A10 AI Gateway
by A10 Networks
Self-hosted LLM control plane for complexity-aware model routing, per-team token budgets and real-time AI cost governance
A10 AI Gateway is an enterprise control plane that sits between your applications, copilots and autonomous agents and every large language model they call. It routes each request to the cheapest model that can handle it, enforces identity-based access policy and per-team token budgets, and reports spend per request — all running inside your own on-premises, private-cloud or air-gapped environment rather than a vendor SaaS.
A10 AI Gateway is a self-hosted control plane that A10 Networks (NYSE: ATEN) took to general availability on 13 August 2026, introduced at Black Hat USA in Las Vegas. It sits between an organisation's applications, copilots and autonomous agents and every large language model those workloads call, whether hosted by OpenAI, Anthropic, Azure OpenAI or run privately. Its distinguishing behaviour is complexity-aware routing: the gateway classifies each incoming prompt as simple or complex and forwards it to the cheapest model that can serve it, escalating only reasoning-intensive work to more capable models, with priority-chain cascading that shifts traffic to an alternative model once a budget is consumed. Around that sit the governance controls enterprises have lacked since shadow AI spending began — virtual API keys scoped per user or team with their own budgets and rate limits, identity-based access and routing policies synchronised with existing directory systems so engineering and finance can be given different model catalogues, real-time per-request cost tracking in dollars instead of an end-of-month provider invoice, hard and soft token budgets per model and per team, business-layer RPM and TPM rate limiting enforced per key or team, and a provider credential vault using OpenBao-backed encryption so raw provider keys never reach developers. Guardrails today are lightweight pattern-based regex filtering of both requests and responses, with A10 positioning stronger controls as policies mature. The product ships as software or integrated hardware and runs entirely inside the customer environment — on-premises, private cloud or air-gapped — deployed via Helm on Kubernetes with single-tenant isolation, which is the whole point for regulated and sovereign-AI buyers. It complements A10's TrojAI acquisition (AI red teaming and runtime model protection) and its ThreatX web application and API protection line, giving A10 coverage from pre-deployment model testing through runtime enforcement.
The platform or FinOps lead inside a regulated enterprise that has multiple teams calling multiple LLM providers, cannot send that traffic through a vendor-hosted SaaS gateway, and has no per-team answer to 'what did we spend on AI last week and who spent it'.
One enforcement point where every LLM and agent request is authenticated, routed to the cheapest sufficient model, charged to a named team budget and logged — inside your own network boundary.
At a Glance
- Category
- Infrastructure & Cloud
- Pricing
- Contact for pricing
- Target Market
- CIOs, CTOs, Platform Engineering Leads, FinOps Teams, Enterprise Developers, Security Architects
- Deployment
- Self-hosted, Hybrid
- Founded
- 2004
- Headquarters
- San Jose, United States
- Team Size
- 500+
- Customers
- A10 Networks reports roughly 7,000 customers globally across its whole portfolio as of FY2025; no customer count has been published for the AI Gateway specifically
Key Features
- ✓Complexity-aware model routing
Classifies each prompt as simple or complex and routes it to the cheapest model capable of serving it, escalating only reasoning-heavy work.
- ✓Priority-chain cascading
Automatically shifts requests to an alternative model when a team or model budget is consumed, so workloads degrade gracefully instead of failing.
- ✓Virtual API keys
Scoped keys per user or team, each with its own token budget and rate limit, so access can be revoked without touching provider credentials.
- ✓Provider credential vault
Stores OpenAI, Anthropic, Azure and other provider credentials with OpenBao-backed encryption so raw keys never reach application developers.
- ✓Real-time per-request cost tracking
Reports dollar spend as requests happen rather than at month end, with hard limits and soft-limit alerts per model and per team.
- ✓Identity-based access policy
Applies access and routing rules by user and group profile, synchronised with existing local directory systems such as Active Directory.
- ✓Business-layer rate limiting
Enforces requests-per-minute and tokens-per-minute caps per key or team to protect shared inference infrastructure from a single noisy workload.
- ✓In-environment deployment
Runs as software or integrated hardware on-premises, in private cloud or air-gapped, via Helm with single-tenant isolation per customer.
Capabilities
Use Cases
- •AI cost attribution and chargeback
Finance gets per-team, per-model dollar spend in real time and can charge AI consumption back to the business unit that generated it.
- •Shadow AI consolidation
Route every application and agent through one governed egress point so security can see which teams call which models with what data.
- •Inference cost reduction
Send routine classification and summarisation prompts to cost-efficient models while reserving frontier models for genuinely complex reasoning tasks.
- •Sovereign and air-gapped AI
Regulated and public-sector operators keep all model traffic, policy and telemetry inside their own boundary with no vendor SaaS dependency.
