The AI governance market just got its first M&A receipts.
In April 2026, Cisco announced its intent to acquire Galileo Technologies — an AI agent observability platform — with plans to fold it into Splunk Observability Cloud. Three weeks later, Palo Alto Networks announced its intent to acquire Portkey, positioning it as the AI gateway layer of Prisma AIRS.
Two named acquisitions in a month. Both from major security and observability players. Both pricing the AI governance category as worth a serious check.
Clearly, there’s not just interest, but significant momentum and investment in the category. What’s shipping in the box? Not yet what the name implies.
So why does this feel familiar to me in a way I want to write about? Let me tell you a story.
Marketing names are great. But.
Way back at the turn of the century, I was a senior sales systems engineer at Legato. An SE counterpart and I had just talked our way into the budget for a corporate HQ demo lab — a skunkworks of two.
The plan: take the backup and high-availability products in our portfolio and stitch them into a single integrated demo. Our own scripting hid the seams. Word got around inside the company.
An ambitious marketing exec spent a couple of days quizzing us. He took notes off the whiteboard where we had everything mapped out. He came back the next week and told us he was going to name what we’d built Information Lifecycle Management. It would become Legato’s new corporate marketing pitch.
I argued with him. What we’d built wasn’t a product. It was a field-engineering demo held together with consulting glue and a wish. He told me the name was the point, and the pitch was going to ship.
So it shipped. And then something happened I didn’t expect.
Legato began getting courted for acquisition. EMC’s leadership let us know the ILM positioning was a meaningful part of what made Legato compelling to buy. The category itself did become truly deliverable — but not for years, and not until a lot of people did a lot of integration work, customer by customer, to make the pitch true.
The exec wasn’t wrong about the name. He was just early — by years of work that other people did to close the gap between what the pitch claimed and what a buyer could actually get.
A category becomes deliverable when buyers can reliably get the value the name promises. ILM got there. Eventually.
That mix of misgiving and recognition I had back then? Knowing the pitch had outrun the product, watching it ship anyway. That’s what I feel looking at the AI governance market today.
Here’s why.
The trigger and the target
We learned in security to shift-left, to move controls as close to the source of risk as possible, because early interventions are cheaper and more reliable than late ones. Shift-left isn’t a slogan. It’s the reason vulnerability scanning moved into the IDE, why secrets detection moved into pre-commit hooks, why input validation moved into the client even though it also has to live on the server.
The AI governance products shipping in 2026 are not shift-left. They sit at the network edge — closer to the target than to the trigger. They watch traffic going to the model and traffic coming back. They are trying to declare hits and misses after the shot has been fired.
You are not buying AI governance. You are buying an API proxy with compliance branding.
I know the people selling these products are smart and the buyers purchasing them are astute. It’s better to put something together with what we have than wait for the perfect solution. But we need to be acutely aware of what we’re getting, what we’re not getting, and where the gap is. So let’s take a hard look at what AI governance provides today.
What an AI gateway actually is
Strip the marketing from the AI gateway offerings. You have a reverse proxy for LLM API traffic. A server that sits between your applications and an upstream API. It inspects traffic, enforces policy, and logs what passes through. The AI-specific versions add a few token-aware features:
multi-provider routing
rate limiting tuned to token consumption
centralized credential management for model providers
prompt and response inspection
audit logging
All valuable features. For a gateway.
Open-source versions (LiteLLM, Helicone, Kong AI Gateway) do most of it competently. The enterprise versions add support, integration, and a six-figure invoice.
What gateways do not do is govern the model.
A gateway sees the prompt going in and the text coming out. It cannot inspect attention patterns, activations, or the intermediate reasoning state that produced the response. It cannot see the agent’s internal goal representation. It cannot see the planning steps before a tool call is emitted. By the time a tool call reaches the gateway, the reasoning that produced it has already completed.
This matters because the things we most want governance to catch — deceptive reasoning, manipulated goals, capability misuse — happen inside the model’s reasoning, not in the text it produces. A gateway watching outputs is a smoke detector watching the parking lot. It will see the fire eventually. It will not see the spark.
Gateways do not govern the model. They govern the traffic around it.
The gateway sees the result of a decision, not the decision or the action itself.
This isn’t a criticism of the engineering. It’s the architecture. Trying to govern from the outside looking in is the wrong place to enforce policy on a system whose decisions happen inside.
The gateway is being a gateway. And that’s a bad place to try to enforce compliance.
The numbers vendors do not lead with
The argument above is architectural. Here’s the data.
The arXiv paper 2504.11168, published by researchers at Mindgard and Lancaster University, tested six prominent prompt-injection and jailbreak guardrails against known evasion techniques. They ran two categories of attack: character injection (emoji smuggling, zero-width characters, bidirectional text) and adversarial ML evasion (BERT-Attack, TextFooler).
