Databricks Unity AI Gateway vs Portkey (2026): AI Gateway and Governance Compared
Unity AI Gateway makes AI governance a property of the Databricks estate; Portkey is a platform-independent gateway with 1,600+ models and a deployment ladder down to air-gapped. Here is how they differ, and where each stops being a gateway question.
Databricks Unity AI Gateway and Portkey solve the same first problem — one governed endpoint in front of many model providers — from opposite bets. Unity AI Gateway (formerly Mosaic AI Gateway, GA since August 4, 2026) is the runtime governance layer of the Databricks platform: built on Unity Catalog, it routes, meters and polices traffic with budgets that hard-block, inline service policies, MCP servers as catalog securables and cost tables in the same billing system finance already reads. Portkey is a gateway and LLM-ops control plane that stands apart from any one data platform: one OpenAI-compatible API to 1,600+ models across 45+ providers, an MIT open-source core, deep observability, and SaaS, hybrid or fully air-gapped deployment — owned by Palo Alto Networks since May 2026.
This page compares the two on the capability axes that matter, with every claim cited to each vendor's own documentation. It then does something a straight head-to-head cannot: it asks what happens when the requirement grows past the gateway — estate-wide inventory, compliance evidence, agent containment — which is where a full AI management platform like Kosmoy enters the frame.
Who each product is for
Databricks Unity AI Gateway
Unity AI Gateway speaks to enterprises already standardized on Databricks that want AI spend, access, guardrails and audit governed where their data governance already lives. Traffic to Databricks-hosted and external models — OpenAI (including Azure OpenAI), Anthropic, Cohere, Amazon Bedrock, Google Vertex AI and any OpenAI-compatible provider — flows through one gateway with fallbacks, traffic splitting and Smart Routing (Beta), budgets that alert or hard-block, and service policies that redact PII and block jailbreaks before routing (docs; GA blog).
It reached GA on August 4, 2026 — with service policies, agent services and Smart Routing still in Beta — and runs only as a Databricks-managed service on AWS, Azure or GCP, requiring a Unity Catalog-enabled workspace. Routing, rate limits and fallbacks are free; payload logging and usage tracking bill DBUs (pricing).
Portkey
Portkey speaks to platform teams that want the gateway problem solved independently of any data platform: one OpenAI-compatible API to 250+ LLMs and 1,600+ models across 45+ providers, request logging with 21+ metrics, per-key budgets and rate limits, a guardrails library with synchronous blocking, and MCP plus agent gateways with per-user tool provisioning (gateway repo, MIT, ~12.4k stars).
Its deployment ladder is rare among gateways — SaaS, hybrid with the data plane in your VPC, or fully air-gapped (self-hosting docs). Since May 2026 it belongs to Palo Alto Networks as the gateway layer of Prisma AIRS — enterprise security distribution, with a public docs changelog that stops at April 2026.
Databricks Unity AI Gateway vs Portkey vs Kosmoy — the capability radar
Three shapes on the same ten axes. Unity AI Gateway (orange) and Portkey (violet) track each other closely on the gateway spokes — Portkey edges ahead on Gateway & Policy Control and Observability (9 to 8 on both) and they tie at 8 on Guardrails — then split hard on Deployment Sovereignty: 9 for Portkey's self-host-to-air-gap ladder against 3 for a Databricks-managed-only service. Unity AI Gateway holds a slight edge on Agent Containment (5 to 4) through hard budget blocks and contextual policies. Both cluster at 5 on the inventory and compliance axes — the gateway category's signature. Kosmoy (blue) trades a little raw gateway breadth for reach across inventory, compliance and agent containment. Read it as area: the two gateways compete spoke by spoke; the suite covers the web.