- •Runaway agent containment
Token budgets and RPM/TPM limits per virtual key stop a looping autonomous agent from burning an entire quarterly AI budget overnight.
Ideal For
Best For
- ✓Capping and attributing LLM spend per team, per model and per virtual API key before the provider invoice arrives
- ✓Consolidating shadow AI usage across business units behind a single governed egress point
- ✓Cutting inference cost by routing simple prompts to cheap models and reserving frontier models for reasoning-heavy work
- ✓Sovereign, air-gapped or on-premises AI deployments where traffic must never leave the customer's environment
- ✓Giving engineering, finance and legal different model catalogues driven by existing Active Directory or LDAP group membership
- ✓Preventing raw OpenAI or Anthropic provider keys from being distributed to application teams
Not Ideal For
- ✗Teams wanting a managed, zero-ops SaaS gateway — this deploys via Helm into your own Kubernetes and you run and upgrade it yourself
- ✗Buyers who need deep semantic guardrails today: filtering is currently lightweight regex pattern matching on requests and responses, not a full prompt-injection or PII detection engine
- ✗Small teams on a single model provider, where a provider-native spend dashboard or an open-source proxy such as LiteLLM covers the need at no licence cost
- ✗Organisations that require published list pricing or a self-serve trial before evaluating — this is a quote-only enterprise sale
Deployment
Market & Ratings
A10 Networks reports roughly 7,000 customers globally across its whole portfolio as of FY2025; no customer count has been published for the AI Gateway specifically
Market Analysis
Pros
- ✓Cost governance is unusually concrete: per-request dollar tracking, hard and soft token budgets, and rate limits enforced per virtual key or team
- ✓Fully in-environment deployment (on-prem, private cloud, air-gapped) makes it viable where a hosted gateway is disqualified by policy
- ✓Backed by a profitable NYSE-listed vendor with roughly 7,000 customers and $290.6M FY2025 revenue, not a seed-stage startup
- ✓Complexity-aware routing plus priority-chain cascading is a genuine cost lever rather than a passthrough proxy
- ✓Fits an existing enterprise procurement relationship for A10 ADC, ThreatX or TrojAI customers
Cons
- ✗Guardrails are, by A10's own description, lightweight pattern-based regex filtering — thinner than the semantic prompt-injection and data-loss controls competing AI gateways ship
- ✗No independent user reviews exist anywhere yet: nothing on G2, Capterra or TrustRadius for this product, and Hacker News has no discussion of A10 Networks since 2019
- ✗No published pricing, no free tier and no self-serve trial, so evaluation requires a sales cycle
- ✗Self-hosted only — you own the Kubernetes deployment, upgrades and availability, which is a real operational cost versus a managed SaaS gateway
- ✗A10 is a networking and application-delivery vendor entering a crowded category against API-gateway and AI-native incumbents; the AI Gateway's ecosystem of provider integrations is not publicly enumerated
Pricing
Enterprise (software or integrated hardware)
Contact for pricing
- ✓Complexity-aware routing
- ✓Virtual API keys with per-team budgets
- ✓Real-time per-request cost tracking
- ✓Identity-based access policy
- ✓Provider credential vault
- ✓On-premises, private-cloud or air-gapped deployment
A10 publishes no list price for the AI Gateway anywhere on its product page, in the GA press release or in trade coverage — it is a quote-only enterprise sale consistent with the rest of A10's portfolio, sold as either software or integrated hardware. There is no free tier and no advertised self-serve trial, so budget for a sales-led evaluation. Because the gateway runs inside your own environment, the licence is not the whole cost: you also carry the Kubernetes footprint and operational burden of running it, though A10 states no GPU is required for the base deployment.
Security & Compliance
Connect
Sources
This page was written from 6 sources, 3 on domains other than a10networks.com.
- 1.a10networks.com — a10 ai gatewayvendor
- 2.a10networks.com — ai gateway intelligent control planevendor
- 3.a10networks.com — companyvendor
- 4.helpnetsecurity.com — a10 networks introduces ai gateway to secure and manage ente
- 5.stocktitan.net — a10 networks launches a10 ai gateway an intelligent control
- 6.en.wikipedia.org — A10 Networks
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
ScienceLogic Skylar AI
Agentic AIOps intelligence layer that turns alerts, telemetry and tickets into prioritised advisories and next best actions
Etched Sohu
Transformer-only inference ASIC shipped as rack-scale frontier inference clusters
Nebius AI Cloud
European full-stack AI cloud with published GPU pricing and enterprise compliance
Emerald Conductor
Makes AI data centres power-flexible so utilities will connect them faster