TYTONEST
AI GATEWAY COMPONENT BENCHMARK 2026

AI Gateway & Agentic AI Security

Model Traffic Governance · Shadow AI Discovery · Prompt-Injection Defense · Model Supply-Chain Risk · Agentic & MCP Governance · 2026 Component Analysis — SASE Codex

Bottom Line Up Front

Palo Alto Networks leads the AI Gateway pillar — Prisma AIRS is the only Big Six stack with a shipped, GA'd capability in every sub-domain (multi-provider LLM gateway, AI-SPM, prompt-injection defense, model/skill scanning, agent identity, and MCP governance), though the gateway and AI-SPM pieces are themselves under three months old. Netskope and Cloudflare are a close, differently-shaped second tier: Netskope's Agentic Broker and AI Guardrails are the strongest MCP and prompt-injection story in the Codex but it has zero native model-scanning capability; Cloudflare's AI Gateway is a genuine multi-provider routing/cost-control plane and its MCP Server Portals are best-in-class, but it also has no model-scanning capability. Cato and Zscaler round out a tight middle tier — both have real, native AI-SPM and agentic-governance depth, but Cato has no LLM API gateway function at all and Zscaler's most-publicized agentic capability (AI Broker / Agent Registry) is confirmed by Zscaler's own investor remarks to still be pre-GA. Fortinet is the surprise of this review: FortiAIGate and FortiOS 8.0's native MCP observability are materially stronger than the Codex's existing SSE-pillar framing of Fortinet as "significantly behind" on agentic AI — that framing is now stale and flagged for a follow-up correction.

AI Gateway: the difference between watching AI traffic and governing an AI estate

Every SASE vendor in the Big Six can, by now, point a DLP engine at an employee's ChatGPT session — that's the existing genai_data_protection criterion in the SSE pillar, and it's a solved problem. This pillar asks a different question: once an organization starts building with AI — calling multiple LLM providers from its own applications, running autonomous agents that take actions, wiring those agents into internal tools via MCP servers, and pulling third-party models off the shelf — who is watching that estate?

That's a governance problem, not an inspection problem. It has six distinct sub-questions: Is there a single control plane for LLM API traffic (routing, rate limits, cost), or is every team calling providers directly with no visibility? Does the platform know what models, agents, and AI apps exist at all — sanctioned or not? Can it stop a prompt-injection attack at inference time, not just flag it afterward? Does anything scan a model file or an agent's tool-skill package for a backdoor before it goes into production? When an autonomous agent acts, does it have its own governed identity and a permission ceiling, or does it inherit a human's blanket access? And when that agent talks to a tool over MCP, is that connection discovered, policed, and audited — or invisible?

2026 is the year this stopped being roadmap language. Five of the Big Six shipped a named, GA'd product against at least four of these six sub-questions in the first three quarters of the year alone — this pillar exists because that shift is now real enough to score.

Criteria at a Glance


CRITICAL ×3

Visibility Foundation

  • AI-SPM / Shadow AI Discovery

You cannot govern what you cannot see — this is the entry point every other criterion depends on.

HIGH ×2

Traffic & Runtime Control

  • AI/LLM API Gateway
  • Runtime Prompt-Injection & Adversarial Defense
  • AI Model & Supply-Chain Scanning
  • Agentic AI Governance
MEDIUM ×1

Protocol Governance

  • MCP / Agentic Protocol Governance

Newest and narrowest criterion — the whole MCP ecosystem is under two years old — but the fastest-moving of the six through 2026.

Scoped separately from two existing criteria elsewhere in the Codex: SSE's genai_data_protection (inspecting GenAI-as-web-traffic — an employee using ChatGPT in a browser) and AIOps's genai_policy (using GenAI to author network policy, e.g. Strata Copilot). Both remain scored as-is in their original pillars; this pillar covers the non-overlapping ground of governing AI the enterprise builds and runs.

