Most teams bring in an AI gateway to get one place to watch and control agent traffic. That's the right instinct. The trouble starts when people assume the gateway sees everything.
Where teams get it wrong
A gateway only controls the traffic that goes through it. If an app holds its own API key for a model provider, it can call that provider directly and skip the gateway. People find side doors slowly. Agents find them right away, and use them at volume.
The second mistake is the gateway's own login. Many gateways make every downstream call with one shared credential. The tool on the other end sees the gateway, not the agent. That's the confused deputy problem, and it hides which agent did what.
What a working gateway needs
It's the only place to get a model credential. Keys come from the gateway, not from a shared vault.
It hands out short-lived tokens for each call, so a leaked token stops working in minutes.
It records which agent made each call, not just that a call happened.
It gets checked against outside logs, so traffic that skipped it shows up.
A concrete example
Pull your network logs for traffic headed to your model providers. Then pull the gateway's own logs. Any traffic in the first list that isn't in the second went around the gateway. That difference is your unchecked AI traffic. Measure it before you trust the gateway to protect anything.