Three things in this table are worth pausing on.
First: no single product is good at both attack categories. Protect AI v2 is the standout against character injection at 20%, more than three times better than the next product. The same Protect AI v2 against adversarial ML evasion is bypassed 67% of the time. Meta Prompt Guard is the inverse — middling against character injection, but the best in the field at 2.76% against adversarial ML.
Second: emoji smuggling defeated every guardrail in the study with 100% success. Across all five products. A single technique, public and well-documented, with no current defense in the commercial field.
Third: and this is the procurement problem — there is no single product you can buy that does what the category name implies. You are picking which attack vector you want to be best-defended against, at the cost of being meaningfully exposed on the other.
So:
The best product against one attack class can be the worst against another.
The field has no product that’s good at both.
There’s at least one technique that defeats all of them.
And the news doesn’t get better.
When the judge is the model
On October 6, 2025, OpenAI announced its Guardrails framework as part of AgentKit. Four days later, HiddenLayer published a bypass.
The bypass worked on a simple principle: if you can manipulate a model, you can manipulate a model acting as judge. OpenAI’s framework uses LLM-based judges to evaluate inputs before they reach the agent. HiddenLayer’s bypass manipulated those judges into lowering their confidence, so prompts that should have been flagged were waved through.
This is the structural issue with the gateway pattern at its sharpest. When your guardrail is itself a language model, it shares an attack surface with the model it’s judging. The defender and the attacker are running on the same kind of substrate. Anything that bends one bends the other.
Launch to public bypass: one week.
The benchmarks that don’t exist
Something is striking about these results: there is no widely recognized independent benchmark for the major commercial AI gateway products. No NSS Labs equivalent. No MITRE ATT&CK-style evaluation. No AV-Comparatives. The performance benchmarks that do exist measure throughput and latency, not security efficacy.
Buyers are spending a lot of money on products with familiar names and deployment models. But they aren’t getting solutions that closely match the problem in the original budget justification.
The numbers here tell the story. They help us set expectations the way the simple marketing story can’t.
It might be the best we can do right now. But we need to go into this knowing exactly what we’re getting.
What to do on Monday
If you’re a senior buyer making decisions today in 2026, here’s where I’d land.
Treat AI gateways as cost control and basic audit tooling. Not as the AI governance end game. Be precise about your goals and budget, and about what the products are, what they aren’t, and what the SOW should claim. You’re going to need to tailor the products and services mix to meet both goals and the budget until more targeted solutions are available.
Layer your defenses. We’ve all seen the gaps in available AI governance testing. Until rigorous, published, well-accepted testing exists, we have no choice but to take up the slack ourselves. This is the principle we all learned in data protection: always test your capability to recover. Gateway plus independent red teaming plus continuous evaluation against known prompt-injection corpora (Garak, ALERT, AdvBench) is the minimum.
Constrain blast radius. Focus on limiting what your agents can do, not just what they’re asked to do. Capability-based controls survive a manipulated reasoning chain better than perimeter filters do. A model that cannot reach a destructive tool cannot be tricked into using it, regardless of what the gateway saw or missed.
Watch the research, not the marketing. Productized AI-native governance that happens before the agent acts is being worked on. Research projects at Anthropic and DeepMind. Academic labs. Early frameworks like MI9 were developed by researchers in Barclays’ Model Risk Management group, and I’m aware of some early-stage startups that are leveraging frameworks like this. The good news is that the gap between research and product is closing in months rather than years.
We have to test each deployment against our own requirements. And expect services to play a more important role than products until the category matures. Build for the world we’re in while keeping an eye on the one that’s coming.
Why I’m starting this
The exec at Legato who named ILM wasn’t wrong to do it. He was naming a category ahead of where the engineering was. That’s a real thing marketing executives do, and sometimes it works out. But the buyer who pays for what’s in the box on the assumption that it matches the name has to know which gap they’re paying to bridge.
I think we’re in one of those moments right now. I’d rather write about the pattern while it’s recognizable and actionable than after it’s resolved.
The point of writing this kind of thing in public is to provoke careful thought and honest discussion. Including, and maybe especially, the kind that tells me where I’ve got it wrong. If you’ve worked through any of this from another angle and reached different conclusions, I’d very much like to hear from you. That’s the conversation I’m hoping this newsletter starts.
I’m also looking at options that might shorten the wait. I have work to do before I can say more. But I don’t think the gap is unbridgeable.
If that’s the kind of thing you’d read, you can subscribe below.
— Brian Gardner
P.S. I use em-dashes shamelessly. And have been doing it since well before AI came around. Please do not discriminate against the lowly em-dash. Their use indicates my judgment — or lack thereof — and predates the current AI moment by about thirty years.


