api-monetization)API Monetization
      • [AI Monetization](/solutions/ai-monetization)AI Monetization
      • [AI FinOps](/solutions/ai-cost-governance-finops)AI FinOps
      • FOR AI TEAMS
      • [Agent Gateway](/agent-gateway)Agent Gateway
      • [AI Governance](/solutions/ai-governance)AI Governance
      • [AI Security](/solutions/ai-security)AI Security
      • [AI Cost Control](/solutions/ai-cost-optimization-management)AI Cost Control
      • [Agentic Infrastructure](/solutions/agentic-ai-workflows)Agentic Infrastructure
      • [MCP Production](/solutions/mcp-production-and-consumption)MCP Production
      • [MCP Traffic Gateway](/solutions/mcp-governance)MCP Traffic Gateway
      • FOR DEVELOPERS
      • [Mobile App API Development](/solutions/mobile-application-api-development)Mobile App API Development
      • [GenAI App Development](/solutions/power-openai-applications)GenAI App Development
      • [API Gateway for Istio](/solutions/istio-gateway)API Gateway for Istio
      • [Decentralized Load Balancing](/solutions/decentralized-load-balancing)Decentralized Load Balancing
      • BY INDUSTRY
      • [Financial Services](/solutions/financial-services-industry)Financial Services
      • [Healthcare](/solutions/healthcare)Healthcare
      • [Higher Education](/solutions/api-platform-for-education-services)Higher Education
      • [Insurance](/solutions/insurance)Insurance
      • [Manufacturing](/solutions/manufacturing)Manufacturing
      • [Retail](/solutions/retail)Retail
      • [Software & Technology](/solutions/software-and-technology)Software & Technology
      • [Transportation](/solutions/transportation-and-logistics)Transportation
      • [See all Solutions](/solutions)See all Solutions
  • [Pricing](/pricing)Pricing
      • DOCUMENTATION
      • [Kong Konnect](https://developer.konghq.com/konnect/)Kong Konnect
      • [Kong Gateway](https://developer.konghq.com/gateway/)Kong Gateway
      • [Kong Mesh](https://developer.konghq.com/mesh/)Kong Mesh
      • [Kong AI Gateway](https://developer.konghq.com/ai-gateway/)Kong AI Gateway
      • [Kong Event Gateway](https://developer.konghq.com/event-gateway/)Kong Event Gateway
      • [Kong Insomnia](https://developer.konghq.com/insomnia/)Kong Insomnia
      • [Plugin Hub](https://developer.konghq.com/plugins/)Plugin Hub
      • EXPLORE
      • [Blog](/blog)Blog
      • [Learning Center](/blog/learning-center)Learning Center
      • [eBooks](/resources/e-book)eBooks
      • [Reports](/resources/reports)Reports
      • [Demos](/resources/demos)Demos
      • [Customer Stories](/customer-stories)Customer Stories
      • [Videos](/resources/videos)Videos
      • EVENTS
      • [API + AI Summit](/events/conferences/api-ai-summit)API + AI Summit
      • [Agentic Era World Tour](/agentic-era-world-tour)Agentic Era World Tour
      • [Webinars](/events/webinars)Webinars
      • [User Calls](/events/user-calls)User Calls
      • [Workshops](/events/workshops)Workshops
      • [Meetups](/events/meetups)Meetups
      • [See All Events](/events)See All Events
      • FOR DEVELOPERS
      • [Get Started](https://developer.konghq.com/)Get Started
      • [Community](/community)Community
      • [Certification](/academy/certification)Certification
      • [Training](https://education.konghq.com)Training
      • COMPANY
      • [About Us](/company/about-us)About Us
      • [We're Hiring!](/company/careers)We're Hiring!
      • [Press Room](/company/press-room)Press Room
      • [Contact Us](/company/contact-us)Contact Us
      • [Kong Partner Program](/partners)Kong Partner Program
      • [Enterprise Support Portal](https://support.konghq.com/s/)Enterprise Support Portal
      • [Documentation](https://developer.konghq.com/?_gl=1*tphanb*_gcl_au*MTcxNTQ5NjQ0MC4xNzY5Nzg4MDY0LjIwMTI3NzEwOTEuMTc3MzMxODI2MS4xNzczMzE4MjYw*_ga*NDIwMDU4MTU3LjE3Njk3ODgwNjQ.*_ga_4JK9146J1H*czE3NzQwMjg1MjkkbzE4OSRnMCR0MTc3NDAyODUyOSRqNjAkbDAkaDA)Documentation
  • [](/search)
  • [Login](https://cloud.konghq.com/login)Login
  • [Book Demo](/contact-sales)Book Demo
  • [Get Started](/products/kong-konnect/register)Get Started
[Blog](/blog)Blog
  • [AI Gateway](/blog/tag/ai-gateway)AI Gateway
  • [AI Security](/blog/tag/ai-security)AI Security
  • [AIOps](/blog/tag/aiops)AIOps
  • [API Security](/blog/tag/api-security)API Security
  • [API Gateway](/blog/tag/api-gateway)API Gateway
|
    • [API Management](/blog/tag/api-management)API Management
    • [API Development](/blog/tag/api-development)API Development
    • [API Design](/blog/tag/api-design)API Design
    • [Automation](/blog/tag/automation)Automation
    • [Service Mesh](/blog/tag/service-mesh)Service Mesh
    • [Insomnia](/blog/tag/insomnia)Insomnia
    • [Event Gateway](/blog/tag/event-gateway)Event Gateway
    • [View All Blogs](/blog/page/1)View All Blogs
We're Entering the Age of AI Connectivity [Read more](/blog/news/the-age-of-ai-connectivity)Read moreProducts & Agents:
    • [Kong AI Gateway](/products/kong-ai-gateway)Kong AI Gateway
    • [Kong API Gateway](/products/kong-gateway)Kong API Gateway
    • [Kong Event Gateway](/products/event-gateway)Kong Event Gateway
    • [Kong Metering & Billing](/products/usage-based-metering-and-billing)Kong Metering & Billing
    • [Kong Insomnia](/products/kong-insomnia)Kong Insomnia
    • [Kong Konnect](/products/kong-konnect)Kong Konnect
  • [Documentation](https://developer.konghq.com)Documentation
  • [Book Demo](/contact-sales)Book Demo
  1. Home
  2. Blog
  3. Enterprise
  4. Kong AI Gateway and the EU AI Act: Compliance Without the Rewrites
[Enterprise](/blog/enterprise)Enterprise
November 26, 2025
4 min read

