ToolsThe story, in brief

Team-wide provider allowlist on AI Gateway

Regulated teams just got compliance teeth. Vercel's AI Gateway now enforces org-wide provider allowlists—blocking unapproved vendors even if developers try to route around them.

Paper-cut illustration of a coral software window opening into a three-dimensional drafting space.
New tools for building and creating with AI.AI illustration by KeyNews
The KeyNews take

Why it matters

Enterprise AI governance just moved from policy document to enforced infrastructure. Vercel's provider allowlist gives regulated orgs the routing control they need to satisfy security/legal sign-off on AI vendors—turning approved-vendor lists into technical guarantees, not just guidelines.

The key facts

15 to know
  1. Feature: Team-wide provider allowlist on Vercel AI Gateway

  2. Enforcement happens at gateway level, not request level—developers cannot bypass org restrictions

  3. Applies to all API formats: AI SDK, OpenAI Chat Completions API, Anthropic Messages API

  4. Blocks unapproved providers even when coding agents attempt to modify request-level filters

  5. Only team owners can modify allowlist, keeping control centralized and auditable

  6. Works in conjunction with Zero Data Retention (ZDR) and request-level filtering

  7. New providers disabled by default once allowlist enabled, preventing silent expansion of approved set

  8. Published: May 28, 2026

  9. Vercel AI Gateway now supports team-wide provider allowlist

  10. Enforcement happens at gateway level, not request level—developers cannot bypass

  11. Restriction applies to coding agents even if they omit or modify provider filters

  12. New providers disabled by default once allowlist is enabled

  13. Only team owners can modify allowlist

  14. Works across OpenAI Chat Completions API, Anthropic Messages API, and AI SDK

  15. Integrates with existing compliance controls: Zero Data Retention, request-level filtering

Go to the source

Vercel Blogvercel.com

Publisher excerpt: AI Gateway now supports a team-wide provider allowlist. Teams can restrict which providers can serve requests, so traffic only routes to approved providers. The allowlist applies to every request through AI Gateway, including Bring Your Own Key (BYOK) traffic. Regulated teams typically vet AI…
Read original report
Back to today's editionMore tools news

Keep reading

Related stories

More from Tools