Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

Gemini Enterprise Agent Platform vs Kong AI Gateway

Gemini Enterprise Agent Platform

Google Cloud platform to build, deploy, govern, and optimize AI agents

Kong AI Gateway

Gateway that governs LLM, MCP, and agent-to-agent traffic

Short answer

Gemini Enterprise Agent Platform is Google Cloud’s platform to build, deploy, and govern agents; Kong AI Gateway is a gateway for LLM, MCP, and A2A traffic.⁠Source 1, Source 2, Source 3, Source 4 Agent Platform runs agents on Agent Runtime, where Agent Gateway can govern their traffic; Kong AI Gateway proxies to agents registered as upstream URLs.⁠Source 5, Source 6

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both put a gateway in front of agent traffic, including MCP and A2A, that can check access before a call goes through and log requests.⁠Source 3, Source 5, Source 6, Source 7, Source 8
Where they differ
Agent Platform also offers Agent Studio and the Agent Development Kit for building agents, and Agent Runtime to run them.⁠Source 1, Source 5 Building agents in Kong AI Gateway is not publicly documented.
Running both
Kong’s docs say Kong AI Gateway can proxy Gemini models, including through Google Cloud’s aiplatform.googleapis.com endpoint.⁠Source 9
Public sources · checked 2 October 2026
  • Offered
  • Preview
  • Not publicly documented

Gemini Enterprise Agent Platform

  • Build agents: OfferedAgent Studio low-code canvas⁠Source 1
  • Host and run agents: OfferedAgent Runtime⁠Source 5
  • Identity and access: OfferedSPIFFE-based Agent Identity⁠Source 10
  • Registry and governance: OfferedAgent Registry⁠Source 11
  • Traffic between agents, tools, and models: OfferedAgent Gateway⁠Source 5
  • Agents across organizations: OfferedGateway calls to outside agents⁠Source 5

Kong AI Gateway

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedPer-agent allow or deny lists⁠Source 6
  • Registry and governance: PreviewKonnect Catalog agents⁠Source 12
  • Traffic between agents, tools, and models: OfferedGateway for LLM, MCP, A2A⁠Source 3
  • Agents across organizations: Not publicly documented

At a glance

TopicGemini Enterprise Agent PlatformKong AI Gateway
What it isGoogle Cloud’s platform to build, deploy, govern, and optimize AI agents, described as an evolution of Vertex AI.⁠Source 1A gateway that governs LLM, MCP, and A2A traffic, with shared authentication, observability, and policy features.⁠Source 3, Source 4
Where governed agents runAgent Gateway can govern traffic into and out of Agent Runtime agents, and out of the Gemini Enterprise app.⁠Source 5 Agents hosted outside Google Cloud can be added to Agent Registry by manual registration.⁠Source 13At their own upstream URLs, which the gateway proxies to.⁠Source 6 Agents can speak A2A or plain HTTP.⁠Source 6
Who runs itAgent Gateway is a managed, regional component.⁠Source 14 Self-hosting Agent Registry or Agent Gateway is not publicly documented.In 2.x, Kong runs the control plane in Konnect, and you run the data plane nodes.⁠Source 4 Fully self-hosted AI gateways are a separate Kong offering.⁠Source 15
Pricing modelAgent Registry is free; skill scanning is billed from January 2027.⁠Source 16 Agent Runtime compute is $0.085 per vCPU-hour, and gateway egress $0.085 per 15,000 requests.⁠Source 17 Monthly free tier.⁠Source 17AI Management Plus from $25 a month plus usage; control planes are $200 a month hybrid, $500 Dedicated Cloud, or $25 serverless.⁠Source 15 A 30-day free trial.⁠Source 15 Enterprise is custom, billed annually.⁠Source 15
Generally availableAgent Registry and Agent Gateway since 18 June 2026.⁠Source 18 Agent Identity is generally available; the Agent Identity API is in preview.⁠Source 18Version 2.0 announced generally available on 1 September 2026.⁠Source 19 The agent inventory in Konnect Catalog is in beta.⁠Source 12

