
Snowflake has launched Cortex AI Gateway at Black Hat 2026, a centralized control platform that governs how autonomous AI agents access models, data and enterprise tools across multiple ecosystems—addressing a critical gap as AI security concerns jumped from 17% to 48% between 2024 and 2026.
The platform integrates Natoma to enforce identity, policy and audit at the tool-call level, while new production-grade security capabilities (Agent Identity, Restricted Session Scope, Native AI Security Posture Management, Ransomware Protection via Multi-Party Approval) help enterprises scale agents safely by reducing unmanaged sprawl, providing real-time visibility into agent actions and automatically controlling AI consumption costs.
What happened
At Black Hat 2026, Snowflake announced Cortex AI Gateway—a centralized control layer integrating Natoma (an MCP gateway) to govern autonomous agent access to models, data and enterprise tools across first-party (Snowflake CoCo, CoWork) and third-party systems (Amazon Bedrock, Azure AI Foundry, ChatGPT, Claude). The company also moved several native AI security capabilities to general availability and public preview, including Agent Identity (GA), Restricted Session Scope (GA soon), Native AI Security Posture Management (GA), Ransomware Protection via Multi-Party Approval (GA), and Data Exfiltration Prevention (preview).
Why it matters
AI security concerns surged from 17% in 2024 to 48% in 2026 according to The Linux Foundation's 2026 State of Tech Talent Report, yet 97% of organizations commit to implementing AI while 57% face a significant capacity gap in security and risk management. Autonomous agents have dramatically expanded the enterprise attack surface by combining data access, system execution and data movement; Cortex AI Gateway directly addresses the hard problem enterprises face—fragmented access, no visibility into agent actions and spiraling AI costs—by enforcing identity, policy and audit at the tool-call level and providing cost control and intelligent model routing.
What to watch
Cortex AI Gateway is available in core form; multiple features (Wide Model Catalog, Access Governance and Sprawl Control, Observability and Tracing, AI Cost Control, Intelligent Model Routing, Context-Aware Access Policies, Advanced Data Exfiltration Prevention, Client-side CoCo CLI VM Sandbox) are in private preview. Snowflake is demonstrating capabilities at Black Hat USA 2026, booth #8206.
At Black Hat 2026, Snowflake announced Cortex AI Gateway, a centralized control and governance layer designed to manage the growing complexity and risk of autonomous agent deployments across enterprise systems. The gateway integrates Natoma, an MCP (Model Context Protocol) gateway, to enforce identity, policy and audit controls at the point where AI agents call tools—addressing a hard problem enterprises now face: fragmented agent access, invisible tool usage, and exploding AI costs.
Cortex AI Gateway provides three core capabilities. Control allows teams to grant, restrict and audit model and tool access from a single endpoint instead of manually configuring each new agent type, supporting fine-grained authorization across 100+ MCP servers. Visibility captures agent actions in real time—which tool was called, which system it touched, in what order and by whom—feeding comprehensive audit trails for security and compliance. Cost and performance includes automatic model routing based on cost, latency, capability and data residency, plus budget guardrails by team, agent or workload. Several features—Wide Model Catalog (bringing GPT, Gemini, Claude, Grok, Mistral, GLM and others under unified governance), Access Governance and Sprawl Control, Observability and Tracing, AI Cost Control, and Intelligent Model Routing—are in private preview.
Snowflake complemented this new gateway with a suite of AI security capabilities moving into general availability and public preview. Agent Identity (GA) enables governance teams to enforce data access policies specific to agent sessions, preventing sensitive data access even when agents run on behalf of privileged users; third-party agent identity integrations with security vendors (1Password, Aembit, Cyera, Linx Security, Okta, SailPoint, Saviynt) extend the same policies to external AI tools. Restricted Session Scope (GA soon) limits what an agent can do to only what the task requires, ensuring read-only analysis stays read-only. Native AI Security Posture Management (GA) now fully integrates proactive risk scanning, compliance assessment and programmatic remediation into the Snowflake Trust Center. Ransomware Protection via Multi-Party Approval (GA) requires two or more authorizations before destructive system changes, removing single points of failure from sensitive architecture. Advanced Data Exfiltration Prevention (preview) pairs real-time telemetry with strict data movement policies to detect and block unauthorized sensitive data fetches triggered by agents, unauthorized data routing and mass downloads. Client-side CoCo CLI VM Sandbox (private preview) isolates AI-assisted development workflows in separate Linux kernels on macOS, minimizing credential and local storage exposure to AI workloads.
The announcement arrived as AI security concerns surged from 17% in 2024 to 48% in 2026, according to The Linux Foundation's 2026 State of Tech Talent Report. While 97% of organizations report commitment to implementing AI, 57% face significant capacity gaps in security and risk management. Autonomous agents have accelerated this pressure by expanding the attack surface—combining data access, system execution and data movement creates new vectors for tool hijacking, data exfiltration and cost runaway that legacy monitoring tools and application-layer patches cannot address. Snowflake positioned Cortex AI Gateway as foundational: by moving security controls into the data and AI infrastructure planes themselves rather than bolting them on afterward, enterprises can scale agent deployments without sacrificing visibility, governance or cost control. Demonstrations and product team details are available at the Snowflake booth (#8206) at Black Hat USA 2026.
Enterprise AI adoption is accelerating but outpacing security maturity. The gap between deployment commitments and governance readiness—97% of organizations committed to AI yet 57% facing significant capacity gaps in security—creates real operational risk. Autonomous agents amplify this exposure: by consolidating data access, system execution and data movement into single profiles, they have expanded the attack surface dramatically. Traditional defenses—fragmented application-layer fixes and legacy monitoring tools—cannot keep pace.
Snowflake's announcement reflects this inflection. Cortex AI Gateway targets the precise friction point enterprises encounter as agent adoption scales: decentralized tool connections via MCP standards create unmanaged sprawl, tool hijacking vulnerabilities, unvetted data exfiltration pathways, and invisible cost blowout. By centralizing control at the MCP gateway level—integrating Natoma to enforce identity, policy and audit before agent tool calls execute—the platform shifts from reactive fixes to preventive architecture. The complementary security stack (Agent Identity, Restricted Session Scope, context-aware policies, exfiltration detection, multi-party approval for destructive changes) extends governance into agent sessions themselves, not just user sessions.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
Ask AI anything about this article. Q&As are published on this page for other readers too.
Foxconn announced on August 12 at its second-quarter 2026 earnings conference that it is broadening its busine…

Pegatron reported strong server business growth in Q2 2026 and said it has begun stocking inventory for H2 202…

China's high-end AI chip market is projected to reach nearly 90% domestic market share in 2026, leaving overse…

Pegatron reported second-quarter 2026 results on the 12th, with net profit attributable to the parent company…

South Korea plans to establish a strategic investment account with at least 20 trillion won in assets within t…

Foxconn's second-quarter 2026 operating profit rose 68%, driven by stronger-than-expected revenue in its AI se…

The AI news that matters, in one minute each morning.
Sign up free