
Snowflake has launched Cortex AI Gateway, a centralized control platform for autonomous agents that enforces security, governance and cost management across enterprise AI deployments. The announcement comes as AI security concerns have jumped to 48% in 2026 from 17% in 2024, driven by autonomous agents expanding the corporate attack surface. Snowflake is also moving several native security features to production, including agent identity tracking, security posture scanning, data exfiltration prevention and ransomware protection via multi-party approval.
Summaries like this, in your inbox every morning.
Sign up free →What happened
Snowflake announced Cortex AI Gateway, a centralized control layer for autonomous agents that enforces identity, policy and audit at the tool-call level, integrating the MCP standard. The company also transitioned several AI security features to general availability (GA) and public preview, including Agent Identity, Restricted Session Scope, Native AI Security Posture Management, and Ransomware Protection via Multi-Party Approval.
Why it matters
AI security concerns have surged from 17% in 2024 to 48% in 2026, yet 57% of organizations face a significant capacity gap in security and risk management even though 97% are committed to implementing AI. Autonomous agents have expanded the enterprise attack surface by combining data access, system execution and data movement, making legacy monitoring tools insufficient. Snowflake's unified approach embeds security into the data and control planes rather than relying on patchwork application-layer fixes.
What to watch
Cortex AI Gateway is available now as the first milestone on Snowflake's AI gateway roadmap, with several features in private preview, including Wide Model Catalog, Access Governance and Sprawl Control, Observability and Tracing, AI Cost Control, and Intelligent Model Routing. The gateway integrates with leading models (GPT, Gemini, Claude, Grok, Mistral, GLM) and tools including Amazon Bedrock, Azure AI Foundry, ChatGPT, Claude Code, Cursor, and custom LangChain or LlamaIndex apps, and works with 100+ MCP servers. Demonstrations are available at Snowflake booth #8206 at Black Hat USA 2026.
At Black Hat USA 2026, Snowflake unveiled Cortex AI Gateway and a suite of AI security capabilities aimed at enterprises scaling autonomous agents. The Cortex AI Gateway integrates Natoma, a centralized MCP (Model Context Protocol) gateway, into Snowflake's ecosystem to enforce identity, policy and audit at the tool-call level. This addresses a core operational problem: as enterprises deploy autonomous agents across multiple models, tools and platforms, they lose visibility into what agents are doing, where data is flowing and how much AI is costing.
The gateway provides three operational layers. Control allows teams to grant, restrict and audit model and tool access from a single endpoint, replacing manual configuration of each new agent type with centralized, fine-grained authorization. Visibility captures agent actions in real time — which tool was called, which system it touched, in what order and by whom — providing audit trails for security and compliance teams without requiring individual instrumentation of each agent. Cost and performance features route requests automatically to the right model based on cost, latency, capability and data residency requirements, and enforce spending limits by team, agent or workload. Several features, including Wide Model Catalog, Access Governance and Sprawl Control, Observability and Tracing, and Intelligent Model Routing, are launching in private preview.
Cortex AI Gateway integrates with a broad ecosystem of first-party and third-party tools. It works with Snowflake's native CoCo and CoWork, as well as external platforms including Amazon Bedrock, Azure AI Foundry, ChatGPT, Claude Code, Cursor, and custom LangChain or LlamaIndex applications. It supports models from OpenAI (GPT), Google (Gemini), Anthropic (Claude), xAI (Grok), Mistral and others, and can govern access to 100+ MCP servers, including bring-your-own and VPC-connected servers.
Parallel to the gateway, Snowflake is transitioning a suite of native security capabilities to production. Agent Identity, now GA, gives security teams visibility into agent activity and allows policies to apply specifically when an agent is in a session, protecting sensitive data even when the agent runs on behalf of a privileged user. The company is also extending agent identity frameworks to third-party tools through integrations with security vendors including 1Password, Aembit, Cyera, Linx Security, Okta, SailPoint and Saviynt. Restricted Session Scope (GA soon) constrains what an agent session can do to only what the task requires — keeping a read-only analysis read-only even if the underlying user role allows more.
On the data protection side, Snowflake has launched its Data Exfiltration Prevention (DXP) package into preview. By pairing real-time telemetry with strict data movement policies (already GA), the platform detects and intercepts unauthorized data flows, proactively flagging and blocking sensitive data fetches triggered by AI agents, unauthorized data routing to internal or external stages, and mass data downloads. Native AI Security Posture Management, now GA, integrates into the Snowflake Trust Center and provides a dashboard for security teams to scan for AI-specific configuration risks, assess compliance against emerging regulations and deploy programmatic fixes. For development workflows, Client-side CoCo CLI VM Sandbox (in private preview on macOS) isolates each session in a separate Linux kernel, minimizing exposure of credentials and local storage to client-side AI workloads.
Finally, Snowflake moved Ransomware Protection via Multi-Party Approval to GA. This control requires two or more authorizations before any destructive system change can proceed, removing single points of failure from sensitive architectures so that even if top-tier administrative credentials are compromised, ransomware actors cannot unilaterally wipe data or alter configurations. The context for these announcements is stark: AI security concerns have surged from 17% in 2024 to 48% in 2026 according to The Linux Foundation's 2026 State of Tech Talent Report, yet while 97% of organizations are committed to implementing AI, 57% face a significant capacity gap in security and risk management. Snowflake's strategy is to embed security directly into the data and control planes rather than relying on patchwork application-layer fixes and legacy monitoring tools. Demonstrations of Cortex AI Gateway, Agent Identity controls and the automated threat scanners are available at Snowflake booth #8206 at Black Hat USA 2026.
The jump in AI security concerns from 17% to 48% between 2024 and 2026 reflects a fundamental shift in enterprise risk perception. While 97% of organizations say they are committed to implementing AI, 57% report a significant capacity gap in security and risk management — a mismatch that creates acute vulnerability. Snowflake's announcement addresses this gap directly by framing security not as an add-on layer but as a core component of the data and control planes.
Autonomous agents have become the flashpoint. These systems combine data access, system execution and data movement into a single operational profile, dramatically expanding the attack surface beyond what traditional application-layer fixes and legacy monitoring can handle. Decentralized adoption of agent standards (like MCP) has created what the company describes as unmanaged sprawl, fractured visibility and exposure to tool hijacking and data exfiltration. Cortex AI Gateway directly targets this problem by centralizing governance at the tool-call level — the point where agents request access to external systems — so that identity, policy and audit all flow through a single vantage point.
The breadth of the security stack Snowflake is releasing to GA and preview signals a recognition that no single control is sufficient. Agent Identity allows policies to apply only when an agent is acting (even on behalf of a privileged user), Restricted Session Scope constrains what an agent can do to the minimum required for its task, and Multi-Party Approval removes single points of failure in critical administrative changes. Together with Native AI Security Posture Management (which scans for AI-specific configuration risks) and Advanced Data Exfiltration Prevention (which flags sensitive data fetches and unauthorized data routing in real time), the suite aims to cover the entire workflow from agent identity through data protection.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
No comments yet. Be the first to share your thoughts!
Log in to join the discussion




Get curated AI news from 200+ sources delivered daily to your inbox. Free to use.
Get Started FreeFree · takes 30 seconds · unsubscribe anytime