What each one is

Gemini Enterprise Agent Platform

Gemini Enterprise Agent Platform is Google Cloud’s platform to build, deploy, and govern agents, an evolution of Vertex AI.⁠Source 1, Source 2 Agent Registry catalogs agents and MCP servers, Agent Identity can give agents on supported runtimes an identity, and Agent Gateway applies policy checks to traffic.⁠Source 5, Source 10, Source 11

Kong AI Gateway

Kong AI Gateway is one gateway for LLM, MCP, and agent-to-agent (A2A) traffic, with shared authentication, observability, and policy features.⁠Source 3, Source 4 In 2.x, an agent is added as an AI Agent entity, which proxies to the agent’s URL and can carry policies.⁠Source 6, Source 20

The differences that matter

  1. Agent registry

    Gemini Enterprise Agent Platform

    Agent Registry, generally available, catalogs agents per Google Cloud project; agents on supported runtimes can be registered automatically, and others by manual registration.⁠Source 11, Source 18, Source 21, Source 22, Source 23

    Kong AI Gateway

    In 2.x, each agent entity is scoped to one gateway instance; Konnect Catalog’s organization-wide agent inventory is in beta, not for production.⁠Source 4, Source 6, Source 12

    Google’s automatic registration doesn’t discover agents in other projects.⁠Source 23 In Kong’s Catalog beta, agents are added by pasting an A2A card; other import routes are marked coming soon.⁠Source 12

  2. Identity and access

    Gemini Enterprise Agent Platform

    Agents on supported runtimes can get a SPIFFE-based identity, linked by IAM policies to approved tools; by default, Agent Gateway blocks connections without a grant.⁠Source 5, Source 10

    Kong AI Gateway

    The gateway can require an API key or OpenID Connect from callers, then check a per-agent allow or deny list before traffic reaches the agent.⁠Source 6

    Google’s Agent Identity is the agent’s own, for acting as itself or for a user; Kong’s access lists check the caller’s AI Consumer identity.⁠Source 6, Source 10

  3. Which agents each gateway covers

    Gemini Enterprise Agent Platform

    Agent Gateway can govern traffic for agents on Agent Runtime, both ways, and in the Gemini Enterprise app, outbound only.⁠Source 5

    Kong AI Gateway

    One data plane carries LLM, MCP, and A2A traffic, with shared authentication, observability, and policy, to any agent registered as an upstream URL.⁠Source 4, Source 6

    Google’s inbound mode works only for agents deployed in Agent Runtime.⁠Source 5 Kong says AI Gateway connects to major LLM providers through one consistent API.⁠Source 24

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicGemini Enterprise Agent PlatformKong AI Gateway
Network exposureAgent Gateway manages mTLS.⁠Source 5 Inbound mode fronts only Agent Runtime agents; outbound gateway calls need an IAM grant by default.⁠Source 5In 2.x, data plane nodes you run proxy to each agent’s URL and authenticate to the control plane over mTLS.⁠Source 4, Source 6
IdentityAgents on supported runtimes can have a SPIFFE-based Agent Identity, generally available; the Agent Identity API is in preview.⁠Source 10, Source 18Can require an API key, or OpenID Connect through Okta, Azure AD, Google, or another OIDC provider, before routing.⁠Source 6, Source 25
Access changes and revocationDeny rules override allow; deleting an agent leaves inactive IAM grants behind.⁠Source 10, Source 26 Disabling without deleting is not publicly documented.Each agent has an enabled switch; Request Termination or deny lists block callers.⁠Source 6, Source 27, Source 28 Nodes keep their last config without Konnect.⁠Source 4
Audit trailRegistry admin changes are audit-logged; other calls only if Data Access logs are on.⁠Source 29, Source 30 Gateway logs record access requests.⁠Source 7A2A audit logs: task IDs, method calls, latencies, errors.⁠Source 8 Konnect audit logs (Enterprise): webhook delivery, kept 7 days in Konnect.⁠Source 15, Source 31
ComplianceListed in scope for ISO 27001, SOC 1, 2, and 3, and PCI DSS, and in Google Cloud’s HIPAA BAA.⁠Source 32, Source 332.2+ FIPS mode: FIPS 140-3 algorithms only, not NIST-validated.⁠Source 34 Kong Inc. lists ISO 27001 and SOC 2 (report under NDA).⁠Source 35

