The short version
The AI gateway in Azure API Management (APIM) is not a separate product. It is a set of capabilities on top of Microsoft's API gateway for securing, scaling, monitoring and governing language models, MCP servers and agents. It fronts models in Microsoft Foundry, Amazon Bedrock and self-hosted endpoints.
Sluis is a managed gateway hosted in the EU by 7Lab B.V. in Amsterdam. It is one product with a fixed pipeline, Inspect, Route, Seal: detect and pseudonymize sensitive values, route by a residency and ownership policy, and write a tamper-evident audit entry. It speaks the OpenAI and Anthropic Messages protocols.
The real difference is who builds the controls. In Azure you compose them from policies, backends, Content Safety, Monitor and Foundry deployment choices. In Sluis they are the product, and you configure them.
At a glance
| Azure API Management AI gateway | Sluis | |
|---|---|---|
| Operator | Microsoft Corporation (US) | 7Lab B.V., Amsterdam |
| Form | Azure service in your subscription and region, policy XML | Managed EU service, optional self-hosted Sluis Edge |
| Schemas | OpenAI Chat Completions and Responses, Anthropic Messages (v2 tiers), Vertex; unified OpenAI-compatible API in preview | OpenAI-compatible and native Anthropic Messages, any model behind either |
| Residency | Region of your gateway and backends; Foundry Standard, DataZone or Global deployment types | Organisation policy enforced at dispatch; default EU-only, refused with 403 |
| PII | No dedicated PII policy found in the policy reference; Content Safety moderates harm categories | 60 detectors, reversible pseudonymization before dispatch |
| Logging | Prompts and completions to Azure Monitor and Application Insights | Hash-chained audit ledger, verifiable offline |
| Budgets | Token limits and quotas per counter key | Per-workload rate limits, budgets, allow-lists |
| MCP | Expose REST APIs as MCP servers, front existing ones, A2A agents | Tool calls through the same gate, deny-by-default grants |
| Cost shape | Per tier or per request for the gateway, model usage billed separately | Provider list price + 10%, BYOK EUR 0.50 per 1M tokens |
Where data goes and who controls it
With APIM, location follows your deployment. You pick the Azure region for the gateway and for each backend. There is no jurisdiction policy in the gateway that refuses a request for a provider outside the EU; you express that through which backends exist and how routes are written.
Foundry adds its own rules. Models sold by Azure process prompts and responses within the customer-specified geography unless you use a Global or DataZone deployment type: DataZone can process anywhere inside the defined zone, Global anywhere the model is deployed. Microsoft also documents the EU Data Boundary, a commitment to store and process Customer Data in the EU, subject to limited listed exceptions. Used carefully, this can meet strict EU requirements.
Sluis makes the restriction the default. API routing allows only the EU jurisdiction, a request for a provider outside the allowed set is refused with 403 before dispatch, and widening the policy is a recorded decision. EU ownership of the provider is a separate switch, because an EU region does not imply an EU-owned provider. See residency and models.
On ownership, Microsoft Corporation is a US company, so the CLOUD Act applies to data in its control wherever it is stored. Microsoft has published a commitment to challenge government demands for EU public sector and enterprise customer data where there is a legal basis, and to compensate customers for disclosure in violation of EU law. Sluis operates from the Netherlands, which brings EU law, not immunity from every government. Our CLOUD Act guide covers both sides.
Personal data, content safety and abuse monitoring
APIM's llm-content-safety policy sends prompts and optionally completions to Azure AI Content Safety, which scores four harm categories against thresholds you set. Violations return 403, but for streaming responses the policy stops forwarding events without returning an error. The policy catalogue we read contains no dedicated policy that detects and replaces personal data; you can build one with find-and-replace, policy expressions or another service, and then you own its accuracy.
Sluis puts personal-data handling in the request path. Detectors cover personal data and secrets, including checksum-validated national IDs for 12 EU countries. Policy can block, mask, log or pseudonymize reversibly with tokens like «EMAIL_1» that are restored in the response, streaming included. Detection is not perfect and using Sluis does not by itself establish GDPR compliance. See data protection.