Vendor Summaries — AI Gateway Pillar


Palo Alto Networks — Most Architecturally Complete, Still Very New

EVERY SUB-DOMAIN COVERED · PRISMA AIRS

Prisma AIRS is the only Big Six stack with a shipped, GA'd capability against all six criteria in this pillar rather than partial coverage. Prompt-injection and jailbreak defense has run inline since April 2025 and is the most mature capability the Codex found in this review; MCP governance (Secure AI Agents, May 2026) enforces a default-disabled human-in-the-loop approval gate before any new MCP server can be used — a materially stricter default than most peers. The catch is timing: the multi-provider AI Gateway (built on the May 2026 Portkey acquisition) only reached GA on July 10, 2026, and Cortex AISPM's model/agent discovery layer shipped in August 2026 — both are under three months old at time of review, and nearly every capability claim currently traces to Palo Alto's own materials rather than independent validation. The stack itself is a recent stitch of native Prisma AIRS plus two 2026 acquisitions (Koi Security for the agentic endpoint, Portkey for the gateway).

▲ Strengths

Deepest native model/artifact scanning in the pillar — 35+ file formats, 25+ threat categories, CI/CD-integrated. Prompt-injection defense mature since April 2025, extended with native Anthropic/OpenAI inference hooks (Aug 2026). MCP governance is a fully specified native architecture with a default-disabled approval gate. Agent Identity Security gives agents governed, ephemeral, least-privilege identities. Unified AI Gateway consolidates routing, budget/rate enforcement, and cost observability in one control plane.

▼ Watch Areas

AI Gateway and Cortex AISPM are both under three months old at GA — provider breadth and telemetry normalization not yet independently proven at scale. Nearly all capability claims trace to Palo Alto's own press/blog. Dataset-level scanning and license/provenance risk scoring aren't clearly evidenced — coverage is model/artifact-centric, not full ML-pipeline. The stack is a recent stitch of native tech plus two 2026 acquisitions; analysts already flag integration-complexity risk.

→ Full AI Gateway analysis — palo-alto-networks.html

Netskope — Strongest MCP & Prompt-Injection Story, Zero Model Scanning

FASTEST BUILD-OUT · SKYLIGHT AI SECURITY

Netskope shipped the fastest six-criterion build-out of any vendor reviewed — AI Gateway, Agentic Broker, AI Guardrails, AI Red Teaming, AI Command Center, and Agent Action Control all launched between March and September 2026, now rebranded under "Netskope Skylight" as of September 15, 2026. Agentic Broker is the single strongest-evidenced capability the Codex found across all vendors in any criterion this pass — native MCP discovery, a default-block policy on public MCP traffic, and full session/tool-call audit. AI Guardrails' prompt-injection and jailbreak blocking spans 29 languages and maps directly to MITRE ATLAS and the OWASP LLM Top 10. The clear structural gap: there is no native model, dataset, or ML-pipeline-artifact scanning anywhere in the portfolio — "AI Red Teaming" is confirmed to be adversarial-prompt simulation against deployed models, not artifact scanning, and no partnership fills the gap. Agent identity and least-privilege enforcement also currently leans on a third-party partnership (Aembit) rather than native IAM.

▲ Strengths

Agentic Broker: native MCP discovery, default-block public-MCP policy, full tool-call audit trail. AI Guardrails: 29-language, multi-turn prompt-injection/jailbreak blocking mapped to MITRE ATLAS/OWASP LLM Top 10. AI Command Center: continuous multi-vector (endpoint/eBPF/inline) AI-app and agent discovery with automated risk scoring. AI Gateway Analytics Dashboard gives genuine per-provider token/cost/rate-limit observability.

▼ Watch Areas

No native model/dataset/ML-pipeline scanning anywhere in the portfolio — a structural gap, not just an unverified claim. Agent identity/least-privilege depends on the Aembit partnership rather than native IAM. Agent Action Control launched September 15, 2026 — days old at time of review. "Skylight" rebrand is actively reshuffling product names as this review closed; re-verify feature-parity claims as docs catch up.