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

Gemini Enterprise Agent Platform and Kong AI Gateway compared on 18 criteria
Gemini Enterprise Agent PlatformKong AI Gateway
What it is
What it is and who it’s forGoogle Cloud platform to build, deploy, govern, and optimize AI agents, described as an evolution of Vertex AI, for developers and technical teams.⁠Source 1, Source 2A gateway that governs LLM, MCP, and A2A traffic.⁠Source 3, Source 4 All three run through one data plane, with shared authentication, observability, and policy features.⁠Source 4
MaturityGoogle announced it on 22 April 2026.⁠Source 36 Registry and Gateway GA 18 June 2026.⁠Source 18 Agent Identity is generally available; the Agent Identity API is in preview.⁠Source 18Version 2.0 announced generally available on 1 September 2026; 2.2.0 released 30 September 2026.⁠Source 19, Source 37 Konnect Catalog’s agent inventory is in beta.⁠Source 12
Control
Agent registry and discoveryAgent Registry: a per-project catalog of agents, MCP servers, and tools.⁠Source 11, Source 21 Agents on supported runtimes can be registered automatically, others manually.⁠Source 22, Source 23In 2.x, each AI Agent entity, A2A or plain HTTP, is scoped to one gateway instance.⁠Source 4, Source 6 Konnect Catalog’s agent inventory is in beta.⁠Source 12
Identity and access controlSPIFFE-based identity for agents on supported runtimes.⁠Source 10 IAM policies link it to approved tools; by default, Agent Gateway blocks connections without a grant.⁠Source 5Can require an API key or an OpenID Connect login, through Okta, Azure AD, or another provider, then check a per-agent allow or deny list.⁠Source 6, Source 25
Ownership, policy, and revocationAllow and deny access policies (deny overrides allow), enforce and dry-run modes, and Model Armor filters.⁠Source 5, Source 26 An agent owner field is not publicly documented.Agent policies include input validation, logging, and rate limits.⁠Source 6 Kong’s AI PII Sanitizer scrubs requests to AI models: a Plus add-on, included on Enterprise.⁠Source 15, Source 38
Audit log and observabilityRegistry admin changes are audit-logged; reads only if Data Access logs are on.⁠Source 29, Source 30 Gateway logs record access requests.⁠Source 7 Traces need agents’ OpenTelemetry data.⁠Source 39A2A audit logs record task IDs, method calls, latencies, and errors.⁠Source 8 A2A telemetry can go to Konnect and OpenTelemetry.⁠Source 6 Bodies go to Konnect only if you opt in.⁠Source 4
Connection
How agents connectAgent Gateway can govern calls in and out of Runtime agents, and out of the Gemini Enterprise app.⁠Source 5 Outside agents are registered by endpoint or agent card.⁠Source 13Each agent is an upstream URL the gateway proxies to.⁠Source 6 In 2.x, data plane nodes you run forward allowed traffic and stay connected to Konnect.⁠Source 4
Agents across organizationsRuntime agents can call agents anywhere via Agent Gateway.⁠Source 5 A2A agents (preview) that control access themselves can be exposed to untrusted callers, Google says.⁠Source 40Not publicly documented (checked 2 October 2026)
Protocol supportAgent Registry catalogs MCP servers and A2A agents; Agent Gateway carries MCP and A2A traffic.⁠Source 5, Source 23, Source 41 A2A agents on Agent Runtime are in preview.⁠Source 42A2A over JSON-RPC and REST bindings.⁠Source 6 Four MCP revisions, 2025-03-26 to 2026-07-28 (the last from version 2.1).⁠Source 43
