AIToday
Large Language ModelsAI Regulation & PolicyAI Business & IndustrySnowflake AI BlogPublished: Aug 24, 2026, 16:01 JST

Snowflake CoCo expands AI governance with cost, access, and tool controls

Snowflake CoCo expands AI governance with cost, access, and tool controls

3 Key Points

  1. What happened

    Snowflake CoCo now offers per-user AI credit quotas that are generally available, and introduced three new governance layers—managed settings, agent profiles, and restricted session scope—which will be generally available soon.

  2. Why it matters

    These controls let administrators define boundaries for AI costs, access, behavior, and external tool connections, making it easier to open CoCo broadly across organizations while maintaining security and auditability.

  3. What to watch

    The new Cortex AI Gateway, built on Snowflake's Natoma acquisition, provides server-level allowlisting, tool-level policy, rate limits, and audit trails for MCP servers, with governance policies defined in the Horizon Catalog.

Not sure about something? Ask the AI

Questions and answers are published on this page.

Summaries like this, in your inbox every morning.

Context & Analysis

In July, Snowflake outlined a vision for governing AI costs, grounding AI in enterprise context, and bringing trusted AI to work. This launch delivers on that vision by expanding governance beyond cost to access, behavior, and tooling. Administrators can now set per-user quotas, enforce organization-wide policies via managed settings, define defaults with agent profiles, and constrain agent actions with restricted session scope. These controls address common security review questions, potentially reducing the need for sandboxes and manual approvals. For builders, the governance layer is designed to be invisible in normal use, surfacing only when an action would be problematic. External tool access through the Cortex AI Gateway adds another layer of control and auditability, built on Snowflake's Natoma acquisition. This holistic approach aims to balance security with developer productivity, enabling broader AI adoption within enterprises.

FAQ
When will the new governance layers be available?
The three new capabilities—managed settings, agent profiles, and restricted session scope—are generally available soon. Per-user quotas are available today.
What does restricted session scope do?
Restricted session scope constrains what SQL an agent can run until an appropriate role is active in the session, reducing the blast radius of agent actions.
How does the Cortex AI Gateway help with tool access?
It provides server-level allowlisting, tool-level policy, rate limits, and a comprehensive audit trail for MCP server connections, with policies defined in the Horizon Catalog.
Snowflake AI BlogRead Original Article

AI news that matters for your work, delivered every morning.

Pick your industry and the AI tools you use, and get news related to your work every day.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.

Questions and answers are published on this page.

Related Articles

Next articleCyberAgent creates AI-first unit AIX Design Office