→ Full AI Gateway analysis — netskope.html

Cloudflare — Genuine Multi-Provider Gateway, Best-in-Class MCP

AI GATEWAY LIVES UP TO ITS NAME

Cloudflare's product literally named "AI Gateway" earns the name: dynamic routing by latency/cost/availability across providers, fixed and sliding-window rate limiting, and dollar-denominated spend limits scoped by model/provider/team with automatic fallback routing — not the narrower single-app inline-inspection tool the name might suggest at a glance. MCP Server Portals (GA since an August 2025 open beta) are arguably Cloudflare's standout differentiator in this pillar: centralized MCP discovery and sync, per-server Access policy enforcement, tool-call-level audit logs, and an August 2026 WriteGuard add-on for fine-grained write-action controls. Prompt-injection defense runs inline in the WAF request path with a numeric likelihood score per prompt. Like Netskope, Cloudflare has no native model or dataset supply-chain scanning capability at all — that specialist ground (Protect AI, HiddenLayer, JFrog) is untouched — and its agentic-governance architecture (the Agent Access Model) is real but still landing in beta rather than fully GA.

▲ Strengths

Multi-provider AI Gateway with real routing, rate limits, and dollar-denominated spend controls. Best-in-class MCP governance: server portals, shadow-MCP detection, tool-call audit, WriteGuard write-action controls. Inline, scored prompt-injection detection built into the WAF request path (GA). Combined shadow-AI + sanctioned-app discovery with confidence/risk scoring via CASB. Identity-aware AI Gateway (Aug 2026) ties LLM usage and agent behavior to individual identity for anomaly detection.

▼ Watch Areas

Zero native model/dataset/ML-pipeline supply-chain scanning — a real gap versus AI-security specialists. AI-SPM doesn't yet inventory models, agents, or unmanaged API keys — sanctioned/shadow app scoring only. Agent Access Model and WriteGuard are architecture papers or closed/private beta, not GA. The dynamic-routing feature of AI Gateway currently requires the OpenAI-compatible endpoint rather than the REST API.

→ Full AI Gateway analysis — cloudflare.html

Cato Networks — Native Governance and Scanning, No Gateway Function

AISEC ON NEURAL EDGE GPUs · NO LLM ROUTING

Cato moved fast into this pillar via the Q3 2025 Aim Security acquisition and the March 2026 Cato AI Security (AISEC) launch, running inline on Neural Edge GPUs deployed across its private backbone — prompt-injection and jailbreak blocking happens at wire speed with no hairpin to a third-party inspection environment. AI-SPM, agent/MCP discovery, and model-supply-chain scanning are all genuinely native rather than bolted-on, sharing the same policy engine as the rest of the SASE platform. The clear gap: no Cato source describes a multi-provider LLM API gateway with routing, rate limiting, or cost control — everything Cato does in this pillar is traffic inspection and governance, not an API intermediation layer for the enterprise's own LLM calls. As with Cato's broader AI Security launch, every capability here is under six months old with maturity resting on a small, vendor-selected customer set.

▲ Strengths

Inline prompt-injection/jailbreak detection at wire speed on backbone-edge GPUs, no hairpin to third-party inspection. Continuous, agentless discovery of sanctioned and unsanctioned AI apps, models, and agents unified with existing SASE identity/policy. Native MCP server discovery and agent tool-call audit built into the core platform. AI-SPM explicitly claims native model scanning for misconfigurations, vulnerabilities, and license/usage violations.

▼ Watch Areas

No multi-provider LLM API gateway with routing, rate limiting, or cost control — the pillar's weakest score in the Codex's review. Model/dataset supply-chain scanning claims lack confirmed dataset-level or malicious-code scanning depth. Agentic governance reads as runtime policy enforcement plus logging rather than a formal agent-identity/least-privilege IAM system. Entire AI Security line is very new (GA March 17, 2026) with a small early customer set.

→ Full AI Gateway analysis — cato-networks.html

Zscaler — Real Model Scanning, Flagship Agentic Story Still Pre-GA

AI-SPM SHIPPED · AGENT REGISTRY EARLY ACCESS

Zscaler's AI-SPM (January 2026) does genuine deep-file scanning of pickle, PyTorch, Keras, and ONNX model formats for backdoors and supply-chain risk — including named exploit classes like AWS-credential theft via IMDS exploitation — which is unusual depth for an SSE-first vendor and one of the stronger model-scanning stories in the pillar. MCP Gateway shipped in the same January 2026 launch with roughly eight months of runway by this review. The more agent-centric announcements from Zenith Live (June 2026) — AI Broker, Agent Registry, AI Access Graph — are the ones to hold loosely: Zscaler's own September 2026 investor-conference remarks confirm this capability set is still "early access, not generally available," with revenue impact not expected until the back half of fiscal 2027. AI Guard, Zscaler's inline prompt-injection layer, plugs into third-party gateways (LiteLLM, Portkey) as a guardrails/content-filter add-on rather than providing native multi-provider routing or cost control itself.