Frameworks, models, and clouds supportedAgent Development Kit or any open-source framework, with Gemini or other Model Garden models.⁠Source 44 Agents hosted outside Google Cloud can be registered manually.⁠Source 13Kong says it governs A2A traffic without changing how agents are built.⁠Source 45 Agents that don’t use A2A can pass through as plain HTTP.⁠Source 6
Operations
Deployment options and data residencyAgent Gateway is managed and regional.⁠Source 14 Agent data at rest stays in a supported location you pick.⁠Source 46 Self-hosting the registry or gateway: not publicly documented.2.x: a Konnect-managed control plane in a region you choose, data plane nodes you run.⁠Source 4, Source 47 Kong also sells Kong-managed Dedicated Cloud and serverless gateways.⁠Source 15, Source 48, Source 49
Compliance attestationsGoogle lists Agent Platform in scope for ISO 27001, 27017, and 27018, SOC 1, 2, and 3, and PCI DSS, and in the Google Cloud HIPAA BAA.⁠Source 32, Source 33From 2.2, FIPS mode uses only FIPS 140-3 approved algorithms; not submitted for NIST validation.⁠Source 34 Kong lists ISO 27001, SOC 2, and PCI DSS for Kong Inc.⁠Source 35
Support and SLAGoogle Cloud support packages, including 24/7 coverage.⁠Source 50 An uptime SLA naming Agent Registry, Gateway, Identity, or Runtime is not publicly documented.Konnect targets 99.9% availability; Dedicated Cloud Gateways list a 99.99% SLA, serverless gateways none.⁠Source 15 Enterprise support SLAs: 30 min to 2 hours.⁠Source 15
Time and effort to get runningA Google Cloud project with the Agent Registry API enabled, plus the Identity-Aware Proxy API for gateway policy.⁠Source 21 Google recommends a dry run in staging.⁠Source 26A quickstart script creates a Konnect control plane and a local Docker data plane.⁠Source 24 To route A2A traffic, create an AI Agent entity and attach policies.⁠Source 20
Pricing model and public pricesAgent Registry is free; skill scanning is billed from January 2027.⁠Source 16 Gateway egress: $0.085 per 15,000 requests; runtime: $0.085 a vCPU-hour.⁠Source 17 Monthly free tier.⁠Source 17Plus: from $25 a month plus usage; per control plane, $200 hybrid, $500 Dedicated Cloud, $25 serverless.⁠Source 15 Enterprise: custom, billed annually.⁠Source 15
Building
Agent building toolsAgent Studio (a low-code canvas), the open-source Agent Development Kit, and Agent Garden prebuilt agents and templates.⁠Source 1, Source 44 A Managed Agents API is in preview.⁠Source 1Kong says it can generate MCP tools and servers from Kong-managed APIs.⁠Source 3 Tools for building agents in Kong AI Gateway are not publicly documented.
Model accessGoogle says Model Garden offers more than 200 models, including Gemini, third-party models such as Anthropic’s Claude, and open-source models.⁠Source 1, Source 36One API to providers including OpenAI, Anthropic, Amazon Bedrock, Gemini, Azure AI, Mistral, and Ollama, with credentials you supply.⁠Source 4, Source 24, Source 51
Integrations and ecosystemAgents in Agent Registry can be made available to users of the Gemini Enterprise app.⁠Source 14 Google’s own remote MCP servers are registered automatically.⁠Source 41A Policies Hub of policies and integrations.⁠Source 27 AI Vault works with AWS, GCP, Azure, and HashiCorp Vault secrets backends.⁠Source 4

