Kosmoy vs Databricks Unity AI Gateway: AI Governance and Control Compared (2026)
Databricks' Unity AI Gateway (GA August 2026, formerly Mosaic AI Gateway) brings budgets, guardrails and MCP governance to everything routed through a Databricks workspace. Kosmoy is an independent control plane for the whole estate — including the AI that never touches Databricks. The architectural decision comes before the feature table.
This comparison names the product precisely, because the scope matters: Unity AI Gateway — relaunched under that name after starting life as Mosaic AI Gateway — is Databricks' runtime governance layer, built on Unity Catalog. It meters, routes, guards and audits AI traffic that flows through a Databricks workspace, and since August 2026 it is generally available with budgets that hard-block, service policies, and MCP servers governed as Unity Catalog securables. It is a serious governance product, not a checkbox.
Kosmoy meets it in RFPs from the other direction: an AI management platform that is deliberately independent of any data platform, cloud or model vendor — one inventory, one policy gateway, one audit trail and a containment runtime, deployed in the customer's own Kubernetes. The honest comparison is not which product is better; it is which scope you are buying for: the Databricks estate, or the estate.
Who each product is for
Databricks Unity AI Gateway
Unity AI Gateway is for enterprises whose AI centre of gravity is Databricks. If your models serve from Databricks Model Serving, your agents are built with Databricks tooling, and your governance culture is Unity Catalog, the gateway extends that governance to runtime: budgets that block when spent, PII and safety guardrails with block-or-redact actions, per-principal rate limits, and MCP servers registered, permissioned and audited as Unity Catalog securables (docs).
It also reaches beyond Databricks-hosted models in one specific way: external providers — OpenAI, Anthropic, Cohere, Bedrock, Vertex — can be fronted by the gateway, and external apps or coding agents can point their base URL at the workspace endpoint. Participation is opt-in per application; the governance boundary is the workspace.
Kosmoy
Kosmoy is for the executive accountable for AI wherever it runs — CIO, Chief AI Officer, CISO. Its unit of governance is the AI use case and the agent, not the workspace: four registries inventory every model, agent and MCP server across platforms; the gateway enforces one policy on LLM, MCP and A2A traffic; compliance turns registry state and logs into EU AI Act, ISO/IEC 42001 (aligned) and NIST AI RMF evidence; and the Action Capsule contains the agents that act.
It is single-tenant software in your own Kubernetes — including on-premises and air-gapped — in production at Italy's central bank and Europe's largest defence and aerospace group. Databricks can be one of the platforms it governs; it does not need to be there at all.
The capability radar
Read the shapes for scope, not quality. Unity AI Gateway peaks on Observability & FinOps (8 vs 7) — its system tables and hard-blocking budgets are excellent — and matches Kosmoy on Gateway (8) and Guardrails (8) inside its boundary. Kosmoy's web is wider where the estate is bigger than one platform: inventory (9 vs 5), compliance (9 vs 5), containment (9 vs 5) and sovereignty (10 vs 3), the last a categorical fact — one product runs in your Kubernetes, the other only as a Databricks-managed service.
- Databricks Unity AI Gateway
- Kosmoy
| Capability (0–10) | Databricks Unity AI Gateway | Kosmoy | Notes on Databricks Unity AI Gateway |
|---|---|---|---|
| AI Inventory & Discovery | 5 | 9 | Registered inventory of models, providers, MCP services and agents in Unity Catalog; no discovery of unregistered AI outside the platform. |
| Security & Shadow AI | 5 | 8 | Credential brokering (agents never see provider keys), query permissions and identity-aware controls; shadow-AI detection outside routed traffic not documented. |
| Observability & FinOps | 8 | 7 | System tables for per-request usage and hourly spend, request tags for team/app attribution, payload logging, dashboards — strong, and newer than Portkey's. |
| Gateway & Policy Control | 8 | 8 | Rate limits, traffic splitting, fallbacks, Smart Routing (Beta) and service policies — Databricks-anchored rather than provider-breadth-focused. |
| Guardrails & Runtime Safety | 8 | 8 | Safety, PII (block or redact), keyword/topic, jailbreak and hallucination filters plus custom guardrails, enforced inline. |
| Agent Containment | 5 | 9 | Contextual Service Policies (Beta) can deny or require approval for agent actions; no sandbox or kill switch in the gateway itself. |
| Compliance & Audit | 5 | 9 | Audit logs and policy decisions as queryable Unity Catalog records; no AI-regulation evidence tooling. |
| Testing, Evals & Red-teaming | 4 | 7 | Delegated to MLflow 3: gateway inference tables feed MLflow tracing, judges and monitoring — documented integration, not a native suite. |
| Agent Building | 2 | 6 | The gateway registers and governs agents; building happens in separate Databricks products (Agent Bricks, Agent Framework). |
| Deployment Sovereignty | 3 | 10 | Databricks-managed only, on AWS/Azure/GCP regions; no self-hosted, on-prem or air-gapped deployment target. |
Bold marks the highest score on each row. 10 is reserved for categorical architectural facts; specialists are expected to outscore platforms on their own spoke.