▲ Strengths

Native AI-SPM model/dataset scanning (pickle/PyTorch/Keras/ONNX) for backdoors and supply-chain risk. MCP Gateway shipped since January 2026, ahead of most peers on agentic-protocol governance timing. AI Guard's inline prompt-injection/jailbreak detectors span most major clouds and dev frameworks. Continuous AI/shadow-AI asset inventory with risk and misconfiguration scoring. Symmetry Systems acquisition provides real identity-to-data access-graph technology underpinning future agent governance.

▼ Watch Areas

No native multi-provider LLM API gateway — AI Guard is a guardrails layer bolted onto third-party gateways, not a gateway itself. Agent Registry / AI Broker / AI Access Graph confirmed still "early access, not GA" as of the September 2026 investor call — do not treat as shipped agentic governance yet. Zscaler's own "industry's first complete Zero Trust platform for agentic AI" claim has been publicly challenged by analysts as premature. Action-level agent audit trail and model provenance/license-risk scanning not independently confirmed.

→ Full AI Gateway analysis — zscaler.html

Fortinet — Stronger Than the Rest of the Codex Currently Credits

FORTIAIGATE + NATIVE MCP OBSERVABILITY

Fortinet is the notable surprise of this review. FortiAIGate (GA March 4, 2026) is a real multi-provider LLM gateway — it proxies OpenAI, Anthropic, and AWS Bedrock traffic with cost/latency-aware routing, token-based cost governance, and OWASP-LLM-Top-10-mapped observability — and FortiOS 8.0's native MCP observability (server discovery, Read/Write/Execute function-level policy, tool-call audit tied to human identity) is arguably the pillar's standout Fortinet capability. This materially updates, and partially contradicts, the existing Codex framing of Fortinet as "significantly behind" the market leaders on agentic AI — that line was written before FortiAIGate and FortiOS 8.0 shipped and should be revisited in the SSE pillar's Fortinet notes as a follow-up. The gaps that remain are real: AI-SPM breadth beyond basic shadow-AI discovery runs through the Astrix Security alliance rather than natively, model/dataset scanning covers only agent-skill files (not model weights or datasets), and the Virtue AI acquisition that would close both gaps closed in August 2026 but isn't yet integrated into shipping products.

▲ Strengths

FortiAIGate: native multi-provider LLM gateway (OpenAI, Anthropic, AWS Bedrock) with cost/latency-aware routing and OWASP-mapped observability, GA March 2026. Inline prompt-injection scanner with automated blocking, extended to inspect MCP tool calls. FortiOS 8.0 MCP observability: server discovery, read/write function-level policy, tool-call audit tied to human identity. FortiCNAPP Skills Scanning: native, deterministic, pre-deployment scanning of AI-agent skill packages, CI/CD-integrated.

▼ Watch Areas

AI-SPM breadth (agent inventory, unmanaged API-key discovery) currently runs through the Astrix Security alliance, not natively. Model/dataset/ML-pipeline scanning unconfirmed beyond agent-skill files — no evidence of native model-weight or dataset scanning. Virtue AI acquisition (closed Aug 2026) not yet integrated into shipping products. Entire line is under seven months old with no independent efficacy validation, consistent with Fortinet's broader below-average customer-experience rating pattern.

→ Full AI Gateway analysis — fortinet.html

Emerging vendors not yet scored. This pillar launched scoped to the Big Six only (2026-09-23). Aryaka, CrowdStrike, Island, Nile, Versa, and VeloCloud are not yet evaluated against this rubric — Phase 2, not started.

Vendor Scoring — AI Gateway Pillar


Scale: 1=Poor/Missing · 3=Adequate · 5=Best-in-Class. Weight multipliers: Critical ×3 · High ×2 · Medium ×1.

