Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.
Gemini Enterprise Agent Platform vs Kong AI Gateway
Gemini Enterprise Agent Platform
Google Cloud platform to build, deploy, govern, and optimize AI agents
Kong AI Gateway
Gateway that governs LLM, MCP, and agent-to-agent traffic
Short answer
Gemini Enterprise Agent Platform is Google Cloud’s platform to build, deploy, and govern agents; Kong AI Gateway is a gateway for LLM, MCP, and A2A traffic.Source 1, Source 2, Source 3, Source 4 Agent Platform runs agents on Agent Runtime, where Agent Gateway can govern their traffic; Kong AI Gateway proxies to agents registered as upstream URLs.Source 5, Source 6
Where each one sits
Six layers of running AI agents at a company, and what each product’s own public sources say it covers.
These aren’t the same kind of product
- Where they overlap
- Both put a gateway in front of agent traffic, including MCP and A2A, that can check access before a call goes through and log requests.Source 3, Source 5, Source 6, Source 7, Source 8
- Where they differ
- Agent Platform also offers Agent Studio and the Agent Development Kit for building agents, and Agent Runtime to run them.Source 1, Source 5 Building agents in Kong AI Gateway is not publicly documented.
- Running both
- Kong’s docs say Kong AI Gateway can proxy Gemini models, including through Google Cloud’s aiplatform.googleapis.com endpoint.Source 9
Gemini Enterprise Agent Platform
Kong AI Gateway
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Agents across organizations: Not publicly documented
At a glance
What each one is
Gemini Enterprise Agent Platform
Gemini Enterprise Agent Platform is Google Cloud’s platform to build, deploy, and govern agents, an evolution of Vertex AI.Source 1, Source 2 Agent Registry catalogs agents and MCP servers, Agent Identity can give agents on supported runtimes an identity, and Agent Gateway applies policy checks to traffic.Source 5, Source 10, Source 11
Kong AI Gateway
Kong AI Gateway is one gateway for LLM, MCP, and agent-to-agent (A2A) traffic, with shared authentication, observability, and policy features.Source 3, Source 4 In 2.x, an agent is added as an AI Agent entity, which proxies to the agent’s URL and can carry policies.Source 6, Source 20
The differences that matter
Agent registry
Gemini Enterprise Agent PlatformAgent Registry, generally available, catalogs agents per Google Cloud project; agents on supported runtimes can be registered automatically, and others by manual registration.Source 11, Source 18, Source 21, Source 22, Source 23
Kong AI GatewayIn 2.x, each agent entity is scoped to one gateway instance; Konnect Catalog’s organization-wide agent inventory is in beta, not for production.Source 4, Source 6, Source 12
Google’s automatic registration doesn’t discover agents in other projects.Source 23 In Kong’s Catalog beta, agents are added by pasting an A2A card; other import routes are marked coming soon.Source 12
Identity and access
Gemini Enterprise Agent PlatformAgents on supported runtimes can get a SPIFFE-based identity, linked by IAM policies to approved tools; by default, Agent Gateway blocks connections without a grant.Source 5, Source 10
Kong AI GatewayThe gateway can require an API key or OpenID Connect from callers, then check a per-agent allow or deny list before traffic reaches the agent.Source 6
Google’s Agent Identity is the agent’s own, for acting as itself or for a user; Kong’s access lists check the caller’s AI Consumer identity.Source 6, Source 10
Which agents each gateway covers
Gemini Enterprise Agent PlatformAgent Gateway can govern traffic for agents on Agent Runtime, both ways, and in the Gemini Enterprise app, outbound only.Source 5
Kong AI GatewayOne data plane carries LLM, MCP, and A2A traffic, with shared authentication, observability, and policy, to any agent registered as an upstream URL.Source 4, Source 6
Google’s inbound mode works only for agents deployed in Agent Runtime.Source 5 Kong says AI Gateway connects to major LLM providers through one consistent API.Source 24
For security teams
What a security review asks, answered from each vendor’s public documentation.
