
Snowflake has launched Cortex AI Gateway, a centralized control system for managing autonomous AI agents across enterprise environments, addressing a surge in AI security concerns that have risen to 48% in 2026.
The gateway enforces identity, policy, and audit controls at the tool-call level, giving enterprises visibility and cost control over agent activity while preventing unauthorized data access and tool hijacking.
The announcement also includes the general availability of Agent Identity and other production-grade security features built directly into Snowflake's data and control infrastructure.
What happened
Snowflake announced Cortex AI Gateway, a centralized control layer for AI agents that integrates Natoma (an MCP gateway) into its ecosystem. The company also transitioned multiple AI security features to general availability and public preview, including Agent Identity, Restricted Session Scope, Native AI Security Posture Management, and Ransomware Protection via Multi-Party Approval.
Why it matters
AI security concerns have jumped from 17% in 2024 to 48% in 2026 according to The Linux Foundation's 2026 State of Tech Talent Report, while 97% of organizations are committed to implementing AI but 57% face a significant capacity gap in security and risk management. Autonomous agents have dramatically expanded the enterprise attack surface by combining data access, system execution, and data movement; Cortex AI Gateway addresses this by enforcing identity, policy, and audit at the tool-call level across first-party and third-party models and platforms.
What to watch
Cortex AI Gateway is available now as a foundation layer; several features including Wide Model Catalog, Access Governance and Sprawl Control, Observability and Tracing, AI Cost Control, Intelligent Model Routing, Context-Aware Access Policies, and Client-side CoCo CLI VM Sandbox are in private preview. Visit Snowflake booth #8206 at Black Hat USA 2026 for demonstrations.
At Black Hat USA 2026, Snowflake announced Cortex AI Gateway alongside a set of production-grade AI security features, responding to a marked shift in enterprise AI risk awareness. According to The Linux Foundation's 2026 State of Tech Talent Report, AI security concerns have surged from 17% in 2024 to 48% in 2026. The gap between adoption and preparedness is stark: 97% of organizations are committed to implementing AI, yet 57% face a significant capacity gap in security and risk management.
The core challenge Snowflake addresses is the explosion of autonomous agents. As enterprises rapidly adopt agent standards like MCP to connect large language models to databases, internal tools, and SaaS environments, they encounter what Snowflake describes as a "hard problem: fragmented access, no visibility into what agents are doing and AI costs spiraling out of control." Autonomous agents have dramatically expanded the enterprise attack surface by combining data access, system execution, and data movement into a single profile, and a patchwork of application-layer fixes and legacy monitoring tools is no longer sufficient. Snowflake's answer is Cortex AI Gateway, which integrates Natoma—a centralized MCP gateway—into its ecosystem to enforce identity, policy, and audit at the tool-call level. The gateway governs how AI agents access models, data, MCP servers, and enterprise tools, covering both first-party solutions (Snowflake CoCo and CoWork) and third-party ecosystems (Amazon Bedrock, Azure AI Foundry, ChatGPT, Claude Code, Cursor, custom LangChain or LlamaIndex apps, and others). According to Snowflake, Cortex AI Gateway delivers three capabilities: Control (grant, restrict, and audit model and tool access from a single endpoint using fine-grained authorization); Visibility (capture agent tool calls in real time, showing which tool was called, which system it touched, in what order, and by whom, with comprehensive audit trails for usage tracking and forensics); and Cost and performance (route requests automatically to the right model based on cost, latency, capability, and data residency, and enforce spending limits by team, agent, or workload before costs escalate).
Cortex AI Gateway is positioned as the first milestone on Snowflake's AI gateway roadmap. Several features are available now, while others are in private preview: Wide Model Catalog (bringing GPT, Gemini, Claude, Grok, Mistral, GLM and more under one roof to run in the user's geography), Access Governance and Sprawl Control (reducing the need for manual configuration across dozens of emerging agent types), Govern Every Agent Connection (providing access and data policies, authentication, fine-grained authorization, and permissions across 100+ MCP servers, including bring-your-own and VPC connect options, with automatic discovery and monitoring of shadow AI), Observability and Tracing (securely capturing agent tool calls in real time for comprehensive audit trails), Agent Action Auditability (providing end-to-end records of agent actions), AI Cost Control (unifying AI consumption visibility by team, agent, or workload, with budget guardrails and prompt management), and Intelligent Model Routing (automatically routing requests based on cost, latency, capability, and data residency requirements).
