
Snowflake launched Cortex AI Gateway at Black Hat 2026 to centrally govern how autonomous agents access enterprise data, models, and tools—addressing a sharp rise in AI security concerns that grew from 17% to 48% between 2024 and 2026. The gateway integrates Natoma to enforce identity, policy, and audit controls at the tool-call level, giving enterprises visibility into agent activity and control over AI consumption costs. Snowflake also transitioned several native security features to general availability, including Agent Identity, Restricted Session Scope, and Ransomware Protection via Multi-Party Approval, as organizations struggle with security and risk management capacity despite high AI adoption commitment.
Summaries like this, in your inbox every morning.
Sign up free →What happened
Snowflake announced Cortex AI Gateway at Black Hat 2026, a centralized control layer integrating Natoma (an MCP gateway) to manage how AI agents access models, data, and enterprise tools. The company also moved several security features—including Agent Identity, Restricted Session Scope, Native AI Security Posture Management, and Ransomware Protection via Multi-Party Approval—to general availability or public preview.
Why it matters
AI security concerns jumped from 17% in 2024 to 48% in 2026 according to The Linux Foundation's 2026 State of Tech Talent Report, while 97% of organizations are committed to implementing AI but 57% face a significant capacity gap in security and risk management. Autonomous agents have dramatically expanded the enterprise attack surface by combining data access, system execution, and data movement; a patchwork of application-layer fixes is no longer sufficient, making built-in security at the data and control planes critical.
What to watch
Cortex AI Gateway offers three core capabilities—control (grant, restrict, and audit access from a single endpoint), visibility (capture agent actions in real time for audit trails), and cost management (automatically route requests based on cost and latency). Most features are in private preview, with some moving toward general availability; enterprises can visit booth #8206 at Black Hat USA 2026 for demonstrations.
At Black Hat 2026, Snowflake announced Cortex AI Gateway alongside major AI security advancements, responding to a dramatic shift in enterprise risk perception. According to The Linux Foundation's 2026 State of Tech Talent Report, AI security concerns jumped from 17% in 2024 to 48% in 2026—a nearly threefold increase. The backdrop is stark: while 97% of organizations say they are committed to implementing AI, 57% report a significant capacity gap in security and risk management.
The core problem Cortex AI Gateway addresses is the expanding attack surface created by autonomous agents. Unlike traditional applications, agents combine data access, system execution, and data movement into a single profile, creating what Snowflake describes as "severe security liabilities." Currently, enterprises are building agents in a decentralized manner using standards like MCP (Model Context Protocol) to connect LLMs to databases, internal tools, and SaaS environments. But this fragmented approach leaves organizations vulnerable to unvetted servers, tool hijacking, and data exfiltration, with no visibility into what agents are doing and AI costs spiraling out of control.
Cortex AI Gateway serves as a centralized MCP gateway that enforces identity, policy, and audit controls at the tool-call level. It governs how AI agents—both Snowflake-native tools (CoCo and CoWork) and third-party ecosystems (Amazon Bedrock, Azure AI Foundry, ChatGPT, Claude Code, Cursor, custom LangChain or LlamaIndex apps, and others)—access models, data, MCP servers, and enterprise tools. The gateway delivers three core capabilities: Control allows teams to grant, restrict, and audit model and tool access from a single endpoint, replacing manual per-agent configuration with centralized fine-grained authorization. A Wide Model Catalog (private preview) lets enterprises run GPT, Gemini, Claude, Grok, Mistral, GLM and more within their own geography, helping keep data in the region where it must reside. Access Governance and Sprawl Control (private preview) reduces the administrative burden of configuring connections for dozens of emerging agent types.
Visibility is the second pillar. Agent actions are captured in real time: which tool was called, which system it touched, in what order, and by whom. Observability and Tracing (private preview) securely captures agent tool calls in real time, providing comprehensive audit trails for usage tracking, troubleshooting, and forensics. Agent Action Auditability (private preview) gives an end-to-end record of agent actions and the systems touched.
