The ACL (access control list) policy allows you to restrict AI Consumers or AI Consumer Groups access to AI Gateway entities. This is the same capability provided by access.acls for AI Models, AI MCP Servers, and AI Agents. However, the policy provides additional configuration options.
You can configure either an allow list or a deny list with AI Consumers, AI Consumer Groups or authenticated groups (discovered by an AI Auth Strategy running in openid-connect mode).
The ACL policy requires that AI Consumers are authenticated and you should set up AI Auth Strategies before enabling this policy.