AIToday
Large Language ModelsAI Regulation & PolicyAI Business & IndustrySnowflake AI BlogPublished: Aug 24, 2026, 16:01 JST2 min read

Snowflake CoCo expands AI governance with cost, access, and tool controls

Snowflake CoCo expands AI governance with cost, access, and tool controls

Key takeaway

  • Snowflake has expanded AI governance in CoCo with new cost, access, and tool controls. Per-user quotas are now generally available.

  • Three additional layers are coming soon.

  • These controls aim to give administrators more visibility and builders more freedom.

3 Key Points

  1. What happened

    Snowflake CoCo now offers per-user AI credit quotas that are generally available, and introduced three new governance layers—managed settings, agent profiles, and restricted session scope—which will be generally available soon.

  2. Why it matters

    These controls let administrators define boundaries for AI costs, access, behavior, and external tool connections, making it easier to open CoCo broadly across organizations while maintaining security and auditability.

  3. What to watch

    The new Cortex AI Gateway, built on Snowflake's Natoma acquisition, provides server-level allowlisting, tool-level policy, rate limits, and audit trails for MCP servers, with governance policies defined in the Horizon Catalog.

Ask the AI about this article →

Context & Analysis

In July, Snowflake outlined a vision for governing AI costs, grounding AI in enterprise context, and bringing trusted AI to work. This launch delivers on that vision by expanding governance beyond cost to access, behavior, and tooling. Administrators can now set per-user quotas, enforce organization-wide policies via managed settings, define defaults with agent profiles, and constrain agent actions with restricted session scope. These controls address common security review questions, potentially reducing the need for sandboxes and manual approvals. For builders, the governance layer is designed to be invisible in normal use, surfacing only when an action would be problematic. External tool access through the Cortex AI Gateway adds another layer of control and auditability, built on Snowflake's Natoma acquisition. This holistic approach aims to balance security with developer productivity, enabling broader AI adoption within enterprises.

FAQ

When will the new governance layers be available?
The three new capabilities—managed settings, agent profiles, and restricted session scope—are generally available soon. Per-user quotas are available today.
What does restricted session scope do?
Restricted session scope constrains what SQL an agent can run until an appropriate role is active in the session, reducing the blast radius of agent actions.
How does the Cortex AI Gateway help with tool access?
It provides server-level allowlisting, tool-level policy, rate limits, and a comprehensive audit trail for MCP server connections, with policies defined in the Horizon Catalog.
Snowflake AI BlogRead Original Article

Get the latest Large Language Models news every morning

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytime

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleCyberAgent creates AI-first unit AIX Design Office

The AI news that matters, in one minute each morning.

Sign up free