# Kong AI Gateway and the EU AI Act: Compliance Without the Rewrites

Jordi Fernandez Moledo
Principal Architect, Kong

The EU AI Act is here, and for many enterprises, it represents a massive coordination challenge. As the world’s first comprehensive AI law, it mandates strict governance on transparency, risk management, and data quality.

For platform engineers and architects, the immediate question is operational: **How do we comply with these new regulations without forcing every developer to rewrite their applications?**

If you leave compliance to individual application teams, you risk [fragmentation](https://konghq.com/blog/enterprise/hidden-ai-connectivity-tax)fragmentation — different logging standards, inconsistent guardrails, and "shadow AI" usage that exposes the organization to fines. The answer lies in centralization. By positioning **Kong AI Gateway** as your AI control plane, you can enforce the EU AI Act’s requirements globally, acting as a "trust layer" that governs all AI traffic regardless of the underlying model or application.

Here's how Kong helps you map directly to the key articles of the EU AI Act.

_Article 10_

## Data Governance & PII Protection (Article 10)

**The Requirement**: Article 10 of the EU AI Act mandates strict data governance for high-risk AI systems. This includes error detection, bias monitoring, and arguably most critically for enterprise use — ensuring that sensitive personal data (PII) is not improperly processed or leaked into public models.

**The Kong Solution**: Instead of asking developers to manually sanitize inputs in every Python script or Java app, you can enforce data governance at the gateway level before the request ever leaves your perimeter.

