Share with your CISO
Snowflake is betting that the governance gap in enterprise AI agents, specifically the inability to see what an agent touched, under whose authority, and at what cost, is the defining security problem of the next two years. Its answer is Cortex AI Gateway, built on its May acquisition of MCP governance startup Natoma Labs and launching in public preview soon. The product centralizes access policy, end-to-end audit logging, and token-cost attribution across both Snowflake-native agents and third-party agents from platforms like Claude Code and Cursor, with identity integrations from 1Password, SailPoint, and Saviynt already lined up.
What this means for your business
The organization most exposed here is the one that has already let agents into production without solving identity. The recurring failure mode looks like this: an agent inherits a user’s broad credentials, completes a task, and leaves no clean record of which system it touched or why. When something goes wrong, security teams have logs from five different platforms and no single thread connecting them. If your agent deployments today rely on long-lived service account credentials rather than task-scoped, short-lived access, Cortex AI Gateway is describing your gap whether or not you buy Snowflake’s answer to it.
The MCP angle deserves attention beyond the product announcement. Model Context Protocol is the emerging standard that lets AI agents call external tools and data sources in a structured way, roughly analogous to how APIs standardized application-to-application communication a decade ago. Snowflake supporting more than 100 MCP servers through a single governance layer is a land-grab for the control plane position, the chokepoint through which agent activity flows and therefore the natural place to enforce policy. If MCP becomes the dominant agent-to-tool interface, whoever owns the governance layer above it owns the audit trail enterprises will eventually be required to produce for regulators.
The cost-attribution piece is underrated and will matter faster than most CISOs expect. Token consumption across dozens of agents running at scale produces bills that arrive before anyone has mapped which business process generated them. Snowflake is positioning spend visibility alongside access control in the same product, which is smart because the CFO and the CISO will both come looking and finding only one of them served is a support ticket waiting to happen. The falsification condition here is whether the gateway’s telemetry, the detailed system data showing what agents did and spent, proves accurate enough under adversarial conditions to hold up in an incident review. If it doesn’t, the audit log becomes a liability rather than a defense.
Concept deep-dive: Model Context Protocol (MCP)
MCP is a specification that gives AI agents a standardized way to call external tools, read from data sources, and take actions in outside systems, much like a universal adapter that lets any agent plug into any compatible service without custom wiring. It exists because agents built on different platforms were otherwise incompatible with each other’s tool ecosystems. For security teams, MCP creates a defined interface where policy can actually be enforced, which is why governance at the MCP layer is the right architectural place to start.
Based on reporting from Snowflake debuts Cortex AI Gateway to govern and monitor enterprise AI agents, originally published 2026-07-28 09:00:00.