Snowflake is also advancing its native AI security posture by transitioning multiple features to general availability and public preview. Agent Identity is now GA, enabling security and governance teams to enforce data access policies specific to agent sessions and track agent activity in Account Usage views for auditing. Restricted Session Scope will be GA soon, limiting what an agent session can do to only what the task requires—so a read-only analysis stays read-only even if the underlying user role normally allows more. Third-Party Agent Identity extends these governance frameworks to external AI tools through integrations with 1Password, Aembit, Cyera, Linx Security, Okta, SailPoint, and Saviynt. Native AI Security Posture Management is now GA, integrating into the Snowflake Trust Center to provide a comprehensive dashboard for proactively scanning AI-specific risks, assessing compliance postures against emerging global regulations, and deploying programmatic remediations for misconfigurations. Context-Aware Access Policies are in private preview, offering zero-trust controls that allow security admins to author a single policy evaluating identity, network, and client context jointly. Advanced Data Exfiltration Prevention is in preview via the Trust Center, pairing real-time telemetry with strict data movement policies (GA) to detect and intercept unauthorized data flows—flagging and blocking sensitive data fetches triggered by AI agents, unauthorized data routing to internal or external stages, and mass data downloads via user interfaces. Client-side CoCo CLI VM Sandbox is in private preview, isolating each CoCo session in a separate Linux kernel from the host operating system, with availability as an admin-enforced or self-managed control currently on macOS. Ransomware Protection via Multi-Party Approval is now GA, requiring two or more authorizations before any destructive system change, preventing single-point-of-failure scenarios where hijacked administrative credentials could allow unilateral data deletion or configuration alteration. Snowflake invited attendees to booth #8206 at Black Hat USA 2026 to experience demonstrations of Cortex AI Gateway, AI Agent Identity controls, and automated threat scanners built into the Snowflake Trust Center.
The announcement reflects a critical shift in enterprise AI risk perception. According to The Linux Foundation's 2026 State of Tech Talent Report cited in the body, AI security concerns have jumped from 17% in 2024 to 48% in 2026—a near-tripling that underscores growing anxiety about deploying AI agents at scale. This concern is well-founded: the body notes that while 97% of organizations are committed to implementing AI, 57% face a significant capacity gap in security and risk management. The core problem Snowflake targets is the rapid proliferation of autonomous agents using standards like MCP to connect to databases, internal tools, and SaaS environments. Without centralized governance, this creates what the body calls "unmanaged sprawl, fractured user experiences and severe security liabilities," leaving organizations vulnerable to unvetted servers, tool hijacking, and data exfiltration. By integrating Natoma—a centralized MCP gateway—into its ecosystem, Snowflake aims to place security enforcement at the tool-call level rather than relying on application-layer fixes and legacy monitoring tools, which the body suggests are no longer sufficient.
The feature roadmap emphasizes three pillars: control (centralized access management), visibility (real-time auditing of agent actions), and cost governance (automatic model routing and budget guardrails). Supporting these capabilities is a suite of native security features transitioning to production readiness, including Agent Identity (now GA), Restricted Session Scope (GA soon), and Native AI Security Posture Management (GA)—all designed to address what the body frames as the need to "build security directly into the data and control planes" rather than layering it on top. The announcement positions Cortex AI Gateway as a foundation milestone on a longer AI gateway roadmap, suggesting Snowflake views this as the first step in a broader security architecture for the "agentic enterprise."
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
Ask AI anything about this article. Q&As are published on this page for other readers too.
The AI news that matters, in one minute each morning.
Sign up free