Snowflake introduces Cortex AI Gateway and other AI security

WorkAI.TV Editorial Desk
4 Min Read

Share with your CISO

Snowflake is betting that the agentic enterprise needs a dedicated control plane, and it’s positioning itself as that plane with Cortex AI Gateway, announced alongside integrations with Okta, SailPoint, and four other identity and access vendors. Built on the May 2026 Natoma acquisition, the gateway centralizes how AI agents, including third-party agents from external platforms, authenticate, access data, invoke tools, and consume model tokens. The cost-visibility angle matters too: Cortex AI Gateway attributes token spend by team, agent, and workload, and can enforce spending limits before budgets run over.

What this means for your business

The CISO who hasn’t yet drawn a governance boundary around AI agents is the person this announcement is aimed at. Right now, most enterprise AI deployments have an identity problem that’s easy to miss: agents often inherit the full permissions of the user who invoked them, meaning a task-scoped assistant quietly carries the access rights of a senior engineer or a finance director. If your organization is running any third-party agents against Snowflake data, that exposure is almost certainly not visible in your current audit logs.

Snowflake’s framing here is sharper than a typical platform extension, though the company obviously benefits from positioning Snowflake as the mandatory transit layer for every agent interaction in your stack. The specific tilt worth watching is the MCP (Model Context Protocol, the emerging standard that lets AI agents discover and call external tools the way a browser calls a website) angle. Claiming support for over 100 MCP servers is a meaningful number if it holds up to enterprise vetting, because MCP is where the real identity sprawl will happen as agents start chaining tool calls across systems. The Natoma acquisition suggests Snowflake has real engineering depth here rather than a roadmap slide.

The falsification condition for this bet is straightforward. Cortex AI Gateway only matters as a control plane if agents from platforms like Anthropic’s Claude Code or Microsoft Copilot actually route through it, which requires those vendors to accept Snowflake’s governance layer sitting between their product and your data. Vendors with their own platform ambitions have every incentive to resist that. If the ecosystem integrations stay narrow, what looks like a universal agent gateway becomes a Snowflake-native agent gateway, useful but not the architectural chokepoint the announcement implies. Watch which non-Snowflake agent platforms formally certify the integration in the next two quarters.

Concept deep-dive: Agent identity and task-scoped access

Traditional access controls assume a human logs in and gets a permission set. AI agents break that model because they act autonomously, often chaining multiple tool calls without a human approving each step. Task-scoped access means an agent receives only the specific permissions needed for a defined task, expiring when the task ends, rather than inheriting a user’s full credential set. Think of it as a contractor badge that works only in one room for one shift. For security teams, this is the difference between a manageable audit trail and an ungovernable blast radius.

Based on reporting from Snowflake introduces Cortex AI Gateway and other AI security, originally published 2026-07-31 07:48:00.

TAGGED:
Share This Article