  • - [**AI PII Sanitizer**](https://developer.konghq.com/plugins/ai-sanitizer/)**AI PII Sanitizer**: Automatically detects and redacts entities like names, SSNs, and emails from prompts before they reach the LLM.
  • - [**Prompt Guard**](https://developer.konghq.com/plugins/ai-prompt-guard/)**Prompt Guard**** and **[**Response Guard**](https://developer.konghq.com/plugins/ai-semantic-response-guard/)**Response Guard**: Enforce a hard boundary on what data enters and exits your organization, preventing "data leakage" that could violate Article 10’s governance standards.
  • - **Cloud Integrations**: Kong integrates with [AWS Bedrock Guardrails](https://developer.konghq.com/plugins/ai-aws-guardrails/)AWS Bedrock Guardrails, [AI Azure Content Safety](https://developer.konghq.com/plugins/ai-azure-content-safety/)AI Azure Content Safety, and [Google Cloud Model Armor](https://developer.konghq.com/plugins/ai-gcp-model-armor/)Google Cloud Model Armor capabilities to provide a defense-in-depth strategy.
_Articles 12 & 26_

## Logging & Traceability (Articles 12 & 26)

**The Requirement**: Article 12 requires high-risk AI systems to have automatic recording of events (logs) to ensure traceability of the system's functioning. Furthermore, Article 26 (Obligations of Deployers) requires enterprises to monitor these systems and keep logs for at least six months.

**The Kong Solution**: Fragmented logs are a compliance nightmare. Kong standardizes logging across all your AI traffic.

  • - [**AI Proxy Advanced**](https://developer.konghq.com/plugins/ai-proxy-advanced/)**AI Proxy Advanced**: Captures comprehensive logs of every prompt, response, latency metric, and model used. This creates the "paper trail" required by auditors to prove conformity.
  • - [**AI Semantic Cache**](https://developer.konghq.com/plugins/ai-semantic-cache/)**AI Semantic Cache**: Beyond performance, caching provides a deterministic record of exactly what inputs produced what outputs, further aiding in traceability.
  • - **Unified Format**: Whether a team is using OpenAI, Anthropic, or a self-hosted Llama 3, Kong logs the interaction in a consistent format, making post-market monitoring (Article 72) feasible.

_Articles 9 & 15_

## Risk Management & Guardrails (Articles 9 & 15)

**The Requirement**: Article 9 requires a continuous "risk management system" to identify and mitigate risks to health, safety, and fundamental rights. Article 15 demands that systems achieve appropriate levels of accuracy, robustness, and cybersecurity.

**The Kong Solution**: Kong acts as the enforcement point for your risk management policies.

  • - **Centralized Guardrails**: You can implement policies that block hallucinations, toxic content, or jailbreak attempts at the gateway. If a prompt violates your risk policy, it is rejected by Kong, never reaching the model.
  • - [**LLM-as-a-Judge**](https://developer.konghq.com/plugins/ai-llm-as-judge/)**LLM-as-a-Judge**: You can use a smaller, faster model to "judge" the output of a larger model for compliance and safety before sending it back to the user, automating the risk mitigation loop.
  • - **Cybersecurity**: By centralizing AI access, Kong protects against model denial-of-service (DoS) and credential leakage, directly addressing the cybersecurity mandates of Article 15.
_Article 50_

## Transparency (Article 50)

**The Requirement**: Article 50 (formerly Article 52 in drafts) enforces transparency obligations. Users must be informed when they are interacting with an AI system (like a chatbot) and deepfakes or synthetic content must be clearly marked.

**The Kong Solution**: Transparency requires visibility. You cannot disclose what you do not track.

  • - **Model Independence**: Kong abstracts the underlying model. If you need to swap a model because it fails a transparency or compliance check, you can do so at the gateway without changing application code.
  • - **Header Injection & Decoration**: Kong can inject system messages or headers that force models to self-identify or append disclaimers to responses, ensuring that the "I am an AI" disclosure required by Article 50 is consistently applied across all chatbots in your fleet.
_Articles 14 & 26_

## Human Oversight (Articles 14 & 26)

**The Requirement**: Article 14 requires that AI systems be designed for effective human oversight. Article 26 places the burden on the deployer (the enterprise) to assign human oversight and monitor the system for anomalies.

**The Kong Solution**: Kong empowers the "humans in the loop" (Platform Engineers and Compliance Officers) with the tools they need to oversee the system.