Full comparison
18 criteria in five groups. Every cell links to its source, or says no public source answers it.
| Gemini Enterprise Agent Platform | Kong AI Gateway | |
|---|---|---|
| What it is | ||
| What it is and who it’s for | Google Cloud platform to build, deploy, govern, and optimize AI agents, described as an evolution of Vertex AI, for developers and technical teams.Source 1, Source 2 | A gateway that governs LLM, MCP, and A2A traffic.Source 3, Source 4 All three run through one data plane, with shared authentication, observability, and policy features.Source 4 |
| Maturity | Google announced it on 22 April 2026.Source 36 Registry and Gateway GA 18 June 2026.Source 18 Agent Identity is generally available; the Agent Identity API is in preview.Source 18 | Version 2.0 announced generally available on 1 September 2026; 2.2.0 released 30 September 2026.Source 19, Source 37 Konnect Catalog’s agent inventory is in beta.Source 12 |
| Control | ||
| Agent registry and discovery | Agent Registry: a per-project catalog of agents, MCP servers, and tools.Source 11, Source 21 Agents on supported runtimes can be registered automatically, others manually.Source 22, Source 23 | In 2.x, each AI Agent entity, A2A or plain HTTP, is scoped to one gateway instance.Source 4, Source 6 Konnect Catalog’s agent inventory is in beta.Source 12 |
| Identity and access control | SPIFFE-based identity for agents on supported runtimes.Source 10 IAM policies link it to approved tools; by default, Agent Gateway blocks connections without a grant.Source 5 | Can require an API key or an OpenID Connect login, through Okta, Azure AD, or another provider, then check a per-agent allow or deny list.Source 6, Source 25 |
| Ownership, policy, and revocation | Allow and deny access policies (deny overrides allow), enforce and dry-run modes, and Model Armor filters.Source 5, Source 26 An agent owner field is not publicly documented. | Agent policies include input validation, logging, and rate limits.Source 6 Kong’s AI PII Sanitizer scrubs requests to AI models: a Plus add-on, included on Enterprise.Source 15, Source 38 |
| Audit log and observability | Registry admin changes are audit-logged; reads only if Data Access logs are on.Source 29, Source 30 Gateway logs record access requests.Source 7 Traces need agents’ OpenTelemetry data.Source 39 | A2A audit logs record task IDs, method calls, latencies, and errors.Source 8 A2A telemetry can go to Konnect and OpenTelemetry.Source 6 Bodies go to Konnect only if you opt in.Source 4 |
| Connection | ||
| How agents connect | Agent Gateway can govern calls in and out of Runtime agents, and out of the Gemini Enterprise app.Source 5 Outside agents are registered by endpoint or agent card.Source 13 | Each agent is an upstream URL the gateway proxies to.Source 6 In 2.x, data plane nodes you run forward allowed traffic and stay connected to Konnect.Source 4 |
| Agents across organizations | Runtime agents can call agents anywhere via Agent Gateway.Source 5 A2A agents (preview) that control access themselves can be exposed to untrusted callers, Google says.Source 40 | Not publicly documented (checked 2 October 2026) |
| Protocol support | Agent Registry catalogs MCP servers and A2A agents; Agent Gateway carries MCP and A2A traffic.Source 5, Source 23, Source 41 A2A agents on Agent Runtime are in preview.Source 42 | A2A over JSON-RPC and REST bindings.Source 6 Four MCP revisions, 2025-03-26 to 2026-07-28 (the last from version 2.1).Source 43 |
| Frameworks, models, and clouds supported | Agent Development Kit or any open-source framework, with Gemini or other Model Garden models.Source 44 Agents hosted outside Google Cloud can be registered manually.Source 13 | Kong says it governs A2A traffic without changing how agents are built.Source 45 Agents that don’t use A2A can pass through as plain HTTP.Source 6 |
| Operations | ||
