WHY GARTNER’S “CONTEXT MESH” CHANGES EVERYTHING AI CONNECTIVITY: THE ROAD AHEAD DON’T MISS API + AI SUMMIT 2026 SEPT 30 – OCT 1
  • Why Kong
    • Explore the unified API Platform
        • BUILD APIs
        • Kong Insomnia
        • API Design
        • API Mocking
        • API Testing and Debugging
        • MCP Client
        • RUN APIs
        • API Gateway
        • Context Mesh
        • AI Gateway
        • Event Gateway
        • Kubernetes Operator
        • Service Mesh
        • Ingress Controller
        • Runtime Management
        • DISCOVER APIs
        • Developer Portal
        • Service Catalog
        • MCP Registry
        • GOVERN APIs
        • Metering and Billing
        • APIOps and Automation
        • API Observability
        • Why Kong?
      • CLOUD
      • Cloud API Gateways
      • Need a self-hosted or hybrid option?
      • COMPARE
      • Considering AI Gateway alternatives?
      • Kong vs. Postman
      • Kong vs. MuleSoft
      • Kong vs. Apigee
      • Kong vs. IBM
      • GET STARTED
      • Sign Up for Kong Konnect
      • Documentation
      • FOR PLATFORM TEAMS
      • Developer Platform
      • Kubernetes and Microservices
      • Observability
      • Service Mesh Connectivity
      • Kafka Event Streaming
      • FOR EXECUTIVES
      • AI Connectivity
      • Open Banking
      • Legacy Migration
      • Platform Cost Reduction
      • Kafka Cost Optimization
      • API Monetization
      • AI Monetization
      • AI FinOps
      • FOR AI TEAMS
      • AI Governance
      • AI Security
      • AI Cost Control
      • Agentic Infrastructure
      • MCP Production
      • MCP Traffic Gateway
      • FOR DEVELOPERS
      • Mobile App API Development
      • GenAI App Development
      • API Gateway for Istio
      • Decentralized Load Balancing
      • BY INDUSTRY
      • Financial Services
      • Healthcare
      • Higher Education
      • Insurance
      • Manufacturing
      • Retail
      • Software & Technology
      • Transportation
      • See all Solutions
  • Pricing
      • DOCUMENTATION
      • Kong Konnect
      • Kong Gateway
      • Kong Mesh
      • Kong AI Gateway
      • Kong Event Gateway
      • Kong Insomnia
      • Plugin Hub
      • EXPLORE
      • Blog
      • Learning Center
      • eBooks
      • Reports
      • Demos
      • Customer Stories
      • Videos
      • EVENTS
      • API + AI Summit
      • Agentic Era World Tour
      • Webinars
      • User Calls
      • Workshops
      • Meetups
      • See All Events
      • FOR DEVELOPERS
      • Get Started
      • Community
      • Certification
      • Training
      • COMPANY
      • About Us
      • We're Hiring!
      • Press Room
      • Contact Us
      • Kong Partner Program
      • Enterprise Support Portal
      • Documentation
  • Login
  • Book Demo
  • Get Started
Blog
  • AI Gateway
  • AI Security
  • AIOps
  • API Security
  • API Gateway
|
    • API Management
    • API Development
    • API Design
    • Automation
    • Service Mesh
    • Insomnia
    • View All Blogs
  1. Home
  2. Blog
  3. Product Releases
  4. Kong Gateway 3.9: Extended AI Support and Enhanced Security
Product Releases
December 20, 2024
3 min read

Kong Gateway 3.9: Extended AI Support and Enhanced Security

Alex Drag
Head of Product Marketing

Today we're excited to announce Kong Gateway 3.9! 

Since unveiling Kong Gateway 3.8 at API Summit 2024 just a few months ago, we’ve been busy making important updates and improvements to Kong Gateway. This release introduces new functionality around LLM support for AI governance and security and threat protection. Keep reading to learn more!

Make your organization even more AI-ready: Added support for 1M+ new AI models and agentic workflows

With the Kong Gateway 3.9 release, we also shipped new improvements to our AI Gateway. This new release ships with support for a new GenAI provider, Hugging Face, providing users with access to more than 1.1 million new AI models. You'll be able to easily secure, observe, and govern the Hugging Face models via the Kong AI Gateway in the same way you are currently able to do so for GCP Vertex, AWS BedRock, Azure AI, OpenAI, Mistral, Antrophic, Cohere, and more.

Support for AI agentic workflows has also been significantly improved by enhancing AI Gateway’s function-calling capabilities across every GenAI provider. Building chatbots, AI agents, and "copilot" capabilities has never been easier while ensuring governance, security, speed, and observability via the AI capabilities available through Kong's AI Gateway.

Enhanced security and threat protection: Injection protection and more advanced rate limiting

Given how mission-critical API security is from a tech and financial perspective, we decided to further our API security offering with new API security functionality: injection protection and service-level rate limiting. 

Injection protection (Enterprise only)

An injection attack is a type of security vulnerability where an attacker exploits flaws in a system to inject malicious data or code into a program, query, or request. The goal is to manipulate the system's behavior, often to gain unauthorized access, retrieve sensitive information, or execute malicious actions. 

There are several different kinds of injection attacks (SQL, XSS, etc.), and now you can use Kong to protect your organization from these malicious threat vectors.

Kong Gateway can now enforce injection protection policies, all powered by the new Injection Protection plugin. This new enterprise plugin is designed to cover a wide range of common injection patterns, such as SQL, XSS, Server-side include, XPath Syntax, and Java Exception — all out of the box. The plugin will extract information from request headers, path, query, or body payload parameters and evaluate that content against pre-defined regular expressions. If the content matches any of the patterns, the request is flagged as malicious and blocked.

