TL;DR: AI gateways now route enterprise model access, but they do not inspect prompt content, response content, or tool calls, leaving organisations blind to prompt injection, jailbreaks, and sensitive data leakage, according to Lasso Security. The practical shift is that AI traffic inspection is becoming an identity and policy control, not just an observability add-on.
Editorial analysis by NHI Mgmt Group, based on content published by Lasso Security: “How Lasso Secures AI Gateway Traffic Across Kong, Portkey, LiteLLM, Envoy, and More”.
Key questions
Q: How should teams govern AI gateways that route model and tool traffic?
A: Teams should treat the gateway as the control boundary for identity, spend, logging, and policy enforcement.
Q: Why are AI gateways not enough to stop prompt injection and data leakage?
A: AI gateways control where traffic goes, but they do not understand what the traffic means.
Q: What are the signs that AI traffic inspection is not working?
A: The clearest warning signs are traffic logs that show routing but not content, policies that cannot explain why a prompt was blocked or allowed, and audit trails that miss the returned output or any downstream tool action.
Practitioner guidance
- Define the AI gateway as a policy enforcement boundary Map gateway routes, model endpoints, and tool-call paths into your access governance model so the control owner is explicit.
- Inspect prompts, responses, and tool calls inline Apply different policy checks to inbound prompts, model outputs, and any tool invocation so violations are caught at the point of execution.
- Preserve interaction-level audit records Log the sent content, returned content, applied policy, and enforcement action so incident review and governance review use the same evidence.
Bottom line: AI gateway routing solves model access coordination, but it does not by itself govern the content or effects of AI interactions.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
AI gateway traffic inspection is becoming an identity control, not a monitoring feature. The gateway already represents an access chokepoint for models, but the real risk sits inside the interaction where prompts, responses, and tool calls can move sensitive material or adversarial instructions. That makes content-level enforcement part of the identity plane rather than a separate detection concern. Practitioners should treat AI gateway inspection as policy enforcement at runtime, not as a passive analytics layer.
A few things that frame the scale:
- 24,008 unique secrets were exposed in MCP configuration files in 2025 alone, the protocol's first year of widespread adoption, according to The State of Secrets Sprawl 2026.
- AI-related credential leaks surged 81.5% year-over-year in 2025, with the surrounding AI infrastructure leaking 5x faster than core LLM providers.
A question worth separating out:
Q: What is the difference between gateway routing and AI traffic inspection?
A: Gateway routing moves requests between services and models. AI traffic inspection evaluates the content of those requests and responses for policy violations, sensitive data, and adversarial manipulation. The first is an access-path function. The second is a security enforcement function.
👉 Read our full editorial: AI gateway traffic inspection is becoming an identity control
AI gateway traffic inspection is becoming an identity control, not a monitoring feature. The gateway already represents an access chokepoint for models, but the real risk sits inside the interaction where prompts, responses, and tool calls can move sensitive material or adversarial instructions. That makes content-level enforcement part of the identity plane rather than a separate detection concern. Practitioners should treat AI gateway inspection as policy enforcement at runtime, not as a passive analytics layer.
A few things that frame the scale:
- 24,008 unique secrets were exposed in MCP configuration files in 2025 alone, the protocol's first year of widespread adoption, according to The State of Secrets Sprawl 2026.
- AI-related credential leaks surged 81.5% year-over-year in 2025, with the surrounding AI infrastructure leaking 5x faster than core LLM providers.
A question worth separating out:
Q: What is the difference between gateway routing and AI traffic inspection?
A: Gateway routing moves requests between services and models. AI traffic inspection evaluates the content of those requests and responses for policy violations, sensitive data, and adversarial manipulation. The first is an access-path function. The second is a security enforcement function.
👉 Read our full editorial: AI gateway traffic inspection is becoming an identity control
AI gateway traffic is becoming an identity control layer, not a network convenience. Once enterprises centralise model access through Kong, Portkey, LiteLLM, Envoy, and similar gateways, the control question shifts from routing to governance. The gateway now decides which identities reach which models, under what policy, and with what logging. That makes it part of identity security architecture, not a separate observability stack. Practitioners should align gateway policy with access governance rather than treating it as an AI operations add-on.
A few things that frame the scale:
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: What happens when AI gateway controls are limited to rate limits and API keys?
A: The gateway still manages access, but the organisation remains blind to what the model receives and returns. That leaves prompt injection, jailbreak attempts, sensitive-data leakage, and unsafe tool actions outside the control boundary. The result is a visible network flow with an invisible security decision.
👉 Read our full editorial: AI gateway traffic inspection is becoming an identity control