AIToday
Large Language ModelsAI Safety & AlignmentSnowflake AI BlogPublished: Aug 24, 2026, 19:00 JST2 min read

Snowflake CoCo expands AI governance with new enterprise controls

Snowflake CoCo expands AI governance with new enterprise controls

Key takeaway

  • Snowflake CoCo has made per-user AI cost quotas generally available. It also introduced three new governance layers, available soon.

  • These controls extend oversight from cost to access, behavior, and external tooling.

  • The goal is to give administrators visibility while keeping guardrails invisible to builders.

3 Key Points

  1. What happened

    Snowflake announced that per-user AI cost quotas for CoCo are now generally available across all surfaces. It also introduced three new governance capabilities — managed device management, agent profiles, and restricted session scope — that are generally available soon.

  2. Why it matters

    These controls let administrators enforce policy before a session starts, covering cost, access, behavior, and external tool connections. This gives security teams concrete answers to review questions and aims to let more developers use CoCo beyond sandbox environments.

  3. What to watch

    The new external tool access goes through Tools by Cortex AI Gateway, which is generally available soon. It offers server-level allowlisting, tool-level policy, rate limits, and a comprehensive audit trail for every tool call.

Ask the AI about this article →

Context & Analysis

Snowflake is building on its July announcement about CoCo's ability to scale enterprise AI with trust. The new controls address a common friction point for platform teams: giving developers broad access while keeping risk measurable. Before these changes, teams often limited CoCo to narrow groups, sandbox schemas, or manual approval processes because the productivity gains were clear but the risks were harder to quantify.

The expansion moves governance from a focus on cost to a more complete framework covering access, behavior, and tooling. Per-user quotas handle spend, while managed device management pushes organization-wide policy across every CoCo installation. Agent profiles apply defaults by role, and restricted session scope limits what SQL an agent can run until an appropriate role is active. Each control answers a specific security review question, which could make it easier for administrators to open CoCo broadly.

For builders, the intended benefit is that governance becomes invisible. Agent profiles load the right model and skills by role, and governed external connections appear automatically without manual configuration. The company frames these controls as a way to give more developers production access, not less. That said, the article is a forward-looking product announcement, so actual availability and feature details may differ from what is described here.

FAQ

When are the new governance capabilities available?
Per-user quotas are generally available today. The three new capabilities — managed device management, agent profiles, and restricted session scope — are generally available soon.
How do the new controls affect external tool access?
CoCo connects to MCP servers through Tools by Cortex AI Gateway, which is generally available soon. Administrators can allowlist servers, disable individual tools, set rate limits, and view an audit trail of tool calls.
What does restricted session scope do?
Restricted session scope constrains what SQL an agent can run until an appropriate role is active in the session. This directly limits the blast radius by not trusting the agent with everything the user's credentials permit.
Snowflake AI BlogRead Original Article

Get the latest Large Language Models news every morning

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytime

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleTeachers Hit by AI Deepfakes as Students Cross Line