  • - [**AI RAG Injector**](https://developer.konghq.com/plugins/ai-rag-injector/)**AI RAG Injector**: By forcing AI models to use your vetted enterprise data (Retrieval Augmented Generation) rather than their internal training data, you drastically reduce hallucinations and ensure the system remains "under control."
  • - [**AI Prompt Decorator**](https://developer.konghq.com/plugins/ai-prompt-decorator/)**AI Prompt Decorator**: Enforce "system prompts" that set behavioral boundaries (e.g., "You are a helpful assistant for Acme Corp, do not provide financial advice") globally. This ensures that no individual developer can bypass the oversight instructions defined by your compliance team.
_Conclusion_

## The "No Rewrite" Compliance Strategy

The EU AI Act is not just a checklist; it’s a mandate for governance. Trying to bolt this governance onto every single microservice is a recipe for failure.

Kong AI Gateway offers a cleaner path:** governance at the edge**. By centralizing your AI traffic, you can solve for data protection, logging, risk, and transparency in one place. You get to be compliant with the EU AI Act, and your developers get to keep coding without rewriting their apps.

## AI-powered API security? Yes please!

[Learn More](/products/kong-ai-gateway/)Learn More[Get a Demo](/contact-sales)Get a Demo
- [AI](/blog/tag/ai)AI- [AI Gateway](/blog/tag/ai-gateway)AI Gateway- [Governance](/blog/tag/governance)Governance

Table of Contents

  • Data Governance & PII Protection (Article 10)
  • Logging & Traceability (Articles 12 & 26)
  • Risk Management & Guardrails (Articles 9 & 15)
  • Transparency (Article 50)
  • Human Oversight (Articles 14 & 26)
  • The "No Rewrite" Compliance Strategy

## More on this topic

_Webinars_

## Building The API Platform For Platform Builders: Where Kong Goes Next

_Webinars_

## Drive real AI value with state of the art AI infrastructure

## See Kong in action

Accelerate deployments, reduce vulnerabilities, and gain real-time visibility. 

[Get a Demo](/contact-sales)Get a Demo
**Topics**
- [AI](/blog/tag/ai)AI- [AI Gateway](/blog/tag/ai-gateway)AI Gateway- [Governance](/blog/tag/governance)Governance
Jordi Fernandez Moledo
Principal Architect, Kong

Recommended posts

# LLM Cost Management: How to Implement AI Showback and Chargeback

[Enterprise](/blog)EnterpriseApril 6, 2026

Bring Financial Accountability to Enterprise LLM Usage with Konnect Metering and Billing Showback and chargeback are not the same thing. Most organizations conflate these two concepts, and that conflation delays action. Understanding the LLM showb

Alex Drag
[](https://konghq.com/blog/enterprise/llm-cost-management-ai-showback-and-chargeback)

# The AI Governance Wake-Up Call

[Enterprise](/blog)EnterpriseDecember 12, 2025

Companies are charging headfirst into AI, with research around agentic AI in the enterprise finding as many as 9 out of 10 organizations are actively working to adopt AI agents.  LLMs are being deployed, agentic workflows are getting created left

Taylor Hendricks
[](https://konghq.com/blog/enterprise/ai-governance-wake-up-call)

# Consistently Hallucination-Proof Your LLMs with Automated RAG

[Enterprise](/blog)EnterpriseApril 2, 2025

AI is quickly transforming the way businesses operate, turning what was once futuristic into everyday reality. However, we're still in the early innings of AI, and there are still several key limitations with AI that organizations should remain awa

Adam Jiroun
[](https://konghq.com/blog/enterprise/automated-rag-hallucination-proof-llms)

# PII Sanitization Needed for LLMs and Agentic AI is Now Easier to Build

[Enterprise](/blog)EnterpriseApril 2, 2025

LLMs are powerful, but not inherently privacy-aware LLMs operate as highly capable, non-deterministic pattern matchers. But they come with two significant privacy challenges: They don’t automatically distinguish between sensitive and non-sensitive

Alex Drag
[](https://konghq.com/blog/enterprise/building-pii-sanitization-for-llms-and-agentic-ai)

