Snowflake launches AI Gateway and security capabilities for enterprise AI agents, ETCISO

WorkAI.TV Editorial Desk
4 Min Read

Share with your CISO

Snowflake is betting that the emerging chaos of enterprise AI agents, dozens of them hitting production with no unified identity, access policy, or cost attribution, is a governance problem it can own. The company’s Cortex AI Gateway centralizes control over both native Snowflake agents and third-party ones like Claude Code and Cursor, covering authentication, permissions, and access policies across more than 100 MCP servers. Integrations with Okta, SailPoint, and Aembit extend identity governance to agents built outside Snowflake’s walls. The Natoma acquisition, closed May 2026, provided the MCP foundation underneath all of it.

What this means for your business

The CISO who already owns identity governance for humans is now inheriting the same problem for machines, and the window to get ahead of it is closing fast. If your organization is running AI agents in production today, even a handful, they almost certainly have broader data access than any human employee would be granted under least-privilege rules. Most enterprises discovered shadow IT after the fact; agent sprawl is the same pattern running at software speed. Whether Snowflake is your data platform or not, the question this announcement forces is whether you have any centralized answer at all for agent identity, and most teams don’t.

The deeper play here is that Snowflake is trying to become the identity plane for AI agents the way Active Directory became the identity plane for users. That is a much larger strategic claim than “we secured our own agents.” By supporting third-party agents through MCP, a protocol that lets AI systems describe and request tool access, Snowflake is positioning the gateway as infrastructure-layer control rather than a Snowflake-native feature. The vendor ecosystem it assembled, Okta, SailPoint, Saviynt, are names that live in enterprise security budgets already, which makes the integration story credible to a CISO reviewing a purchase.

The falsification condition is interoperability. Cortex AI Gateway’s value proposition collapses if MCP adoption fragments into competing standards or if hyperscalers ship their own agent control planes that enterprises naturally consolidate onto. Microsoft and Google both have strong reasons to own this layer. If your agent portfolio runs predominantly on Azure or Google Cloud, Snowflake’s gateway becomes a second control plane rather than the single one, which reintroduces exactly the visibility gap it promises to close. Renewing your Snowflake contract with the expectation that this becomes your agent governance layer is a reasonable call now, but it should hinge on whether your agent inventory actually lives where Snowflake can see it.

Concept deep-dive: Model Context Protocol (MCP)

MCP is a standard that lets AI agents describe what tools and data sources they need access to, and request permission to use them in a structured, auditable way. Think of it as OAuth for AI agents, the same basic idea that lets you log into a website using your Google account, applied to an agent asking permission to query a database or call an API. Without a shared protocol like this, every agent-to-system connection is a custom, ungoverned integration, which is why MCP becoming a control point matters to enterprise security teams.

Based on reporting from Snowflake launches AI Gateway and security capabilities for enterprise AI agents, ETCISO, originally published 2026-07-28 23:37:00.

TAGGED:
Share This Article