Harness, provider of the AI Software Delivery Platform™, alongside API and AI connectivity developer Kong, announced a significant expansion of their strategic technology alliance. The collaboration addresses pressing security challenges surrounding modern AI deployments, including autonomous agents, large language model (LLM) infrastructure, and Model Context Protocol (MCP) workflows.
Recent findings from The State of AI-Native Application Security 2025 report highlight a sharp governance gap across enterprise IT. According to the study, 62% of organizations lack visibility into LLM usage across their internal environments. Furthermore, 74% of respondents anticipate that AI sprawl will swiftly surpass API sprawl in overall security risk making embedded, infrastructure-level defense mechanisms an immediate operational priority.
To resolve these vulnerabilities, the companies are extending their existing joint security capabilities from the Kong API Gateway to the Kong AI Gateway. By embedding Harness AI Security directly into the underlying connectivity layer, enterprise IT teams can discover, analyze, and govern every autonomous agent, LLM endpoint, and agent-to-agent (A2A) interaction traversing their networks.
Reinforcing a Proven API Defense Foundation
For years, global enterprises have relied on the unified Harness and Kong API Gateway architecture to protect mission-critical application programming interfaces (APIs).
The core platform provides:
- Deep Traffic Visibility: Behavioral analysis and traffic monitoring of all Kong-managed microservices.
- Proactive Threat Protection: Automated protection from critical threats, such as OWASP API Security Top 10, automated credential abuse, and logical flaws in business processes.
- Data Governance & Compliance: Automated monitoring of payload data for sensitive information and protection against PII data leaks.
- Smooth Integration: Easy deployment working together with existing Kong configurations.
By bringing this framework to the Kong AI Gateway, security leaders gain identical operational visibility across non-deterministic AI environments.
Also Read: SpaceXAI Announces the Launch of Grok 4.5: Redefining Coding, Agentic Tasks, and Knowledge Work
“Our partnership with Harness has given joint customers production-grade API security that works with the way they build, not against it,” said Ken Kim, Senior Vice President, Business Development at Kong Inc. “Extending to include Kong AI Gateway is a natural next step. The same enterprises are now moving AI into production through our gateway and need the same depth of visibility and control they’ve come to rely on for their APIs for all AI traffic types including LLM, MCP, and A2A. That’s exactly what this delivers and is crucial for organizations scaling in the agentic era.”
Securing the Non-Deterministic AI Attack Surface
Unlike standard software applications that follow predictable, deterministic logic paths, autonomous AI agents operate dynamically. The same agent can produce different outputs across sequential executions, creating specialized attack vectors that legacy AppSec tools cannot effectively parse or mitigate.
The expanded integration addresses these vulnerabilities through two main operational pillars:
-
Continuous AI Discovery
Harness automatically generates a real-time inventory of all active AI assets passing through the Kong AI Gateway. This includes cataloging underlying LLM models, connected tools, MCP servers, user prompts, and external system dependencies eliminating security blind spots without requiring manual developer documentation.
-
Advanced Real-Time AI Protection
The tool utilizes behavioral analytics to constantly monitor AI traffic for any threat that emerges. It automatically detects and stops any prompt injection attacks, jailbreaks, malicous code payload injection, and any accidental data leakage through LLM output. All information about any incident is immediately disclosed, including complete payload from prompt and output.
“Shadow AI has become the defining security blind spot for enterprises today. Traditional tools were built for static code and predictable systems, not for adaptive AI models, agent-to-agent communication, and MCP-connected workflows that evolve continuously,” said Rahul Sood, GM of Application Security at Harness. “This integration of Harness AI Security with Kong puts security intelligence directly into the connectivity layer where AI traffic flows. Joint customers now have the visibility and control they need to move fast without losing sight of what’s happening across their AI infrastructure.”


