top of page

Notification, blog

Agentic AI 시대 API Gateway의 변화

  • 7월 2일
  • 3분 분량

Agentic AI 시대, API Gateway는 어떻게 바뀌어야 하는가?


Agentic AI는 사용자의 단순 질문에 답하는 수준을 넘어, 목표를 이해하고 여러 도구와 시스템을 호출해 작업을 수행하는 방향으로 발전하고 있습니다. Gartner는 2028년까지 기업용 소프트웨어 애플리케이션의 33%가 Agentic AI를 포함할 것으로 전망했으며, 일상 업무 의사결정의 일부가 AI Agent를 통해 자율적으로 수행될 것으로 예측했습니다.


출처. ChatGPT 생성형 이미지
출처. ChatGPT 생성형 이미지

이 변화는 API Gateway의 역할도 바꾸고 있습니다. 기존 API Gateway는 주로 API 요청을 라우팅하고, 인증·권한·Rate Limit·트래픽 제어를 적용하는 역할을 했습니다. Kong Gateway 공식 문서는 Gateway가 업스트림 서비스 앞에서 요청과 응답을 동적으로 제어·분석·라우팅하고, 플러그인 기반으로 API 정책을 적용한다고 설명합니다.


그러나 Agentic AI 환경에서는 API Gateway가 단순 API 트래픽뿐 아니라 LLM, MCP, Agent-to-Agent 트래픽까지 다뤄야 합니다. Kong은 Agentic 시대에는 LLM, MCP, A2A 연결을 하나의 Gateway에서 관리해야 하며, 다중 Agent 트래픽에 대한 인증, 관측성, 감사 기능이 필요하다고 설명합니다. 또한 AI Agent가 API와 이벤트 데이터 자산에서 컨텍스트를 소비하는 방식까지 통제해야 한다고 제시합니다.


리티스는 이러한 변화에 맞춰 APIM과 AI Gateway를 함께 제안할 수 있습니다. Kong API Gateway는 기존 API 트래픽의 안정적인 제어 기반을 제공하고, Kong AI Gateway는 LLM·MCP·Agent 트래픽의 거버넌스를 담당합니다. litis API Creator는 내부 시스템을 API로 표준화하고, Akamai API Security는 API 위협 탐지, OWASP API Security Top 10 대응, Zero Trust 모델 적용, 비정상 트래픽 탐지를 지원합니다.


Agentic AI 시대의 API Gateway는 더 이상 단순한 Reverse Proxy가 아닙니다. API, AI 모델, MCP 서버, Agent, 내부 데이터 흐름을 함께 통제하는 Enterprise Connectivity Control Point가 되어야 합니다. 기업이 AI Agent를 실제 업무에 적용하려면 API Gateway는 AI Gateway와 결합되어 보안, 정책, 관측성, 비용 관리까지 포괄해야 합니다.


출처 및 참고자료



How API Gateway Must Evolve in the Age of Agentic AI


Agentic AI is moving beyond answering user questions. It understands goals, invokes tools and systems, and performs tasks across workflows. Gartner predicts that by 2028, 33% of enterprise software applications will include agentic AI, and part of daily work decisions will be made autonomously through AI agents.


This shift changes the role of API Gateway. Traditionally, API Gateway has routed API requests and applied authentication, authorization, rate limiting, and traffic control. Kong Gateway documentation describes Gateway as a layer that sits in front of upstream services and dynamically controls, analyzes, and routes requests and responses through a plugin-based policy model.


In an Agentic AI environment, however, API Gateway must handle not only API traffic but also LLM, MCP, and agent-to-agent traffic. Kong states that the agentic era requires governing LLM, MCP, and A2A connectivity through a single gateway. It also highlights the need for authentication, observability, auditability, and governance over how agents consume context from APIs and event data estates.


LITIS can address this shift by combining APIM and AI Gateway. Kong API Gateway provides a stable foundation for controlling traditional API traffic, while Kong AI Gateway governs LLM, MCP, and agent traffic. litis API Creator standardizes internal systems as APIs, and Akamai API Security supports API threat detection, OWASP API Security Top 10 response, Zero Trust enforcement, and abnormal traffic detection.


In the age of Agentic AI, API Gateway is no longer just a reverse proxy. It must become an Enterprise Connectivity Control Point that governs APIs, AI models, MCP servers, agents, and internal data flows. To deploy AI agents in real business operations, enterprises must combine API Gateway with AI Gateway to cover security, policy enforcement, observability, and cost governance.



References

 
 
bottom of page