# The Incessant AI Death Knell

[Enterprise](/blog)EnterpriseApril 8, 2026

CLIs, MCP, and the Real Governance Tradeoffs Shaping Enterprise AI Agents The CLI case is real Let's start with the strongest version of the CLI argument. For well-known tools baked into model training data (e.g., git, grep, curl, jq, docker, kub

Michael Field
[](https://konghq.com/blog/enterprise/cli-vs-mcp-enterprise-ai-governance)

# AI Input vs. Output: Why Token Direction Matters for AI Cost Management

[Enterprise](/blog)EnterpriseMarch 10, 2026

The Shifting Economic Landscape: The AI token economy in 2026 is evolving, and enterprise leaders must distinguish between low-cost input tokens and high-premium output tokens to maintain profitability. Agentic AI Financial Risks: The transition t

Dan Temkin
[](https://konghq.com/blog/enterprise/ai-input-vs-output-cost-management)

# What is AI Governance? 2026 Framework Guide

[Learning Center](/blog)Learning CenterJanuary 2, 2026

AI governance establishes the principles, roles, processes, and controls for responsible AI deployment. It transforms abstract ethics into concrete practices. Think of ​​AI governance as a rulebook for how to use AI in a secure, ethical, observable,

Kong
[](https://konghq.com/blog/learning-center/what-is-ai-governance)

## Ready to see Kong in action?

Get a personalized walkthrough of Kong's platform tailored to your architecture, use cases, and scale requirements.

[Get a Demo](/contact-sales)Get a Demo

## step-0

  • ## Company

    • [About Kong](/company/about-us)About Kong
    • [Customers](/customer-stories)Customers
    • [Careers](/company/careers)Careers
    • [Press](/company/press-room)Press
    • [Events](/events)Events
    • [Contact](/company/contact-us)Contact
    • [Pricing](/pricing)Pricing
      • Terms
      • Privacy
      • Trust and Compliance
  • ## Platform

    • [Kong AI Gateway](/products/kong-ai-gateway)Kong AI Gateway
    • [Kong Konnect](/products/kong-konnect)Kong Konnect
    • [Kong Gateway](/products/kong-gateway)Kong Gateway
    • [Kong Event Gateway](/products/event-gateway)Kong Event Gateway
    • [Kong Insomnia](/products/kong-insomnia)Kong Insomnia
    • [Documentation](https://developer.konghq.com)Documentation
    • [Book Demo](/contact-sales)Book Demo
  • ## Compare

    • [AI Gateway Alternatives](/performance-comparison/ai-gateway-alternatives)AI Gateway Alternatives
    • [Kong vs Apigee](/performance-comparison/kong-vs-apigee)Kong vs Apigee
    • [Kong vs IBM](/performance-comparison/ibm-api-connect-vs-kong)Kong vs IBM
    • [Kong vs Postman](/performance-comparison/kong-vs-postman)Kong vs Postman
    • [Kong vs Mulesoft](/performance-comparison/kong-vs-mulesoft)Kong vs Mulesoft
  • ## Explore More

    • [Open Banking API Solutions](/solutions/open-banking)Open Banking API Solutions
    • [API Governance Solutions](/solutions/api-governance)API Governance Solutions
    • [Istio API Gateway Integration](/solutions/istio-gateway)Istio API Gateway Integration
    • [Kubernetes API Management](/solutions/build-on-kubernetes)Kubernetes API Management
    • [API Gateway: Build vs Buy](/campaign/secure-api-scalability)API Gateway: Build vs Buy
    • [Kong vs Apigee](/performance-comparison/kong-vs-apigee)Kong vs Apigee
  • ## Open Source

    • [Kong Gateway](https://developer.konghq.com/gateway/install/)Kong Gateway
    • [Kuma](https://kuma.io/)Kuma
    • [Insomnia](https://insomnia.rest/)Insomnia
    • [Kong Community](/community)Kong Community

Kong enables the connectivity layer for the agentic era – securely connecting, governing, and monetizing APIs and AI tokens across any model or cloud.

  • English
  • Japanese
  • Frenchcoming soon
  • Spanishcoming soon
  • Germancoming soon
© Kong Inc. 2026
Interaction mode