October 2026 Summaries
5 posts from Kong
Filter
Month:
Year:
Post Summaries
Back to Blog
Kong’s API + AI Summit 2026 brought more than 1,000 engineers, architects, and business leaders to Los Angeles for two days focused on deploying, governing, and scaling AI systems and agentic architectures. The company positioned its Kong Konnect platform as an AI connectivity control plane for managing APIs, models, agents, MCP tools, security, cost, discovery, and observability, while CTO Marco Palladino introduced Volcano, an AI application stack featuring branchable Postgres databases, durable functions, hosting, authentication, storage, and distributed locks. Product announcements included AI Cost Management, general availability of Context Management, Token Vault for agent credentials, an Agent and MCP Registry paired with Kong Catalog, Advanced AI Observability, and a Webhook Engine for event-driven agent workflows. Kong also highlighted its seventh consecutive placement as a Leader in Gartner’s Magic Quadrant for API Management, honored ecosystem partners including AWS and several global services firms, and featured its new mascot, Karl, throughout the event. Additional activities included customer and industry presentations, networking events, the Kong Innovator Awards, and a Build Sprint won by Pavan Aripakula’s Vard project, with selected session recordings planned for release in the following weeks.
Oct 08, 2026
1,972 words in the original blog post.
AI coding tools are projected to exceed $13 billion in spending in 2026 as autonomous agents increasingly plan, write, test, and deploy code while calling language models, MCP-connected tools, and other agents. The expanded connectivity creates governance challenges beyond code quality, including insecure generated code, prompt injection, excessive tool permissions, data leakage, unmanaged non-human identities, and uncontrolled token costs; cited research reports limited visibility into developer AI usage and finds that only 55% of tested AI-generated code was secure. Drawing on OWASP’s agentic-application risks and Gartner’s AI TRiSM framework, the discussion argues that policies alone are insufficient and recommends continuous infrastructure-level controls: inventorying agents and their connections, assigning least-privilege identities, applying data and prompt protections, restricting MCP tool access, setting token budgets, and centrally logging activity. It positions AI gateways as a way to enforce these controls across LLM, MCP, and agent-to-agent traffic, while emphasizing that gateways complement rather than replace code scanning, human review, identity management, and other security tools.
Oct 08, 2026
2,481 words in the original blog post.
Kong has introduced Bot Detector in beta for Dedicated Cloud Gateways version 3.10 and later, a Kong Konnect-managed capability intended to identify, monitor, allow, or block automated API traffic before it reaches upstream services. The tool combines Kong-maintained rules for signals such as suspicious user agents, abnormal request shapes, vulnerability probes, and injection attempts with customizable rules that take precedence and can match IPs, CIDRs, JA4 fingerprints, user agents, paths, or advanced Kong Expression Language conditions. It begins in monitoring mode to record potential detections without affecting traffic, allowing users to review results, create passthrough rules for false positives, and later enable blocking, which returns a 403 response and excludes blocked requests from gateway usage billing. Kong positions the feature as complementary to WAFs, IP restrictions, CDNs, and edge bot-management products because it evaluates requests as they arrive at the API gateway, while trusted crawlers and monitoring services are protected through an allowlist. Future plans include network-level allow and block lists and a behavioral detection model trained on Cloud Gateway traffic.
Oct 07, 2026
1,964 words in the original blog post.
Agentic AI governance concerns the policies, technical controls, and accountability structures used to manage autonomous AI agents that can plan, access systems, and execute actions without human approval at every step. Unlike traditional AI governance, which focuses largely on the quality, fairness, and explainability of generated outputs, agentic governance emphasizes enforcing limits at runtime to prevent unauthorized transactions, data exposure, destructive operations, privilege escalation, and other execution-related harms. Effective programs assign each agent a unique identity, human owner, risk tier, narrowly scoped permissions, and comprehensive audit trail, while using centralized registries and execution control layers to monitor and block unsafe tool calls, API requests, MCP interactions, and agent-to-agent communications. Governance should be proportionate to risk, with stronger safeguards and human approval requirements for high-impact activities such as financial transfers or sensitive-data access. Organizations remain primarily accountable for agents they deploy, despite the involvement of model providers or platforms, and can draw on frameworks including the NIST AI Risk Management Framework, ISO/IEC 42001, the EU AI Act, and OWASP guidance.
Oct 06, 2026
2,902 words in the original blog post.
Kong Gateway Enterprise 3.12 will reach end of life in October 2026, after which it will no longer receive full support from Kong. It will then enter a 12-month sunset support period ending in October 2027, during which support will focus on helping customers upgrade to a current release. Organizations using version 3.12 are encouraged to upgrade promptly to retain ongoing support, reduce vulnerabilities, and access current platform capabilities, while Kong’s version support policy provides further details on support timelines.
Oct 06, 2026
146 words in the original blog post.