- Databricks Unity AI Gateway
- Portkey
- Kosmoy
| Capability (0–10) | Databricks Unity AI Gateway | Portkey | Kosmoy |
|---|---|---|---|
| AI Inventory & Discovery | 5 | 5 | 9 |
| Security & Shadow AI | 5 | 4 | 8 |
| Observability & FinOps | 8 | 9 | 7 |
| Gateway & Policy Control | 8 | 9 | 8 |
| Guardrails & Runtime Safety | 8 | 8 | 8 |
| Agent Containment | 5 | 4 | 9 |
| Compliance & Audit | 5 | 5 | 9 |
| Testing, Evals & Red-teaming | 4 | 3 | 7 |
| Agent Building | 2 | 2 | 6 |
| Deployment Sovereignty | 3 | 9 | 10 |
Bold marks the highest score on each row. 10 is reserved for categorical architectural facts; specialists are expected to outscore platforms on their own spoke.
See it live
How Kosmoy scores on these axes — see it on your own use case.
Book a demo30 minutes, straight to the product. Or email sales@kosmoy.com.
Where Databricks Unity AI Gateway wins
Governance woven into the data estate. External MCP servers register as Unity Catalog securables with fine-grained permissions, tool filtering and centralized audit, alongside managed integrations for Google Drive, Jira, Confluence, Slack, GitHub and SharePoint (MCP governance blog) — and every policy decision lands in the same catalog that already governs the data. Portkey's registries govern what is routed through Portkey; they do not live in your data catalog.
Budgets with a documented hard-block lifecycle. Hit a threshold and the gateway can alert — or block further requests until the budget resets or an admin raises it, with per-user and per-budget spend views (budgets docs); cost observability extends to enriched billing records attributing spend across users, teams, applications, models and providers (cost observability docs) — finance-grade tables Portkey's per-key budgets and metrics do not reach into a billing system.
Agent-action policies in the request path. Contextual Service Policies (Beta) can allow, deny or require approval for agent actions such as modifying files or pushing code (guardrails docs) — an approval workflow Portkey does not document; its agent gateway controls skill-level access rather than gating individual actions for approval.
Consumption pricing inside existing billing. Routing, rate limits, fallbacks and traffic splitting are free; payload logging and usage tracking bill through the DBUs a Databricks shop already meters (pricing) — no second vendor contract, procurement cycle or per-seat tier to negotiate.
Where Portkey wins
Model and provider breadth. One API to 250+ LLMs and 1,600+ models across 45+ providers (gateway repo), against Unity AI Gateway's documented set — OpenAI, Anthropic, Cohere, Bedrock, Vertex AI and OpenAI-compatible endpoints (external models docs).
A deployment ladder Databricks does not offer. MIT open-source self-host, hybrid with the data plane in your VPC, or a documented fully air-gapped enterprise deployment (self-hosting docs). Unity AI Gateway runs only as a Databricks-managed service — no self-hosted, on-prem or air-gapped option is documented as of August 16, 2026.
Observability depth. Full request logging with 21+ metrics, per-key budgets and rate limits, OpenTelemetry and data-lake export (observability docs) — a 9 on the radar against Databricks' strong but newer 8, and it exports to your stack rather than living in platform system tables.
No platform commitment, and an open core. The MIT gateway (~12.4k stars) adopts without a Unity Catalog workspace, DBU billing or a Databricks relationship — for an estate that spans Snowflake, bare Kubernetes and three clouds, the gateway does not pull AI governance into one vendor's platform.
Longer-shipping gateway surface. Portkey's guardrails, MCP gateway and (since April 2026) agent gateway with skill-level access control predate Unity AI Gateway's August 2026 GA, where service policies, agent services and Smart Routing are still marked Beta (GA blog) — though Portkey's own last open-source gateway release predates its acquisition.
Where Kosmoy fits
The specialist owns its spoke; the platform holds the frontier
Both products govern the traffic that opts in: an app or coding agent points its base URL at the gateway and inherits budgets, guardrails and logs. Neither documents what a regulated enterprise is increasingly asked to prove — an estate-wide inventory of AI running outside the gateway, evidence against the EU AI Act, ISO/IEC 42001 or NIST AI RMF, or kernel-enforced containment for agents that act. Unity AI Gateway's inventory covers assets registered in Unity Catalog; Portkey's covers assets routed through Portkey; both stop at their own perimeter as of August 16, 2026. When those are the ask, the category changes — from gateway to control plane, the frontier mapped on the AI capability map.
