Any agents that are tied to the tenant/environment that private security gateway is for will get the updated set of security gateways from the cluster on the fly and immediately prioritize that private security gateway. They should begin using it right away without any manual changes to agents being required.
Agree with what James K said. The only exception to this is if you installed the OneAgent with an existing proxy setting that doesn't allow connection to the Security Gateway. The OneAgent won't be able to connect to the Security Gateway directly. To enable the OneAgent to connect to the Security Gateway, you will have to re-install it with no proxy or proxy-related setting.