AIToday
Snowflake AI BlogPublished: Aug 2, 2026, 22:01 JST6 min read

Snowflake launches AI security suite, gateway for autonomous agents

Snowflake launches AI security suite, gateway for autonomous agents

Key takeaway

  • Snowflake has launched Cortex AI Gateway, a centralized control platform for managing autonomous AI agents across enterprise systems, alongside a suite of production-grade security features including Agent Identity, data exfiltration prevention and ransomware protection.

  • The announcement comes as AI security concerns have risen to 48% in 2026 from 17% in 2024, while 57% of organizations report significant gaps in AI security and risk management despite 97% commitment to AI implementation.

3 Key Points

  1. What happened

    Snowflake announced Cortex AI Gateway—a centralized control layer for autonomous agents that enforces identity, policy and audit across AI model access, MCP (Model Context Protocol) servers and enterprise tools. The company also transitioned multiple native security features to general availability and preview, including Agent Identity, Native AI Security Posture Management, Data Exfiltration Prevention, and Ransomware Protection via Multi-Party Approval.

  2. Why it matters

    AI security concerns have surged from 17% in 2024 to 48% in 2026 according to The Linux Foundation's 2026 State of Tech Talent Report, yet 57% of organizations face a significant capacity gap in security and risk management. Autonomous agents have expanded the enterprise attack surface by combining data access, system execution and data movement, making centralized governance and visibility critical as 97% of organizations are committed to implementing AI.

  3. What to watch

    Cortex AI Gateway's key capabilities—Wide Model Catalog (private preview), Access Governance and Sprawl Control (private preview), Observability and Tracing (private preview), and AI Cost Control (private preview)—are currently in preview. Snowflake is demonstrating the suite at Black Hat USA 2026, booth #8206, with live demonstrations of the Gateway, Agent Identity controls and automated threat scanners in the Snowflake Trust Center.

In Depth

Read the full story

At Black Hat USA 2026, Snowflake unveiled a comprehensive security and governance platform designed to address the rapid expansion of autonomous agents in enterprise environments. The announcement centers on two major components: Cortex AI Gateway and a suite of production-grade AI security capabilities.

Cortex AI Gateway functions as a centralized control layer for agent interoperability. It integrates Natoma, described as a centralized MCP gateway, to enforce identity, policy and audit at the tool-call level across both Snowflake's native tools (CoCo and CoWork) and third-party ecosystems including Amazon Bedrock, Azure AI Foundry, ChatGPT, Claude Code, Cursor, custom LangChain and LlamaIndex applications, and others. The gateway governs access to a wide catalog of models including GPT, Gemini, Claude, Grok, Mistral and GLM. Key features include a Wide Model Catalog (private preview) allowing enterprises to run models in their own geography for data residency compliance; Access Governance and Sprawl Control (private preview) to reduce manual configuration of agent connections; and Govern Every Agent Connection (private preview), which supports discovery and monitoring of 100+ MCP servers with automatic detection of shadow AI.

On the visibility side, Cortex AI Gateway offers Observability and Tracing (private preview) to capture agent tool calls in real time for audit trails, and Agent Action Auditability (private preview) to provide end-to-end records of which systems an agent touched and in what sequence. For cost management, the platform features AI Cost Control (private preview) with unified consumption views by team, agent or workload, and Intelligent Model Routing (private preview) to automatically route requests based on cost, latency, capability and data residency, including prompt management.

Parallel to the Gateway, Snowflake transitioned several security capabilities to general availability and preview status. Agent Identity (GA) gives security teams visibility into agent activity and allows enforcement of data access policies that apply when an agent operates on behalf of a privileged user, with dedicated agent identity tracking in Account Usage views. Third-Party Agent Identity extends governance to external AI tools through integrations with security providers including 1Password, Aembit, Cyera, Linx Security, Okta, SailPoint and Saviynt. Restricted Session Scope (GA soon) limits agent sessions to only the permissions required for their task, preventing read-only analysis sessions from escalating privileges. Context-Aware Access Policies (private preview) apply zero-trust evaluation of identity, network and client context in a single expression.