Kosmoy includes the gateway both products are — one OpenAI-compatible policy point with guardrails, RBAC, budgets and logging — but wraps it in the layers a gateway leaves out: a risk-tiered inventory of every model, MCP server and agent across the estate, including a master agent registry that pulls from Foundry, Bedrock, Vertex, Salesforce and ServiceNow; EU AI Act, ISO 42001 (aligned) and NIST AI RMF evidence built from registry state plus gateway logs; and kernel-enforced Action Capsule containment with a kill switch. The direct head-to-heads live at Kosmoy vs Databricks Unity AI Gateway and Kosmoy vs Portkey.
So the honest framing is not “Kosmoy beats Unity AI Gateway and Portkey at being a gateway” — Databricks integrates deeper into its own estate and Portkey routes to more models. It is that a gateway covers two or three spokes of the ten-axis map. If the requirement is the whole web — inventory, gateway, compliance and containment in one self-hosted platform — that is a suite decision, not a gateway decision.
| Capability | Capability | Unity AI Gateway | Portkey | Kosmoy |
|---|---|---|---|---|
| Hosting / deployment | Databricks-managed only (AWS, Azure, GCP) | SaaS, hybrid VPC or air-gapped; MIT core self-host | Self-hosted Kubernetes, air-gap capable | |
| Model / provider breadth | OpenAI, Anthropic, Cohere, Bedrock, Vertex + OpenAI-compatible | 1,600+ models across 45+ providers | One OpenAI-compatible gateway across LLM, MCP and A2A traffic | |
| Budgets & hard spend caps | Alert or hard-block until reset or raised | Per-key budgets and rate limits | Budgets enforced at the gateway | |
| Guardrails in the request path | PII, safety, jailbreak, hallucination + custom (partly Beta) | 20+ checks with sync blocking; partners for advanced detection | ✓ | |
| MCP governance | MCP servers as Unity Catalog securables + managed integrations | MCP gateway with per-user tool provisioning | MCP Gateway + registry | |
| Observability / FinOps | System tables, request tags, payload logging (DBU-billed) | 21+ metrics, OTel and data-lake export | Cost, usage, logs and agent traces per model, app and user | |
| EU AI Act / ISO 42001 / NIST evidence | — | — | ✓ | |
| Kernel-enforced agent containment | No — contextual approval policies (Beta) + budget blocks | — | ✓ | |
| Pricing shape | Consumption via DBUs; routing free | Free tier; Pro from $49/mo; enterprise quote | Enterprise subscription |
Last verified August 16, 2026 against each vendor's public documentation.
Which should you choose?
For a team whose problem genuinely is model traffic, pick on the estate: Unity AI Gateway if Databricks is where AI already lives and consumption billing beats a new contract; Portkey if the gateway must span stacks, export observability to your own tools, or run air-gapped. Both are OpenAI-compatible, so applications move with a base-URL change — the sticky parts are Unity Catalog registrations on one side and Portkey configs and logs on the other. Some enterprises run both today: Unity AI Gateway for workloads inside Databricks, Portkey for everything else.
For an enterprise that has to prove control over all of its AI — not just route it — the choice is not between these two gateways but between a point tool and a suite. Kosmoy can coexist with either: some teams keep Unity AI Gateway for lakehouse workloads or Portkey for developer experimentation while Kosmoy holds the estate-wide inventory, compliance evidence and containment for what reaches production.
Questions buyers ask
Is Unity AI Gateway the same as Mosaic AI Gateway?