| Deployment options and data residency | Agent Gateway is managed and regional.Source 14 Agent data at rest stays in a supported location you pick.Source 46 Self-hosting the registry or gateway: not publicly documented. | 2.x: a Konnect-managed control plane in a region you choose, data plane nodes you run.Source 4, Source 47 Kong also sells Kong-managed Dedicated Cloud and serverless gateways.Source 15, Source 48, Source 49 |
| Compliance attestations | Google lists Agent Platform in scope for ISO 27001, 27017, and 27018, SOC 1, 2, and 3, and PCI DSS, and in the Google Cloud HIPAA BAA.Source 32, Source 33 | From 2.2, FIPS mode uses only FIPS 140-3 approved algorithms; not submitted for NIST validation.Source 34 Kong lists ISO 27001, SOC 2, and PCI DSS for Kong Inc.Source 35 |
| Support and SLA | Google Cloud support packages, including 24/7 coverage.Source 50 An uptime SLA naming Agent Registry, Gateway, Identity, or Runtime is not publicly documented. | Konnect targets 99.9% availability; Dedicated Cloud Gateways list a 99.99% SLA, serverless gateways none.Source 15 Enterprise support SLAs: 30 min to 2 hours.Source 15 |
| Time and effort to get running | A Google Cloud project with the Agent Registry API enabled, plus the Identity-Aware Proxy API for gateway policy.Source 21 Google recommends a dry run in staging.Source 26 | A quickstart script creates a Konnect control plane and a local Docker data plane.Source 24 To route A2A traffic, create an AI Agent entity and attach policies.Source 20 |
| Pricing model and public prices | Agent Registry is free; skill scanning is billed from January 2027.Source 16 Gateway egress: $0.085 per 15,000 requests; runtime: $0.085 a vCPU-hour.Source 17 Monthly free tier.Source 17 | Plus: from $25 a month plus usage; per control plane, $200 hybrid, $500 Dedicated Cloud, $25 serverless.Source 15 Enterprise: custom, billed annually.Source 15 |
| Building | ||
| Agent building tools | Agent Studio (a low-code canvas), the open-source Agent Development Kit, and Agent Garden prebuilt agents and templates.Source 1, Source 44 A Managed Agents API is in preview.Source 1 | Kong says it can generate MCP tools and servers from Kong-managed APIs.Source 3 Tools for building agents in Kong AI Gateway are not publicly documented. |
| Model access | Google says Model Garden offers more than 200 models, including Gemini, third-party models such as Anthropic’s Claude, and open-source models.Source 1, Source 36 | One API to providers including OpenAI, Anthropic, Amazon Bedrock, Gemini, Azure AI, Mistral, and Ollama, with credentials you supply.Source 4, Source 24, Source 51 |
| Integrations and ecosystem | Agents in Agent Registry can be made available to users of the Gemini Enterprise app.Source 14 Google’s own remote MCP servers are registered automatically.Source 41 | A Policies Hub of policies and integrations.Source 27 AI Vault works with AWS, GCP, Azure, and HashiCorp Vault secrets backends.Source 4 |
Which to choose
Choose Gemini Enterprise Agent Platform if
- You want to build, deploy, and govern agents on one platform, with Agent Studio and the open-source Agent Development Kit.Source 1, Source 44
- Your agents run on Google Cloud, where agents on supported runtimes, such as Google Kubernetes Engine, can be registered automatically.Source 22, Source 23
- You want agents on supported runtimes to have their own identity, and Agent Gateway to block connections without an IAM grant.Source 5, Source 10
- You want a wide choice of models: Google says Model Garden offers more than 200, including Anthropic’s Claude.Source 36
Choose Kong AI Gateway if
- You want one gateway for LLM, MCP, and A2A traffic, with shared authentication, observability, and policy features.Source 3, Source 4
- You want a gateway that proxies to existing agents’ URLs; Kong says it governs A2A traffic without changing how agents are built.Source 6, Source 45
- You want to run the gateway’s data plane nodes yourself (2.x), or a fully self-hosted AI gateway, a separate Kong offering.Source 4, Source 15
- You want one API to many model providers, such as OpenAI, Anthropic, Gemini, and Mistral, using credentials you supply.Source 4, Source 24, Source 51
Questions buyers ask
Do they support MCP and A2A?
