
Snowflake has introduced Cortex AI Gateway, a centralized control system for autonomous AI agents that integrates governance, security, and cost management across multiple AI platforms and enterprise tools. The announcement comes as AI security concerns have surged to 48% in 2026, up from 17% in 2024, while 57% of organizations struggle with security and risk management capacity as agents expand the attack surface. The platform extends Snowflake's data governance to agent traffic, offering real-time visibility into agent actions, centralized access policies, and cost controls across models including GPT, Gemini, Claude, and others.
Summaries like this, in your inbox every morning.
Sign up free →What happened
At Black Hat 2026, Snowflake announced Cortex AI Gateway—a centralized control layer for autonomous agents that enforces identity, policy and audit across MCP (Model Context Protocol) connections—alongside a suite of production-ready security features including Agent Identity controls, Data Exfiltration Prevention, and Native AI Security Posture Management.
Why it matters
AI security concerns have jumped from 17% in 2024 to 48% in 2026, yet 57% of organizations face a significant capacity gap in security and risk management. Autonomous agents now expand the enterprise attack surface by combining data access, system execution and data movement; Snowflake's integrated approach aims to let enterprises scale agents safely without patchwork tools, while controlling costs and maintaining governance across 100+ MCP servers and multiple AI platforms (GPT, Gemini, Claude, Grok, Mistral, GLM).
What to watch
Cortex AI Gateway features including Wide Model Catalog, Access Governance and Sprawl Control, Observability and Tracing, AI Cost Control and Intelligent Model Routing are currently in private preview; Restricted Session Scope and Context-Aware Access Policies are in private preview or coming to GA soon. Snowflake will demonstrate the new tools at Black Hat USA 2026 booth #8206.
At Black Hat 2026, Snowflake announced Cortex AI Gateway and a comprehensive set of AI security advancements aimed at enabling enterprises to scale autonomous agents safely. The announcement arrives against a backdrop of surging security concerns: AI security anxiety has climbed from 17% in 2024 to 48% in 2026, according to The Linux Foundation's 2026 State of Tech Talent Report, yet 97% of organizations remain committed to implementing AI—a mismatch that leaves 57% facing a significant capacity gap in security and risk management.
Cortex AI Gateway integrates Natoma, a centralized MCP (Model Context Protocol) gateway, into Snowflake's ecosystem to serve as the connective layer for all trusted agent activity. It governs access for both first-party tools (Snowflake CoCo and CoWork) and third-party ecosystems (Amazon Bedrock, Azure AI Foundry, ChatGPT, Claude Code, Cursor, custom LangChain or LlamaIndex apps, and others). The gateway provides three core capabilities: centralized control over model and tool access via fine-grained authorization; real-time visibility into agent actions captured in audit trails showing which tool was called, which system it touched, in what order and by whom; and intelligent cost management through automatic request routing based on cost, latency, capability and data residency requirements, with spending limits by team, agent or workload. Features in private preview include Wide Model Catalog (covering GPT, Gemini, Claude, Grok, Mistral, GLM and more), Access Governance and Sprawl Control, Observability and Tracing, Agent Action Auditability, AI Cost Control and Intelligent Model Routing that can enforce geographic data residency.
Complementing the gateway, Snowflake is advancing a defense-in-depth security stack. Agent Identity controls are moving to general availability, enabling security teams to enforce data access policies specific to agent sessions and track agent activity in Account Usage views for auditing. Third-Party Agent Identity integrations with security innovators including 1Password, Aembit, Cyera, Linx Security, Okta, SailPoint and Saviynt extend the same governance policies to external AI tools. Restricted Session Scope (coming to GA soon) limits agent sessions to only the permissions required for their task—for example, keeping a read-only analysis read-only even if the underlying user role permits broader actions. Native AI Security Posture Management (GA) integrates continuous configuration risk scanning directly into the Snowflake Trust Center, allowing security operations teams to proactively identify AI-specific risks, assess compliance postures against emerging regulations, and deploy programmatic remediations.
Snowflake is also introducing zero-trust data exfiltration controls. Data Exfiltration Prevention (in preview) pairs real-time telemetry with strict data movement policies to detect and intercept unauthorized data flows before they exit the ecosystem, flagging and blocking sensitive data fetches triggered by AI agents, unauthorized data routing to internal or external stages, and mass data downloads via user interfaces. Client-side CoCo CLI VM Sandbox (private preview) isolates each CoCo session in a separate Linux kernel, minimizing exposure of credentials, local storage or networks to client-side AI workloads; it is currently available on macOS as either an admin-enforced or self-managed control. Ransomware Protection via Multi-Party Approval (MPA) is now GA, requiring two or more authorizations before any destructive system change can proceed, helping protect against scenarios where top-tier administrative credentials are hijacked. Context-Aware Access Policies (private preview) allow security admins to author a single zero-trust policy that evaluates identity, network and client context jointly in one expression.
Snowflake will demonstrate Cortex AI Gateway, AI Agent Identity controls and the automated threat scanners at Black Hat USA 2026 booth #8206. The company positions these tools as the foundation for what it calls the "agentic enterprise," embedding security directly into the data and control planes so organizations can move confidently from prototype to production and deploy agents where they belong: inside the secure enterprise.
The shift in AI security concern from 17% to 48% reflects the growing realization that autonomous agents introduce new attack vectors. When agents combine data access, system execution, and data movement into a single operational profile, they create a significantly larger surface area than traditional application-layer security can address. Snowflake's announcement directly addresses this gap: 97% of organizations claim commitment to implementing AI, yet 57% lack the capacity to secure and manage it. By embedding governance into the data and control planes rather than bolting it on as an afterthought, Snowflake positions itself to help enterprises avoid the fragmentation problem—decentralized adoption of AI agents that creates sprawl, fractured user experiences, and severe security liabilities.
Cortex AI Gateway's core value lies in consolidation: instead of managing agent permissions across dozens of tools, platforms, and agent types individually, administrators can enforce policy, audit, and cost controls from a single endpoint covering 100+ MCP servers. The gateway also addresses a practical pain point: AI costs spiraling out of control through transparent routing and spending limits by team, agent, or workload. The announcement signals that Snowflake sees the agentic enterprise as inevitable, and intends to capture the governance layer where enterprises will be forced to invest as autonomous agents move from prototype to production.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
No discussion yet for this article
Get curated AI news from 200+ sources delivered daily to your inbox. Free to use.
Get Started FreeFree · takes 30 seconds · unsubscribe anytime