apinizer.← AI Gateway Series
AI Gateway1 / 5

AI agents on
both sides.
Who governs the
result?

The talk starts with “how do we give agents tools”.
The real question is in what comes back.
apinizerapinizer.What the agent reads is governed too
AI Gateway2 / 5

Where we
put it.

01
Inbound
REST/SOAP/AI proxies as MCP tools — fail-closed allowlist
02
A2A
AgentCard discovery · JSON-RPC 2.0 · task store · relay
03
Outbound
tool_use → bounded loop, max 5 turns
apinizerapinizer.What the agent reads is governed too
AI Gateway3 / 5

The key point:
when the tool result returns.

It re-enters the full policy chain
PII mask · DLP · prompt guard apply
Not just what the agent sends — what it reads
apinizerapinizer.What the agent reads is governed too
AI Gateway4 / 5

On top:
egress protection.

SSRF guard on every egress path
Private IPs and metadata endpoints blocked
Per-tool RBAC · full audit trail
apinizerapinizer.What the agent reads is governed too
AI Gateway5 / 5

Agent security limited to
“what it sends” is a half model.

The real risk is in what the agent brings back — to the model and the user.
Do you also govern what your
agent brings back?
apinizerapinizer.What the agent reads is governed too
← → to navigate