Agent Registry catalogs MCP servers and A2A agents, and Agent Gateway carries MCP and A2A traffic; A2A agents on Agent Runtime are in preview.Source 5, Source 23, Source 41, Source 42 Kong AI Gateway detects A2A requests over JSON-RPC and REST bindings and accepts four MCP revisions, the newest from version 2.1.Source 6, Source 43
Can either one be self-hosted?
Self-hosting Agent Registry or Agent Gateway is not publicly documented; Google describes Agent Gateway as a managed, regional component.Source 14 Fully self-hosted Kong AI gateways are part of Kong’s separate Gateway Enterprise offering; the 2.x AI entities are hybrid, with a Konnect-managed control plane.Source 4, Source 15
Can either one connect agents across organizations?
Agent Runtime agents can call agents anywhere through Agent Gateway.Source 5 Google says preview A2A agents handling their own auth can be exposed to untrusted callers.Source 40 Kong AI Gateway proxies to agents registered as upstream URLs.Source 6 For both, a cross-organization trust model is not publicly documented.
How is each one priced?
Agent Registry is free; skill scanning is billed from January 2027.Source 16 Agent Runtime is $0.085 per vCPU-hour; Agent Gateway egress, $0.085 per 15,000 requests.Source 17 Kong’s AI Management Plus starts at $25 a month plus usage, and $200 monthly per hybrid control plane; Enterprise is custom.Source 15
How we compare
Read the full methodEvery claim on this page links to a public source. Where none answers a question, the page says so.
We re-check every fact at least every 90 days. This page was last checked .
Something wrong or out of date? Tell us and we’ll correct it.
Sources
58 public sources, each with the date we checked it. Every one opens in a new tab.
Source 2: Gemini Enterprise Agent Platform (formerly Vertex AI) Back:abc
Source 4: AI Gateway architecture - Kong Docs Back:abcdefghijklmnopqrst
Source 6: AI Agents - Kong AI Gateway docs Back:abcdefghijklmnopqrstuvw
Source 8: Route A2A traffic through AI Gateway - Kong Docs Back:abc
Source 9: Gemini - AI Gateway provider | Kong Docs Back to text
Source 17: Gemini Enterprise Agent Platform pricing Back:abcde
Source 18: Gemini Enterprise Agent Platform release notes Back:abcdef
Source 19: Kong AI Gateway 2.0 Is Now GA - And It's Already Moving Faster Back:ab
Source 20: Route A2A agent traffic through AI Gateway - Kong Docs Back:ab
Source 25: AI Auth Strategies - Kong AI Gateway docs Back:ab
Source 28: Request Termination - Configuration Reference - Policy | Kong Docs Back to text
Source 31: Konnect and Dev Portal audit logs - Kong Docs Back to text
Source 32: Google Cloud Platform Services in Scope by Compliance Program Back:ab
Source 34: FIPS 140-3 compliance in AI Gateway - Kong Docs Back:ab
Source 36: Introducing Gemini Enterprise Agent Platform, powering the next wave of agents Back:abc
Source 37: Kong AI Gateway changelog - Kong Docs Back to text
Source 38: AI PII Sanitizer - Policy | Kong Docs Back to text
Source 43: MCP version support - Kong AI Gateway docs Back:ab
Source 44: Build with Gemini Enterprise Agent Platform Back:abc
Source 45: The Agent Gateway for Secure, Observable Agent-to-Agent Communication (Kong) Back:ab
Source 46: Supported locations for agents in Agent Platform Back to text
Source 48: Dedicated Cloud Gateways - Kong Docs Back to text