Snowflake also advanced its security posture capabilities. Native AI Security Posture Management (GA) is now integrated into the Snowflake Trust Center, providing a comprehensive dashboard for security operations teams to scan for AI-specific configuration risks, assess compliance against emerging global regulations and deploy programmatic remediations. For data protection, the company launched its Data Exfiltration Prevention (DXP) package in preview, pairing real-time telemetry with strict data movement policies to detect and intercept unauthorized data flows, including sensitive data fetches triggered by AI agents, unauthorized data routing to internal or external stages, and mass downloads via user interfaces. The Client-side CoCo CLI VM Sandbox (private preview, currently macOS) isolates each CoCo development session in a separate Linux kernel, shielding credentials and local storage from client-side AI workloads. Ransomware Protection via Multi-Party Approval (MPA) reached GA status, requiring two or more authorizations before any destructive system change can proceed to prevent unilateral data wipe or configuration alteration even if top-tier administrative credentials are compromised.

The context for this release is urgent. According to The Linux Foundation's 2026 State of Tech Talent Report, AI security concerns have surged from 17% in 2024 to 48% in 2026. While 97% of organizations are committed to implementing AI, 57% face a significant capacity gap in security and risk management. The underlying problem is structural: autonomous agents have dramatically expanded the enterprise attack surface by combining data access, system execution and data movement into a single workflow, and traditional application-layer fixes and legacy monitoring are insufficient. Snowflake's framing emphasizes that security must be built directly into the data and control planes rather than applied as an external wrapper.

Context & Analysis

The announcement reflects a fundamental shift in enterprise AI risk. According to The Linux Foundation's 2026 State of Tech Talent Report cited in the article, AI security concerns have climbed to 48% from 17% in 2024—a three-fold increase that underscores the maturity crisis facing organizations. The gap is stark: while 97% of organizations are committed to AI implementation, 57% lack adequate capacity in security and risk management, creating a widening vulnerability window.

Autonomous agents, now becoming the operational norm, have dramatically reshaped the attack surface. By consolidating data access, system execution and data movement into a single workflow, agents bypass the traditional perimeter-defense model. Snowflake's diagnosis—that "a patchwork of application-layer fixes and legacy monitoring tools is no longer enough"—mirrors the industry's slow recognition that security must move into the data and control planes rather than remain an external wrapper.

Cortex AI Gateway addresses this by centralizing governance of MCP (Model Context Protocol) adoption, which has become the de facto standard for connecting language models to enterprise databases and tools. The integration of Natoma, a centralized MCP gateway, into Snowflake's ecosystem provides the kind of unified policy enforcement—identity, tool-call audit, cost visibility—that fragmented deployments cannot offer. The suite's depth (100+ MCP servers, integration with third-party identity providers like Okta and 1Password) suggests Snowflake is moving beyond point solutions toward foundational infrastructure for the agent-first enterprise.

FAQ

What is Cortex AI Gateway and what does it do?
Cortex AI Gateway is a centralized control layer that governs how AI agents access models, data, MCP servers and enterprise tools. It provides control (grant, restrict and audit access from a single endpoint), visibility (capture agent tool calls in real time with audit trails), and cost management (route requests to the right model based on cost, latency and capability).
Which AI models and platforms does Cortex AI Gateway support?
The Gateway supports a wide range of models and platforms including GPT, Gemini, Claude, Grok, Mistral, GLM, and can govern both first-party tools (Snowflake CoCo and CoWork) and third-party ecosystems such as Amazon Bedrock, Azure AI Foundry, ChatGPT, Claude Code, Cursor, and custom LangChain or LlamaIndex apps.
What security features are now available or in preview?
Agent Identity (GA) provides visibility into agent activity and allows enforcement of data access policies specific to agent sessions. Restricted Session Scope (GA soon) limits what an agent can do to only task requirements. Native AI Security Posture Management (GA) scans for AI-specific risks and compliance issues. Data Exfiltration Prevention, Context-Aware Access Policies, Client-side CoCo CLI VM Sandbox and Ransomware Protection via Multi-Party Approval (GA) are in preview or recently launched.
Snowflake AI BlogRead Original Article

Get AI news like this every morning

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytime

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Next articleBayeswatch: 2021 sci-fi story imagined AI treaty, now echoed in AI 2027

The AI news that matters, in one minute each morning.

Sign up free