The security industry loves a shortcut. When AI agents started multiplying across the enterprise, the reflexive move was to drop a gateway in front of them and call it a day. That is understandable. Gateways are tangible, they promise control, and they fit neatly into existing network diagrams. But as Nik Kale's analysis makes painfully clear, this is exactly backwards. The gateway is the control teams reach for first, yet it is the one they are least prepared to run, because it depends on identity and attribution layers that, in most organizations, simply do not exist yet. We are not saying gateways are useless. We are saying they are the final piece of a puzzle that most teams have not even started assembling. The pattern of failure is not hypothetical. Consider the LiteLLM flaw that CISA added to its Known Exploited Vulnerabilities catalog after attackers exploited it in the wild. That bug, chained with a second flaw, required no credentials and ran commands on the host through the gateway itself. It was one of seven CVEs disclosed in that single AI gateway in a single month. That is not a fringe product issue; it is a symptom of a deeper structural problem. Teams are treating the gateway as a security boundary when it is actually a routing mechanism that sits on top of an incomplete identity model. And this is where the conversation gets uncomfortable: the gateway can authenticate a user token and check an API call, but it cannot see that the request is agent-initiated, that the agent is executing a more limited function, or that the request is part of a tool chain invoked by an untrusted artifact. The credential is valid. The API call is permissible. The action contradicts the purpose of the delegation. The gateway is there, but its set of supports seems absent. Kale's dependency-gated deployment model offers a way out, and it starts with a simple question: can you name your agents? Not the ones in a pilot program or a slide deck, but the ones actually running in production across open-source frameworks, cloud offerings, and SaaS services. For each one, you need an owner, a purpose, approved tools, and a lifecycle state. That is not busywork. That is the inventory that every downstream control governs. From there, the sequence matters. An agent needs its own identity, distinct from the human or service that delegated the work. It needs task-scoped, short-lived credentials, not inherited permissions from a shared service account. It needs attributable telemetry, so a completed task can be reconstructed from initiation to downstream effect. Only then should runtime enforcement come into play, and even then, only at irreversible boundaries like payments, access policy changes, or data exports. The gateways earn their keep when they can answer the question: is this agent authorized to perform this action, for this principal, within this task, involving this resource? If the answer requires context that does not exist yet, the gateway is just an expensive firewall for a problem it cannot see. The practical takeaway here is not that gateways are worthless. It is that sequencing is everything. Deploying enforcement before building the identity and attribution context it depends on is like installing a deadbolt on a door that has not been framed yet. The data backs this up: in Okta's 2026 survey, only 34% of executives said their organization always applies the same level of security rigor to its agentic workforce as to its human workforce. And in the 2026 Teleport study, organizations with over-privileged AI reported a 76% incident rate, versus 17% for those operating under least privilege. Access scope is not a nice-to-have; it is the strongest predictor of whether an AI incident will happen at all. So here is what we would tell you directly: start your next 30 days by picking ten production agents, writing down their owners, purposes, and credentials, and testing whether your IAM and logging can tell each agent apart from the human who delegated the task. If the chain breaks anywhere, that is where your deployment falls short.
generative AI for data analysis
Gateways can't fix what identity layers don't yet secure.
Start with the agents you can actually name.
4 min readVentureBeat

There is a clear repeating trend in agent deployments: The gateway is the first control teams reach for, but it is the one they are least ready to run. This is because gateways sit on top of identity and attribution layers that are mostly not there.