API management now has to govern agents and MCP servers too
Forrester's API Management Wave for Q3 2026 says an AI gateway alone is not enough. Why APIs, LLM traffic, MCP servers and agents belong under one set of rules.
For fifteen years, API management has been about one thing: controlling who may call which APIs, how often, and with what security. That job is now getting bigger. In September 2026, Forrester published The Forrester Wave: API Management Software, Q3 2026, and according to MuleSoft, which was named a Leader, the report’s main message is that API management must now also cover AI.
From APIs to AI traffic
As MuleSoft quotes it, Forrester writes that enterprises now have to govern LLM traffic, MCP servers and autonomous agents alongside traditional APIs, and that “an AI gateway alone does not meet those needs”. Forrester recommends a holistic solution rather than isolated AI gateways.
The reasoning is easy to follow. An AI agent that orders goods in the ERP system does so through an API, often wrapped as an MCP tool, using a language model that is called through yet another API. If these three layers are governed in three different places, nobody has the full picture of what the agent is allowed to do and what it actually did.
What this looks like in practice
The integration vendors are responding in similar ways this autumn:
- MuleSoft positions Omni Gateway as one layer for visibility, governance and management across APIs, agents, LLMs and MCP servers, with a federated architecture across several gateways.
- Boomi has an MCP Registry in its API management, which in the September release got lifecycle status, server refresh and syncing with Anthropic’s registry, alongside policy templates and per-API OpenTelemetry tracing.
- Workato launched an AI Gateway with separate gateways for models, MCP, agents and APIs.
The terms differ, but the principle is the same: an MCP server is an API with a new consumer, and it needs the same discipline.
What MCP servers need
The Model Context Protocol has quickly become the standard way to give AI agents access to tools and data. A new version of the specification (2026-07-28) makes it easier to put gateways and load balancers in front of MCP servers, and tightens authorisation. That makes MCP easier to govern, but the discipline still has to come from you:
- Catalogue. Keep a register of which MCP servers exist, who owns them and which systems they reach.
- Access. Agents should get their own identities, with the least access they need, not share a service account.
- Lifecycle. Version MCP servers like APIs, with deprecation and change notices.
- Observability. Log tool calls with enough context to reconstruct what an agent did and why.
- Cost. LLM traffic costs money per call. Limits and routing belong in the same place as rate limits.
What to do now
If your organisation has an API management platform, start by asking what it can do for MCP servers and LLM traffic today. Many already have more than you think. If agents and MCP servers are currently being set up outside API management, that is the gap to close first, before the number of agents grows.
Sources
This post was written with AI assistance and reviewed by the editor before publishing.