If our default patterns don't meet your needs, you can define custom patterns and have the gateway validate requests against those as well. This gives you the power to customize the injection protection plugin to fit the unique API security needs of your organization.

Learn more about getting started with the Injection Protection plugin on the Kong blog, or head over to the plugin documentation.

Advanced rate limiting and service protection

Rate limiting is "bread-and-butter" API gateway functionality and is key in making sure that API traffic is secure, reliable, and performant.

Gateway 3.9 expands the scope of Kong rate limiting, allowing you to enforce fine-grained rate limits and access controls at the service level. While service-level rate limiting was already possible by combining the existing rate-limiting plugin with the advanced rate-limiting plugin, you can now do it with a single plugin dedicated to service-level protection. This enables you to enforce multiple rate limits for a single API at both the service and route or consumer levels when used in conjunction with other rate-limiting plugins.

The new Service protection plugin enables this. To learn more and get started, check out the plugin documentation.

Getting started with Kong Gateway 3.9 

Start with Kong Gateway 3.9 by signing up for Kong Konnect for free. Or, if you want to try Kong Gateway Enterprise 3.9, you can explore the options for getting started here. 

To explore the comprehensive list of features, fixes, and updates, please see the available CHANGELOG for Kong Gateway Enterprise here.

Power your APIs with Kong Gateway

Learn MoreGet a Demo
API SecurityAPI GatewayKong GatewayKong Gateway EnterpriseAI Gateway

More on this topic

Webinars

Quarterly Platform Updates & Roadmap Webinar

Webinars

Kong Enterprise Office Hours: Gateway 3.3 Demo and Q&A

See Kong in action

Accelerate deployments, reduce vulnerabilities, and gain real-time visibility. 

Get a Demo
Topics
API SecurityAPI GatewayKong GatewayKong Gateway EnterpriseAI Gateway
Alex Drag
Head of Product Marketing

Recommended posts

Practical Strategies to Monetize AI APIs in Production

EngineeringMarch 27, 2026

Traditional APIs are, in a word, predictable. You know what you're getting: Compute costs that don't surprise you Traffic patterns that behave themselves Clean, well-defined request and response cycles AI APIs, especially anything that runs on LLMs

Deepanshu Pandey

What's New in Kong Gateway 3.7?

Product ReleasesMay 29, 2024

We're thrilled to announce the general availability of Kong Gateway 3.7 and Kong Gateway Enterprise 3.7. Along with enhancements and new features for both OSS and enterprise users, this version comes with the general availability of our edge AI Gate

Veena Rajarathna

Your Secrets and Tokens are Secure with Kong Gateway Enterprise 3.5

Product ReleasesNovember 13, 2023

Kong Gateway Enterprise 3.5 is packed with security features to support the use cases demanded by our enterprise customers through major improvements in  Secrets Management  integrations and our  Open-ID Connect (OIDC)  plugin. Additionally, we’ve a

Tom Brightbill

Kong Simplifies Multicloud Cloud Gateways with Managed Redis Cache

Product ReleasesMarch 12, 2026

Managed Redis cache is a turnkey "Shared State" add-on for Kong Dedicated Cloud Gateways. It is designed to combine the performance of an in-memory data store with the simplicity of a SaaS product. When you spin up a Dedicated Cloud Gateway in Kong

Amit Shah

Expanded Observability, Orchestration, and Security with Kong Gateway 3.13

Product ReleasesDecember 18, 2025

As API ecosystems grow more complex, maintaining visibility and security shouldn't be a hurdle. Kong Gateway 3.13 simplifies these challenges with expanded OpenTelemetry support and more flexible orchestration. These new capabilities not only make y

Amit Shah

How to Dynamically Route Requests With Kong Enterprise

EngineeringJuly 31, 2020

Having worked with many customers and prospects at Kong, one of the main requirements we often hear is how to handle dynamic routing based on the URL and headers. In this blog post, I will cover different use cases we come across for dynamic routing

Mos Amokhtari

Connecting Kong and Solace: Building Smarter Event-Driven APIs

EngineeringMarch 20, 2026

Running Kong in front of your Solace Broker adds real benefits: Authentication & Access Control – protect your broker from unauthorized publishers. Validation & Transformation – enforce schemas, sanitize data, and map REST calls into event topics.

Hugo Guerrero

Ready to see Kong in action?

Get a personalized walkthrough of Kong's platform tailored to your architecture, use cases, and scale requirements.

Get a Demo
Ask AI for a summary of Kong
Stay connected
    • Company
    • About Kong
    • Customers
    • Careers
    • Press
    • Events
    • Contact
    • Pricing
    • Legal
    • Terms
    • Privacy
    • Trust and Compliance
    • Platform
    • Kong AI Gateway
    • Kong Konnect
    • Kong Gateway
    • Kong Event Gateway
    • Kong Insomnia
    • Documentation
    • Book Demo
    • Compare
    • AI Gateway Alternatives
    • Kong vs Apigee
    • Kong vs IBM
    • Kong vs Postman
    • Kong vs Mulesoft
    • Explore More
    • Open Banking API Solutions
    • API Governance Solutions
    • Istio API Gateway Integration
    • Kubernetes API Management
    • API Gateway: Build vs Buy
    • Kong vs Apigee
    • Open Source
    • Kong Gateway
    • Kuma
    • Insomnia
    • Kong Community

Kong enables the connectivity layer for the agentic era – securely connecting, governing, and monetizing APIs and AI tokens across any model or cloud.

  • Japanese
  • Frenchcoming soon
  • Spanishcoming soon
  • Germancoming soon
© Kong Inc. 2026