See it live
How Kosmoy scores on these axes — see it on your own use case.
Book a demo30 minutes, straight to the product. Or email sales@kosmoy.com.
Where Databricks Unity AI Gateway wins
Inside the Databricks estate, the integration is unmatched. Governance rides the platform: MCP servers as Unity Catalog securables with tool-level filtering, agent endpoints and skills registered and discoverable, audit landing in the same catalog as the data (MCP governance). No external product can govern Databricks-native workloads this natively.
Cost observability depth. Per-request usage with custom tags, hourly external-model spend by provider, target model and principal, enriched billing records — queryable as system tables with your own SQL (cost observability). Kosmoy attributes cost per model, app, team, user and agent, but Databricks' lakehouse-native analytics surface is stronger for finance-grade slicing.
Budgets that hard-block, free routing features. Alert-or-block budgets, rate limits, fallbacks and traffic splitting ship free of charge with the platform; Smart Routing (Beta) picks models by quality, cost and budget (budgets). For a Databricks shop the marginal cost of adopting it is close to zero.
Evaluation depth through MLflow 3. Gateway inference tables feed MLflow tracing, LLM judges, human feedback and production monitoring — a documented, first-party loop (MLflow 3 GenAI). Kosmoy's built-in evaluation suite is comprehensive, but MLflow's judge ecosystem and experiment tooling run deeper for ML-platform teams.
Where Kosmoy wins
The estate beyond the workspace. Unity AI Gateway governs what routes through it; participation is opt-in per app. Kosmoy's master agent registry harvests agents from Azure AI Foundry, Bedrock, Vertex, Salesforce and ServiceNow, reconciles them against approved use cases and flags shadow AI — governance of things that never asked to be governed.
Compliance as a product, not a byproduct. Unity AI Gateway produces audit-quality logs; it does not document EU AI Act, ISO/IEC 42001 or NIST AI RMF evidence generation, risk classification or approval workflows as of August 16, 2026. Kosmoy generates framework-mapped evidence bundles from registry state plus gateway logs — the artifact a regulator actually reads.
Containment is architectural. Databricks' contextual service policies (Beta) can deny or require approval for agent actions — real policy-level control. Kosmoy's Action Capsule is a kernel-enforced sandbox: egress physically limited to the paired gateway, per-task credentials, kill switch. Different category of guarantee.
Deployment sovereignty. Unity AI Gateway exists only as a Databricks-managed service on AWS, Azure or GCP. Kosmoy is single-tenant software in your own Kubernetes, air-gap capable — prompts, traces and the policy plane never transit a vendor cloud. For sovereignty-constrained buyers this is the whole decision.
Vendor independence as a strategy. A control plane owned by your data platform governs with your data platform's gravity. Kosmoy is independent of cloud, model and data-platform vendors — which is precisely what makes it credible as the layer above all of them.
Deployment and pricing model
| Databricks Unity AI Gateway | Kosmoy | |
|---|---|---|
| Hosting model | Databricks-managed service (AWS, Azure, GCP workspaces only) | Self-hosted only — single-tenant, your own Kubernetes (air-gap capable) |
| Governance scope | AI traffic routed through the workspace gateway; Unity Catalog-registered assets | Whole estate: registries harvest agents/models/MCP across platforms; gateway governs routed traffic |
| External providers | OpenAI, Anthropic, Cohere, Bedrock, Vertex + any OpenAI-compatible provider | Every provider behind the OpenAI-compatible gateway, incl. self-hosted models |
| Budgets / hard caps | Yes — alert or hard-block per budget | Yes — warn, then block at the gateway |
| Compliance evidence | Audit/system tables; no framework tooling documented | EU AI Act, ISO/IEC 42001 (aligned), NIST AI RMF bundles |
| Agent containment | Contextual service policies (Beta): allow/deny/approve actions | Action Capsule sandbox: kernel-enforced, per-task credentials, kill switch |
| Pricing model | Platform consumption; core routing free, logging/tracking via DBUs | Enterprise subscription; no self-service tier |
Last verified August 16, 2026 against each vendor's public documentation.
