ACKUITY VS AI GATEWAYS

Your AI gateway sees 3 kinds of agent action. Agents use 11.

AI gateways (MCP, LLM and API gateways) put one policy point in front of the traffic routed through them, and they do that job well. Ackuity, the Agent Execution Control Switch, sits beside the agent and checks every action with its full context, including the actions that never reach a gateway. The two work together: the gateway keeps its job, and Ackuity feeds it the context it lacks.

AI gateway and Ackuity, side by side
AI gatewayAckuity
Where it sitsAt a network chokepoint between agents and servicesBeside each agent, in its execution path
What it seesTraffic routed through it: LLM, MCP and API callsAll 11 kinds of agent action, including CLI, SQL, IMDS, memory and A2A
Context per decisionThe request, its caller and its destination29 signals across 6 dimensions, including user, intent and history
Multi-step patternsUsually judges each request on its ownCorrelates actions across steps in real time
Best atAuth, rate limits, central policy and loggingDeciding whether this action, right now, should run
ResponsesAllow, deny or throttle the requestAllow, Constrain, Human in the loop, Block, Terminate
How they relateKeeps its job at the chokepointFeeds the gateway, IAM and SIEM the context they lack

WHAT GATEWAYS DO WELL

What does an AI gateway actually do?

An AI gateway is a proxy between agents and the services they call, so every request routed through it passes one chokepoint. An LLM gateway fronts model providers. An MCP gateway fronts tool servers. An API gateway fronts internal and external APIs.

One agent's actions fan out into 11 kinds: LLM calls, MCP tool calls, API calls, CLI commands, HTTP probes, SQL queries, IMDS metadata calls, Credential searches, Memory writes, RAG retrieval, A2A hand-offs. Ackuity sits beside the agent, in its execution path, and sees all 11 before they run. Only 3 kinds (LLM calls, MCP tool calls and API calls) cross an AI gateway, which keeps its job of auth, quotas, central policy and logging. The other 8 go straight to their targets: CLI commands to host shell, HTTP probes to web endpoints, SQL queries to databases, IMDS metadata calls to cloud metadata, Credential searches to secrets and files, Memory writes to agent memory, RAG retrieval to vector stores, A2A hand-offs to other agents. Ackuity passes context back to the AI gateway, IAM and SIEM, shown as dashed arrows labelled context.AGENTACKUITY11 KINDS OF ACTIONAI GATEWAYTARGETSAgentONE AGENTAckuitysees11 of 11before they runLLM callsMCP tool callsAPI callsCLI commandsHTTP probesSQL queriesIMDS metadata callsCredential searchesMemory writesRAG retrievalA2A hand-offsLLM·MCP·APIAI gatewaykeeps its job8 GO DIRECTModel providersMCP serversAPIsHost shellWeb endpointsDatabasesCloud metadataSecrets and filesAgent memoryVector storesOther agentsCONTEXTIAMSIEMCONTEXT
An AI agent acts through 11 kinds of action, and only 3 of them (LLM, MCP and API calls) cross an AI gateway. Ackuity sits beside the agent, sees all 11 before they run, and passes context back to the gateway, IAM and SIEM, which keep their jobs.

A chokepoint is a good place for rules that apply to every request the same way:

  • Authentication and authorization, so only known clients reach a service
  • Rate limits and quotas, so one runaway agent can't burn through a budget
  • Central policy, written once and applied to every call that passes
  • Logging, so you keep one record of who called what

Picture the security desk in an office lobby. It checks badges, counts visitors and keeps the sign-in sheet. Any team running agents at scale has good reasons to want one.

THE BLIND SPOTS

Why can't a gateway tell a safe action from a rogue one?

A gateway sees the call and very little of the context around it. It knows an agent invoked a tool named send_email or sent a request to a storage API. It usually can't tell which user asked for that, what goal the agent was chasing, what it planned three steps earlier, or whether this request fits anything the agent has done before.

Gateways also tend to judge each request on its own. A rogue agent that reads a credentials file in step 2, encodes it in step 5 and posts it in step 9 makes 3 calls that each look fine in isolation. Catching that pattern takes correlation across steps, and per-request rules at a proxy don't connect step 9 back to step 2.

The bigger gap is traffic that never arrives. Agents act through 11 kinds of action, and only 3 can pass a gateway: LLM calls, MCP tool calls and API calls. The other 8 never meet one: CLI commands, HTTP probes, SQL queries, IMDS metadata calls, credential searches, memory writes, RAG retrieval and A2A hand-offs. The lobby desk can't check a visitor who came in through the loading dock.

That gap has shown up in a real incident. Hugging Face counted about 17,600 actions by rogue agents. They ran through shell commands, raw HTTP and cloud metadata calls, paths an LLM, MCP or API gateway never sees. Read the Hugging Face incident timeline.

WORKING TOGETHER

How does Ackuity work alongside an AI gateway?

Ackuity sits beside each agent, in its execution path, and checks every action before it runs. We call that spot the Goldilocks zone: not inside the agent, not at the gateway. It is close enough to see intent, plan and history, and it stays outside the agent's control.

For each action, Ackuity assembles the Agent Security Context Graph: 29 signals across 6 dimensions, covering the user, the agent, its intent and goal, the target system and data, tools and supply chain, and history. Neurosymbolic verification weighs the action against 60+ threat models in 14 categories and reaches a decision in 40 to 100 ms. The response ladder then allows the action, constrains it, sends it to a person for approval, blocks it or, in catastrophic cases, terminates the container.

The gateway keeps its job. Auth, quotas and central policy stay at the chokepoint. Ackuity holds the context the gateway can't, and it shares that context with your gateway, IAM and SIEM tools so they can act on who, what and why.

Nothing about the gateway has to change. The open source sidecar runs in the agent's pod with no agent code changes. API injection covers platforms such as Copilot Studio, and event pull from OpenTelemetry, Langfuse or LangSmith gives an observe-only start. Your data stays in your own cloud account. See how Ackuity deploys.

QUESTIONS PEOPLE ASK

Frequently asked questions.

Do I still need an AI gateway if I use Ackuity?

Yes, if you rely on one for auth, rate limits or central policy. Ackuity doesn't take over those jobs. It sits beside the agent and adds a context-aware decision on each action, including the 8 kinds of action that never pass a gateway.

What is the difference between an MCP gateway and Ackuity?

An MCP gateway controls traffic between agents and MCP servers, while Ackuity decides whether each agent action should run, whatever path it takes. The MCP gateway sees the tool call. Ackuity sees the tool call plus the user behind it, the agent's goal, its plan and its history, and it also covers shell commands, SQL queries and other actions that never reach an MCP server.

Which agent actions never pass through an AI gateway?

Of the 11 kinds of agent action, 8 never meet a gateway: CLI commands, HTTP probes, SQL queries, IMDS metadata calls, credential searches, memory writes, RAG retrieval and A2A hand-offs. Only LLM calls, MCP tool calls and API calls can be routed through one.

Can Ackuity share context with my gateway, IAM or SIEM?

Yes, feeding those systems is part of the design. Ackuity routes alerts to the SOC and shares the context it builds for each action, so gateway, identity and SIEM tools can work from who, what and why.

Does Ackuity slow agents down like an extra gateway hop?

Ackuity reaches a decision in 40 to 100 ms, and that figure is decision time, not end-to-end latency. The sidecar runs in the agent's own pod, and you choose fail-open or fail-closed per policy, so a sidecar failure affects one pod rather than every agent.

NEXT STEP

Agents are going to act. Decide which actions run.

Show us the actions you need to control, and we’ll show you where Ackuity fits.

Request access