Which to choose

Choose Gemini Enterprise Agent Platform if

  • You want to build, deploy, and govern agents on one platform, with Agent Studio and the open-source Agent Development Kit.⁠Source 1, Source 44
  • Your agents run on Google Cloud, where agents on supported runtimes, such as Google Kubernetes Engine, can be registered automatically.⁠Source 22, Source 23
  • You want agents on supported runtimes to have their own identity, and Agent Gateway to block connections without an IAM grant.⁠Source 5, Source 10
  • You want a wide choice of models: Google says Model Garden offers more than 200, including Anthropic’s Claude.⁠Source 36

Choose Kong AI Gateway if

  • You want one gateway for LLM, MCP, and A2A traffic, with shared authentication, observability, and policy features.⁠Source 3, Source 4
  • You want a gateway that proxies to existing agents’ URLs; Kong says it governs A2A traffic without changing how agents are built.⁠Source 6, Source 45
  • You want to run the gateway’s data plane nodes yourself (2.x), or a fully self-hosted AI gateway, a separate Kong offering.⁠Source 4, Source 15
  • You want one API to many model providers, such as OpenAI, Anthropic, Gemini, and Mistral, using credentials you supply.⁠Source 4, Source 24, Source 51

Questions buyers ask

Do they support MCP and A2A?

Agent Registry catalogs MCP servers and A2A agents, and Agent Gateway carries MCP and A2A traffic; A2A agents on Agent Runtime are in preview.⁠Source 5, Source 23, Source 41, Source 42 Kong AI Gateway detects A2A requests over JSON-RPC and REST bindings and accepts four MCP revisions, the newest from version 2.1.⁠Source 6, Source 43

Can either one be self-hosted?

Self-hosting Agent Registry or Agent Gateway is not publicly documented; Google describes Agent Gateway as a managed, regional component.⁠Source 14 Fully self-hosted Kong AI gateways are part of Kong’s separate Gateway Enterprise offering; the 2.x AI entities are hybrid, with a Konnect-managed control plane.⁠Source 4, Source 15

Can either one connect agents across organizations?

Agent Runtime agents can call agents anywhere through Agent Gateway.⁠Source 5 Google says preview A2A agents handling their own auth can be exposed to untrusted callers.⁠Source 40 Kong AI Gateway proxies to agents registered as upstream URLs.⁠Source 6 For both, a cross-organization trust model is not publicly documented.

How is each one priced?

Agent Registry is free; skill scanning is billed from January 2027.⁠Source 16 Agent Runtime is $0.085 per vCPU-hour; Agent Gateway egress, $0.085 per 15,000 requests.⁠Source 17 Kong’s AI Management Plus starts at $25 a month plus usage, and $200 monthly per hybrid control plane; Enterprise is custom.⁠Source 15

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

58 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Agent Platform overview Google · checked Back:abcdefghij