Loading scores…

Persona Fit — AI Gateway Pillar


PersonaProfilePrimary AI Gateway NeedBest FitRationale
Lean IT
SMB–Mid-market
Small security team building lightly with AI, wants one platform to cover it rather than a separate AI-security stackNative, low-configuration coverage across gateway + discovery + prompt-injectionCLOUDFLARE CATOCloudflare's AI Gateway, CASB-based shadow-AI discovery, and WAF-inline prompt-injection defense all live in the one platform a lean team already runs, with no separate specialist tool to manage. Cato is the alt where the team is already standardized on Cato's single-pass engine and values native agent/MCP discovery over gateway routing specifically.
Global Security Ops
Large Enterprise
Dedicated SOC, threat-prevention depth is the governing constraint, wants AI governance tied into existing XDR/SOC toolingModel/skill scanning, inference-time threat defense, SOC-integrated audit trailsPALO ALTO NETSKOPEPalo Alto is the only vendor covering every sub-criterion natively, with Cortex XDR integration extending AI-security telemetry into the broader SOC. Netskope is the alt where MCP governance and prompt-injection defense specifically are the priority and model-scanning isn't a requirement.
Data-First / Regulated
Finance · Healthcare · Legal
AI governance needs to be audit-ready — every agent action, every MCP call, every shadow-AI instance needs a defensible trailShadow AI discovery depth, prompt-injection defense, MCP tool-call auditNETSKOPE PALO ALTONetskope's Agentic Broker and AI Guardrails give the most defensible discovery-and-audit story in the pillar — full MCP tool-call logs and 29-language, OWASP-mapped prompt-injection blocking. Palo Alto is the alt where model/skill supply-chain risk (not just usage governance) is also a compliance requirement.
Platform / Network Architect
Existing SD-WAN / hardware estate
Wants AI governance folded into the same policy plane as networking and SASE, not a bolted-on point productNative AI-SPM/agent/MCP governance inside the existing platform, ties into estate already deployedCATO FORTINETCato's AI Security runs inline on the same single-pass engine and policy plane as everything else on the platform — no separate console. Fortinet is the alt for organizations with an existing FortiGate/FortiOS estate, where FortiAIGate and FortiOS 8.0's MCP observability extend the estate they already manage rather than adding a new vendor relationship.

AI Gateway in 2026: Four Market Signals

1. Five of the Big Six shipped a named AI-security product line in the first three quarters of 2026 alone. Palo Alto (Prisma AIRS expansion), Netskope (AI Security → Skylight), Cloudflare (AI Security Suite), Zscaler (AI Security Suite), and Cato (AI Security/AISEC) all launched or materially expanded dedicated AI-governance product lines between January and September 2026. Fortinet followed with FortiAIGate in March. This is the fastest simultaneous category build-out the Codex has tracked across any pillar.

2. Model and dataset supply-chain scanning is the pillar's clearest capability gap — and it's a real one, not just thin documentation. Netskope and Cloudflare both score 1/5 here with no evidence of any native or partnered capability; that ground currently belongs to AI-security specialists (Protect AI, HiddenLayer, JFrog, ReversingLabs), not SASE platforms. Watch for acquisition activity here through 2027 — it's the most obvious remaining gap for a Big Six vendor to close by acquisition, the way Palo Alto closed its gateway gap with Portkey.

3. "Agentic governance" claims need to be read against GA status, not announcement date. Zscaler's Agent Registry / AI Broker were announced at Zenith Live in June 2026 with confident framing ("industry's first complete Zero Trust platform for agentic AI") but Zscaler's own September 2026 investor remarks confirm the capability is still early access, with revenue impact not expected until H2 FY2027. Palo Alto's Agent Gateway carried a "limited preview" label as recently as its March 2026 announcement. Treat 2026 agentic-AI press releases as a leading indicator of roadmap direction, not a substitute for checking current GA status.

4. MCP governance moved from novelty to table stakes inside a single year. Every Big Six vendor now has a native MCP discovery-and-policy capability, most GA'd in the first half of 2026 (Netskope and Cloudflare lead on depth; Palo Alto's default-disabled human-in-the-loop approval gate is the strictest default policy found). A protocol that didn't exist as a mainstream enterprise concern before late 2024 is now a scored, comparable criterion across an entire vendor category — the fastest capability-maturity curve the Codex has observed.