Check one more Azure item. Foundry's abuse monitoring can store and review flagged prompts and completions, including human review by authorised Microsoft staff, located in the EEA for EEA deployments; eligible customers can apply to modify it. If prompts contain special-category data, read that page first.
Logging and audit
APIM can log prompts, completions and token usage to Azure Monitor and Application Insights, with a built-in dashboard and per-consumer token metrics, and you control retention and access through Azure. The pages we read describe logging, not a hash-chained or otherwise tamper-evident ledger.
Sluis writes one entry per call, linked by sha256(prev_hash + record), so altering a field breaks every later link; the gateway CLI verifies the chain offline. See security.
Budgets, caching and agents
APIM's token-limit policy sets tokens-per-minute or quotas by hour, day, week, month or year on any counter key, such as a subscription or an IP address. Backends support round-robin, weighted, priority and session-aware load balancing with circuit breakers. APIM can expose REST APIs as MCP servers and front existing MCP servers with OAuth credential management.
Sluis workloads own rate limits, a total, daily or monthly budget, model allow-lists and policy overrides, debited before dispatch. MCP tool calls pass the same inspect, route, seal and meter gate with deny-by-default grants, and Claude Code, Codex and Cursor can run under organisation policy. See budgets and MCP.
Effort and pricing
APIM is priced as a service. Classic tiers are billed per unit, Consumption per operation, and v2 tiers with monthly included requests and a price per extra million; the amounts load dynamically, so check the live page. The self-hosted gateway is free in Developer and an extra cost in Premium. Model usage is billed by whichever service you call.
Sluis has no subscription or seat fee. Managed usage costs provider list price + 10%, BYOK and custom providers EUR 0.50 per 1M input plus output tokens, prepaid from EUR 25. Checks such as name recognition (EUR 0.005 or EUR 0.01 per request) are metered, and payment-method surcharges apply. See pricing. At very high volume a fixed-capacity gateway can cost less than a percentage fee; at low or uneven volume a gateway you pay for by the hour costs more.
Do not forget engineering time. APIM policies, backends, Content Safety and Monitor dashboards are yours to design and maintain. Sluis is configured, not assembled. For the other gateways on the shortlist, see AI gateways for EU organisations compared.
When Azure API Management is the better choice
- Your workloads, identity and networking already live in Azure, with managed identities, private networking and an existing APIM team.
- You want policy-as-code and the freedom to build custom behaviour beyond a product's settings.
- You want Microsoft's compliance portfolio, contract and support under one agreement.
- Your models run in Foundry and you want gateway governance inside that environment.
When Sluis is the better choice
- You want EU-only routing refused at dispatch without designing it, and EU ownership as a separate control.
- Personal data must be replaced before the provider sees it, and restored in the answer.
- You need an audit record that can be verified as unaltered.
- You want employees, applications and coding agents on one policy, with no Azure estate required.
- You want a self-hosted data plane on your own servers through Sluis Edge.
FAQ
Can Azure API Management enforce EU-only routing?
Yes, if you build it. You deploy gateways and backends in EU regions, use Foundry deployment types that stay inside the EU, and restrict who can add backends. It is an architecture, not a switch. Sluis ships EU-only as the default policy.
Does APIM redact personal data?
We found no dedicated PII policy in the policy reference. It offers Content Safety moderation, find-and-replace and custom policy expressions, so redaction is something you build or add. Sluis pseudonymizes reversibly out of the box.
Does Azure train models on my prompts?
Microsoft states that prompts, completions and embeddings are not used to train foundation models without your permission and are not available to other customers. Abuse monitoring may still store flagged content for review.
Can the two be combined?
Possibly. Sluis connects any custom OpenAI-compatible provider, so an Azure endpoint that speaks that API could be one, with your own key and the custom-provider fee. We have not tested this setup; check how the endpoint is classified under your residency policy. You could also keep APIM for internal API traffic and use Sluis for AI.
Sources
- AI gateway capabilities in Azure API Management
- llm-content-safety policy
- Azure API Management policy reference
- Azure API Management pricing
- Data, privacy, and security for Foundry Models sold by Azure
- Foundry Models sold by Azure abuse monitoring
- What is the EU Data Boundary?
- Microsoft's European digital commitments
- 18 U.S.C. § 2713, added by the CLOUD Act of 2018