Snowflake Cortex AI Gateway aims to govern enterprise AI agents
Snowflake is adding a control layer for AI agents, with identity partners helping limit data access, audit actions and track costs.
By Colin Brandt · Enterprise Reporter
· 4 min read
Snowflake Cortex AI Gateway is the company’s new control layer for enterprise AI agents, including agents built outside Snowflake on tools such as Anthropic’s Claude Code and Cursor. Snowflake said the gateway will govern how those agents reach company data, tools and models, while giving IT and finance teams a way to see and limit AI consumption before costs run away.
The launch extends Snowflake’s pitch beyond storing and processing enterprise data. The company is trying to put itself in the path between autonomous agents and the sensitive systems they use. Snowflake announced initial security integrations with 1Password, Aembit, Linx Security, SailPoint and Saviynt, a group of identity and access vendors that often compete for the same enterprise budgets.
What is Snowflake Cortex AI Gateway?
Cortex AI Gateway is a centralized access and policy layer for what Snowflake calls trusted agent activity. It covers agents built inside Snowflake, including Snowflake CoWork and CoCo, as well as third-party agents built on external platforms.
Snowflake said the gateway will support more than 100 MCP servers. MCP, or Model Context Protocol, is a connector standard used to wire AI agents into business tools and data systems. Through the gateway, Snowflake plans to centralize authentication, permissions, policy enforcement and audit logs rather than leaving each agent integration to handle those controls separately.
The product will enter public preview soon, according to Snowflake. The partner integrations are set for private preview. Snowflake did not provide customer adoption numbers for the gateway.
Why Snowflake is pushing agent governance now
Snowflake’s security argument is straightforward: enterprise access systems were built around human users, while agents can make many tool calls across systems at machine speed. Mayank Upadhyay, Snowflake’s chief security and trust officer, told VentureBeat that AI agents expose existing blind spots in enterprise security because they can combine permissions that were not designed to be used together.
1Password CTO Nancy Wang told VentureBeat that giving an agent a person’s credentials creates obvious failure modes, especially when the human has administrative access. She said the audit problem is just as serious: logs may show that a person took an action when the action was actually performed by an agent operating on that person’s behalf.
Snowflake and its partners are using a model the company calls dual attribution. Under that approach, logs record both the non-human identity of the agent and the human who approved the task. The goal is task-scoped access, where an agent receives only the permissions needed for a specific job instead of inheriting a user’s full standing access.
How the gateway addresses AI spending
Cost control is part of the product, not a side feature. Snowflake said the gateway will show AI usage by team, agent or workload and enforce spending limits. Upadhyay told VentureBeat that agent workloads can become expensive when a simple request is routed through a pricier reasoning model, triggers extra searches or launches unnecessary workflows.
The gateway builds on Snowflake’s May 2026 acquisition of Natoma, a 27-person startup focused on centralized MCP governance at the tool-call level. Forbes reported that Snowflake announced the Natoma deal on the same day it reported $1.33 billion in quarterly product revenue and disclosed a $6 billion AWS compute commitment.
SailPoint CTO Chandra Gnanasambandam told VentureBeat that enterprises are already seeing scale problems with non-human identities. He said SailPoint has more than 100 customers using its agent identity product and is seeing human-to-non-human identity ratios of at least 10 to 1, before counting the tools and APIs each agent touches.
The broader market is moving in the same direction. Gartner has predicted that by 2027, governance gaps found after production incidents will cause 40% of enterprises to demote or shut down autonomous AI agents. IDC expects more than 1 billion deployed AI agents by 2029, performing about 217 billion actions per day, and forecasts agentic AI will account for more than $1.3 trillion in worldwide IT spending that year.
For Snowflake, the strategic bet is that proximity to enterprise data gives it leverage in agent governance. The risk for customers is concentration: a governance layer inside Snowflake may work cleanly for Snowflake-heavy environments, while multi-vendor agent stacks will have to test how open that control plane remains in practice.
This story draws on original reporting from VentureBeat.