Cost and performance is the third. The gateway can automatically route requests to the right model based on cost, latency, capability, and other requirements, while enforcing spending limits by team, agent, or workload. AI Cost Control (private preview) provides a unified view of AI consumption and enables budget guardrails. Intelligent Model Routing (private preview) automatically directs agent requests to cheaper models for simpler tasks without sacrificing quality and without sending sensitive data to the wrong region.
Complement to the gateway, Snowflake transitioned several native AI security capabilities to general availability and public preview. Agent Identity (GA) gives security teams greater visibility into agent activity and lets them enforce data access policies that apply specifically when an agent is in session, protecting sensitive data even when the agent runs on behalf of a privileged user. The company is extending these identity frameworks to third-party agents through integrations with 1Password, Aembit, Cyera, Linx Security, Okta, SailPoint, and Saviynt, so the same governance policies can cover external AI tools. Restricted Session Scope (moving to GA soon) limits what an agent session can do to only what the task requires—keeping a read-only analysis read-only even if the user's role permits more.
Snowflake also launched Native AI Security Posture Management (GA), a dashboard in the Snowflake Trust Center that proactively scans for AI-specific risks, assesses compliance postures against emerging global regulations, and deploys programmatic remediations. Advanced Data Exfiltration Prevention (preview) pairs real-time telemetry with strict data movement policies (GA) to detect and intercept unauthorized data flows, flagging and blocking sensitive data fetches triggered by AI agents, unauthorized data routing, and mass downloads. Client-side CoCo CLI VM Sandbox (private preview), available on macOS, isolates each CoCo session in a separate Linux kernel from the host operating system, minimizing exposure of credentials and local storage to client-side AI workloads.
Finally, Snowflake announced that Ransomware Protection via Multi-Party Approval is now GA, requiring two or more authorizations before any destructive system change can proceed. This removes single points of failure and prevents even hijacked top-tier administrative credentials from unilaterally wiping data or altering configurations, improving enterprise resilience against ransomware extortion. Snowflake invited attendees to booth #8206 at Black Hat USA 2026 to see demonstrations of the Cortex AI Gateway, AI Agent Identity controls, and automated threat scanners built into the Snowflake Trust Center.
The timing of Snowflake's announcement reflects a critical inflection point in enterprise AI adoption. The Linux Foundation data showing security concerns jumping from 17% to 48% in just two years signals that organizations are moving beyond early experimentation and confronting the hard security and governance problems that come with deploying autonomous agents at scale. This shift from 2024 to 2026 —a period spanning the current moment—underscores that legacy security approaches (application-layer patches and fragmented monitoring tools) are inadequate when agents can execute actions, move data, and access systems simultaneously.
Snowflake's response positions centralized governance as the answer. By integrating Natoma into the Cortex AI Gateway, Snowflake is betting that enterprises need a single control point—not a patchwork of point solutions—to manage the attack surface created by autonomous agents. The gateway's three pillars (control, visibility, and cost management) directly address the capacity gaps the Linux Foundation survey identified: 57% of organizations lack security expertise to manage AI workloads. Centralizing access policies, audit trails, and spend tracking reduces the manual configuration burden and gives security teams the evidence they need without instrumenting each agent individually.
The timing also matters because Snowflake is moving several security primitives from preview to general availability or near-GA (Agent Identity, Restricted Session Scope, Ransomware Protection via Multi-Party Approval), signaling that these are no longer experimental but production-ready. This progression—from early preview to GA—reflects a maturing ecosystem where enterprises expect built-in security, not optional add-ons. The variety of integrations (1Password, Okta, SailPoint, etc.) and support for third-party agents (AWS Bedrock, Azure AI, ChatGPT, Claude Code) suggests Snowflake is not trying to lock enterprises into Snowflake-only agents but rather to become the governance layer that bridges multiple AI platforms and vendors.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
No comments yet. Be the first to share your thoughts!
Log in to join the discussion





Get curated AI news from 200+ sources delivered daily to your inbox. Free to use.
Get Started FreeFree · takes 30 seconds · unsubscribe anytime