Yes — Unity AI Gateway is the new name for what Databricks previously shipped as Mosaic AI Gateway, rebuilt around Unity Catalog as the governance backbone and taken to general availability on August 4, 2026. Older Databricks material about Mosaic AI Gateway features (rate limits, payload logging, guardrails) describes the same product line; the GA release added budgets with hard blocks, service policies, agent services and MCP governance, several of which remain in Beta.
Is Databricks Unity AI Gateway or Portkey better?
Neither is universally better — the decision follows your estate. Unity AI Gateway is stronger for enterprises standardized on Databricks: governance rides Unity Catalog, budgets hard-block, costs land in finance-grade system tables and there is no second vendor. Portkey is stronger when AI spans many stacks or must run in your own infrastructure: 1,600+ models, deeper request observability with OTel export, an MIT core and a SaaS-to-air-gapped deployment ladder. If you are not a Databricks shop, Unity AI Gateway is not an option — it requires a Unity Catalog-enabled workspace.
Can Unity AI Gateway govern apps that don't run on Databricks?
Only if they opt in. External applications and coding agents participate by pointing their base URL at the workspace gateway endpoint, which requires a Unity Catalog-enabled Databricks workspace. Traffic that bypasses the gateway is not intercepted or governed — no passive discovery of outside AI usage is documented as of August 16, 2026 — and there is no self-hosted or air-gapped deployment of the gateway itself.
Do Unity AI Gateway or Portkey handle EU AI Act compliance?
Not as products. Both provide audit logs and access controls that support a compliance program, but neither documents EU AI Act, ISO/IEC 42001 or NIST AI RMF evidence generation, framework mapping or AI risk classification as of August 16, 2026 — Databricks' compliance support is generic audit and system tables, and Portkey's is SOC 2 / ISO 27001 / HIPAA certifications. That evidence layer is a governance-platform capability — Kosmoy generates it from its registries and gateway logs.
Where does Kosmoy fit against Unity AI Gateway and Portkey?
Kosmoy includes the OpenAI-compatible gateway both provide, but it is one layer of a full AI management platform that runs single-tenant in your Kubernetes: organization-wide inventory beyond the gateway, EU AI Act / ISO 42001 / NIST AI RMF evidence, and kernel-enforced agent containment sit alongside it. If your requirement is governed traffic inside Databricks (Unity AI Gateway) or a platform-independent gateway (Portkey), those are the lighter answers; if it is proving control over all your AI in your own infrastructure, that is a suite decision.
Sources
Every factual claim about another vendor on this page traces to that vendor's own published material or a named third-party source below.
- AI governance with Unity AI Gateway (Databricks docs) — accessed August 16, 2026
- Unity AI Gateway is Generally Available (Databricks blog, Aug 4, 2026) — accessed August 16, 2026
- Manage budgets for Unity AI Gateway — accessed August 16, 2026
- Unity AI Gateway pricing — accessed August 16, 2026
- Portkey open-source gateway repository — accessed August 16, 2026
- Portkey docs — plan & feature comparison (SaaS / hybrid / air-gapped) — accessed August 16, 2026
- Kosmoy AI Gateway — accessed August 16, 2026
- Unity AI Gateway product page — accessed August 16, 2026
- Monitor Unity AI Gateway cost — accessed August 16, 2026
- External models in Model Serving (provider list) — accessed August 16, 2026
- What's new: service policies, guardrails, observability and cost controls — accessed August 16, 2026
- Mosaic AI Gateway updates (former product name; Databricks blog) — accessed August 16, 2026
- Portkey docs — what is Portkey — accessed July 15, 2026
- Portkey docs — observability — accessed July 15, 2026
- Portkey docs — guardrails — accessed July 15, 2026
- Portkey docs — MCP gateway — accessed July 15, 2026
- Portkey pricing — accessed July 15, 2026
- Palo Alto Networks press release — Portkey acquisition completed (May 29, 2026) — accessed July 15, 2026
One suite instead of two point tools
Kosmoy puts an inventory, a policy gateway, compliance evidence and a containment sandbox around every AI your teams run — in your own Kubernetes.
Or email sales@kosmoy.com.