Running them together
Run-both is a legitimate architecture, and for large Databricks customers probably the default: Unity AI Gateway governs Databricks-native serving, agents and MCP inside the workspace, while Kosmoy holds the cross-estate layer — the master inventory that includes the Databricks assets, the compliance evidence for every use case, the policy on traffic that runs elsewhere, and containment for the agents that act on systems of record. Both expose OpenAI-compatible endpoints, so apps can move between the two paths by changing a base URL. The anti-pattern is pretending either one covers the other's scope: a workspace gateway is not an estate inventory, and an estate platform will not out-integrate Databricks inside Databricks.
Questions buyers ask
Is Unity AI Gateway the same as Mosaic AI Gateway?
Yes — Unity AI Gateway is the current name of the product originally launched as Mosaic AI Gateway. The rename accompanied the gateway's move into Unity Catalog and its June 2026 relaunch; general availability followed on August 4, 2026. Databricks' own documentation tree still carries legacy pages under the old endpoint model.
Does Databricks Unity AI Gateway work with AI outside Databricks?
Partially, and opt-in. It can front external model providers (OpenAI, Anthropic, Cohere, Bedrock, Vertex and any OpenAI-compatible endpoint), and external apps or coding agents can point their base URL at the workspace gateway. What it does not document is governing AI that never routes through the workspace — there is no cross-platform discovery or passive interception as of August 16, 2026.
Can Unity AI Gateway produce EU AI Act compliance evidence?
It produces audit-quality records — payload logs, usage system tables, policy decisions in Unity Catalog — which support a compliance program. It does not document EU AI Act, ISO/IEC 42001 or NIST AI RMF evidence generation, use-case risk classification or approval workflows as of August 16, 2026. Kosmoy generates framework-mapped evidence bundles as a product feature; that difference is structural, not roadmap timing.
Should a Databricks customer still evaluate Kosmoy?
If all your AI lives on Databricks, Unity AI Gateway plus MLflow may be enough. Evaluate Kosmoy when any of these are true: agents run on Microsoft, AWS, Google, Salesforce or ServiceNow platforms too; a regulator will ask for framework-mapped evidence; sovereignty rules out a vendor-managed control plane; or high-autonomy agents need containment stronger than policy. In those estates the two products are layers, not rivals.
How do Unity AI Gateway and MLflow 3 relate?
They are complementary Databricks products with a documented integration: the gateway enforces at runtime and writes inference tables; MLflow 3 supplies tracing, LLM-judge evaluation and production monitoring over that telemetry. If you are comparing evaluation and observability tooling specifically, compare against MLflow 3 — not the gateway. We score them as separate entities for exactly that reason.
Sources
Every factual claim about another vendor on this page traces to that vendor's own published material or a named third-party source below.
- AI governance with Unity AI Gateway (Databricks docs) — accessed August 16, 2026
- Unity AI Gateway is Generally Available (Databricks blog) — accessed August 16, 2026
- Unity AI Gateway budgets — accessed August 16, 2026
- MLflow 3 for GenAI (Databricks docs) — accessed August 16, 2026
- Kosmoy Action Capsule — accessed August 16, 2026
- Kosmoy AI Compliance — accessed August 16, 2026
- Unity AI Gateway product page — accessed August 16, 2026
- Monitor Unity AI Gateway cost — accessed August 16, 2026
- External models in Model Serving (provider list) — accessed August 16, 2026
- What's new: service policies, guardrails, observability and cost controls — accessed August 16, 2026
- Unity AI Gateway pricing — accessed August 16, 2026
- Mosaic AI Gateway updates (former product name; Databricks blog) — accessed August 16, 2026
Related comparisons
See the platform behind the scores
Kosmoy puts an inventory, a policy gateway and a containment sandbox around every AI your teams run — in your own Kubernetes.
Or email sales@kosmoy.com.