  2. Source 2: Gemini Enterprise Agent Platform (formerly Vertex AI) Google · checked Back:abc

  3. Source 3: Kong AI Gateway product page Kong · checked Back:abcdefgh

  4. Source 4: AI Gateway architecture - Kong Docs Kong · checked Back:abcdefghijklmnopqrst

  5. Source 5: Agent Gateway overview Google · checked Back:abcdefghijklmnopqrstu

  6. Source 6: AI Agents - Kong AI Gateway docs Kong · checked Back:abcdefghijklmnopqrstuvw

  7. Source 7: Monitor traffic through Agent Gateway Google · checked Back:abc

  8. Source 8: Route A2A traffic through AI Gateway - Kong Docs Kong · checked Back:abc

  9. Source 9: Gemini - AI Gateway provider | Kong Docs Kong · checked Back to text

  10. Source 10: Agent Identity overview Google · checked Back:abcdefgh

  11. Source 11: Agent Registry overview Google · checked Back:abcd

  12. Source 12: Agents in Catalog - Kong Docs Kong · checked Back:abcdef

  13. Source 13: Use manual registration Google · checked Back:abc

  14. Source 14: Import A2A agents from Agent Registry Google · checked Back:abcd

  15. Source 15: Kong Pricing & Plans Kong · checked Back:abcdefghijklmn

  16. Source 16: Agent Registry pricing Google · checked Back:abc

  17. Source 17: Gemini Enterprise Agent Platform pricing Google · checked Back:abcde

  18. Source 18: Gemini Enterprise Agent Platform release notes Google · checked Back:abcdef

  19. Source 19: Kong AI Gateway 2.0 Is Now GA - And It's Already Moving Faster Kong · checked Back:ab

  20. Source 20: Route A2A agent traffic through AI Gateway - Kong Docs Kong · checked Back:ab

  21. Source 21: Set up Agent Registry Google · checked Back:abc

  22. Source 22: Use automatic registration Google · checked Back:abc

  23. Source 23: Register agents Google · checked Back:abcdef

  24. Source 24: Kong AI Gateway | Kong Docs Kong · checked Back:abcd

  25. Source 25: AI Auth Strategies - Kong AI Gateway docs Kong · checked Back:ab

  26. Source 26: IAM Access policies overview Google · checked Back:abc

  27. Source 27: Kong AI Gateway Policies - Kong Docs Kong · checked Back:ab

  28. Source 28: Request Termination - Configuration Reference - Policy | Kong Docs Kong · checked Back to text

  29. Source 29: Agent Registry audit logging Google · checked Back:ab

  30. Source 30: Cloud Audit Logs overview Google · checked Back:ab

  31. Source 31: Konnect and Dev Portal audit logs - Kong Docs Kong · checked Back to text

  32. Source 32: Google Cloud Platform Services in Scope by Compliance Program Google · checked Back:ab

  33. Source 33: HIPAA compliance on Google Cloud Google · checked Back:ab

  34. Source 34: FIPS 140-3 compliance in AI Gateway - Kong Docs Kong · checked Back:ab

  35. Source 35: Trust Center - Kong Inc. Kong · checked Back:ab

  36. Source 36: Introducing Gemini Enterprise Agent Platform, powering the next wave of agents Google · checked Back:abc

  37. Source 37: Kong AI Gateway changelog - Kong Docs Kong · checked Back to text

  38. Source 38: AI PII Sanitizer - Policy | Kong Docs Kong · checked Back to text

  39. Source 39: Observability overview Google · checked Back to text

  40. Source 40: Share an agent Google · checked Back:ab

  41. Source 41: Register MCP servers Google · checked Back:abc

  42. Source 42: Create an Agent2Agent agent Google · checked Back:ab

  43. Source 43: MCP version support - Kong AI Gateway docs Kong · checked Back:ab

  44. Source 44: Build with Gemini Enterprise Agent Platform Google · checked Back:abc

  45. Source 45: The Agent Gateway for Secure, Observable Agent-to-Agent Communication (Kong) Kong · checked Back:ab

  46. Source 46: Supported locations for agents in Agent Platform Google · checked Back to text

  47. Source 47: Geographic regions - Kong Docs Kong · checked Back to text

  48. Source 48: Dedicated Cloud Gateways - Kong Docs Kong · checked Back to text

  49. Source 49: Serverless Gateways - Kong Docs Kong · checked Back to text

  50. Source 50: Getting help for agents Google · checked Back to text

  51. Source 51: AI Gateway providers - Kong Docs Kong · checked Back:ab

  52. Source 52: Why Blocks? Blocks.ai · checked Back to text

  53. Source 53: What is Blocks? Blocks.ai · checked Back to text

  54. Source 54: Your company's private network Blocks.ai · checked Back to text

  55. Source 55: Network requirements Blocks.ai · checked Back to text

  56. Source 56: Solutions: Agent sprawl Blocks.ai · checked Back to text

  57. Source 57: Solutions: Partner networks Blocks.ai · checked Back to text

  58. Source 58: Pricing Blocks.ai · checked Back to text