Snowflake Cortex AI Gateway Aims to Govern AI Agents and Stop Runaway Enterprise Costs

5 Sources

Share

Snowflake launched Cortex AI Gateway to centrally control how AI agents like Claude Code and Cursor access enterprise data. The platform supports 100+ MCP servers and integrates with 1Password, Aembit, SailPoint, Okta, and Saviynt to prevent runaway costs and security risks as agents operate at machine speed across systems.

News article

Snowflake Introduces Cortex AI Gateway to Control AI Agents

Snowflake announced Cortex AI Gateway on Tuesday, a centralized control layer designed to govern how AI agents access enterprise data, tools, and models

1

. The platform manages both first-party agents built within Snowflake, such as Snowflake CoWork and CoCo, and third-party AI agents developed on external platforms including Claude Code and Cursor

2

. With support for more than 100 MCP servers, the gateway centralizes access policies, authentication, permissions, and audit logging in a single location

1

.

Cortex AI Gateway builds directly on Snowflake's acquisition of Natoma Labs in May 2026, bringing enterprise-grade Model Context Protocol platform capabilities into Snowflake for secure agent interoperability

3

. The company also unveiled security integrations with 1Password, Aembit, Linx Security, SailPoint, Okta, and Saviynt, forming a coalition of identity vendors aligned around a shared trust model for autonomous agents

1

.

Traditional Security Models Fail When AI Agents Become Actors

Mayank Upadhyay, Snowflake's chief security and trust officer, explained that decades of enterprise security architecture rest on an assumption that no longer holds: that the actor behind every access request is a person

1

. Traditional security was built for a world where humans accessed one application at a time, operating at human speed within defined boundaries. AI agents change that completely by operating at machine speed and combining access across systems, exercising permissions that were never intended to work together

1

.

Nancy Wang, chief technology officer of 1Password, described the failure mode in stark terms. The default pattern when agents first arrived was dangerously simple: give the agent user credentials so it can act as that person

1

. If someone with admin access grants those credentials to an agent, that agent suddenly has admin access to all systems and could exfiltrate data if subject to prompt injection

1

. Audit logs become useless when they show a person sending millions of dollars offshore when it was actually an agent going off the rails

1

. Her prescription: agents need their own identity

1

.

Cortex AI Gateway Tackles Runaway AI Costs and Governance

Cortex AI Gateway addresses two critical barriers to enterprise AI adoption: securing AI agents while providing centralized visibility and control over AI consumption costs

3

. The platform gives IT and finance teams a unified view of AI consumption, attributes costs to specific teams, agents, or workloads driving them, and enforces spending limits before bills spiral

5

.

Upadhyay described how AI costs compound in practice. Agents can invoke multiple models, call different tools, and execute multi-step workflows, creating consumption patterns that change from task to task

1

. A simple request that only requires retrieving a document could unintentionally be routed through a more expensive reasoning model, trigger additional searches, and drive up token consumption

1

. The gateway tracks token consumption across models, teams, and workloads, helping prevent runaway costs before they occur

2

.

Security Integrations Enable Task-Scoped Agent Access

The first wave of secure third-party agent access integrations targets a common blind spot where an agent operates under a user's broad credentials, making it hard to tell which agent reached which data and under whose authority

2

. The 1Password integration gives third-party agents short-lived, task-scoped access tied to a clear record of the person behind each agent, allowing companies to move agents into production without leaving them standing access to sensitive data

2

.

Aembit co-founder and CEO David Goldschlag said its policy-based access eliminates long-lived credentials

2

. Saviynt works at runtime, weighing an agent's intent and permissions before allowing it to act, while SailPoint frames its role around giving security teams visibility and accountability over third-party agent access

2

. These integrations are designed to make third-party agents governable, enable task-scoped agent access, and extend consistent governance across agent ecosystems

5

.

Early Adopters See Path to Production-Ready AI

Media intelligence firm Meltwater is one early adopter. Chief Technology Officer Aditya Jami said Cortex AI Gateway offers a path to make agents more useful, observable, and production-ready

3

. The gateway should let Meltwater's agents connect to the right data and tools without loosening the controls its customers count on

2

.

Caitlin Halferty, Head of Data & Analytics at Thomson Reuters, said building trusted AI for professionals requires strong AI security and governance, with visibility into how AI systems access data, use tools, and take action

3

. As AI becomes more deeply embedded in professional workflows, organizations need the ability to protect sensitive information and maintain clear controls without limiting innovation

3

.

Snowflake Positions Itself as Control Plane for Agentic Enterprise

The announcement from Snowflake's Bozeman, Montana base represents the company's most aggressive move yet to position itself not merely as the place where enterprise data lives, but as the control plane that decides what AI agents are allowed to do with it

1

. Upadhyay argued that the next era of AI won't be built through more walled gardens but through secure agent interoperability

1

. If every vendor builds a closed ecosystem of agents, enterprises simply recreate the fragmentation they've spent years trying to solve, creating a new generation of AI silos that limit innovation and make it harder to scale AI across the business

1

.

Cortex AI Gateway will enter public preview soon, with third-party agent access integrations following in private preview

2

. The gateway keeps an end-to-end record of agent activity, giving teams a single log of which agent did what, which tools and systems it reached, and the order of steps it followed

2

. Snowflake is also advancing enterprise security foundations across areas that matter most for production-ready AI, including tools for gauging AI risk posture, providing agents with verified identity, protecting sensitive data from improper use, and limiting agent sessions to the scope required for each task

5

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved