
Snowflake CoCo has made per-user AI cost quotas generally available. It also introduced three new governance layers, available soon.
These controls extend oversight from cost to access, behavior, and external tooling.
The goal is to give administrators visibility while keeping guardrails invisible to builders.
What happened
Snowflake announced that per-user AI cost quotas for CoCo are now generally available across all surfaces. It also introduced three new governance capabilities — managed device management, agent profiles, and restricted session scope — that are generally available soon.
Why it matters
These controls let administrators enforce policy before a session starts, covering cost, access, behavior, and external tool connections. This gives security teams concrete answers to review questions and aims to let more developers use CoCo beyond sandbox environments.
What to watch
The new external tool access goes through Tools by Cortex AI Gateway, which is generally available soon. It offers server-level allowlisting, tool-level policy, rate limits, and a comprehensive audit trail for every tool call.
Ask the AI about this article →
Snowflake is building on its July announcement about CoCo's ability to scale enterprise AI with trust. The new controls address a common friction point for platform teams: giving developers broad access while keeping risk measurable. Before these changes, teams often limited CoCo to narrow groups, sandbox schemas, or manual approval processes because the productivity gains were clear but the risks were harder to quantify.
The expansion moves governance from a focus on cost to a more complete framework covering access, behavior, and tooling. Per-user quotas handle spend, while managed device management pushes organization-wide policy across every CoCo installation. Agent profiles apply defaults by role, and restricted session scope limits what SQL an agent can run until an appropriate role is active. Each control answers a specific security review question, which could make it easier for administrators to open CoCo broadly.
For builders, the intended benefit is that governance becomes invisible. Agent profiles load the right model and skills by role, and governed external connections appear automatically without manual configuration. The company frames these controls as a way to give more developers production access, not less. That said, the article is a forward-looking product announcement, so actual availability and feature details may differ from what is described here.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
Ask AI anything about this article. Q&As are published on this page for other readers too.
Canonical is co-funding a three-year PhD project at the University of Bristol to investigate using LLMs to tra…

In 9 days from Aug 10, Meta (Muse Glimmer), NVIDIA (Nemotron 3.5 Lightning), and Alibaba Cloud (Qwen3.8-27B) r…

OpenAI has revealed that its AI agents, being evaluated for cybersecurity capabilities, found and exploited a…

An AlgorithmWatch investigation found that ChatGPT, Gemini, Grok, and Claude linked to anti-abortion websites…

Observe by Snowflake, which combines unified telemetry storage, a context graph, and an AI SRE layer, helped s…

Snowflake announced dynamic model routing in Cortex AI Gateway, which selects the most affordable model for ea…
