Snowflake today announced Cortex AI Gateway and a suite of AI security innovations aimed at establishing the foundation for trusted agent interoperability in the enterprise. The new capabilities address two of the biggest barriers to scaling AI agents: security and governance risks, and the lack of centralized visibility and control over AI consumption costs.
As AI agents increasingly collaborate across data, applications, and platforms, they introduce new security and operational challenges that traditional architectures were not designed to handle. Snowflake positions Cortex AI Gateway as the connective layer for all trusted agent activity, enabling enterprises to govern how agents access models, tools, MCP servers, and enterprise systems while optimizing cost and performance.
“Enterprise AI is moving from data interoperability to agent interoperability, and security has to be at the center of that shift. Agent interoperability only works when enterprises can trust how agents from different platforms access data, invoke tools, and take action on behalf of users. Snowflake provides the visibility, governance, and control capabilities needed to make that interoperability secure for production AI.”
Mayank Upadhyay, Chief Security and Trust Officer at Snowflake, said:
Cortex AI Gateway supports both Snowflake-native agents (such as Snowflake CoWork and CoCo) and third-party agents built on platforms like Claude Code and Cursor. It centralizes access policies, authentication, permissions, and controls, while providing end-to-end visibility into agent activity and a unified view of AI consumption costs. Snowflake also announced the first wave of secure third-party agent access integrations with 1Password, Aembit, Linx Security, Okta, SailPoint, and Saviynt.
The announcement builds on Snowflake’s earlier acquisition of Natoma and continues the company’s push to bring zero-trust principles to the agentic enterprise, with customers including BlackRock and Thomson Reuters highlighting the importance of strong security and governance as they scale AI.
Conditions Driving the Change
AI agents are rapidly evolving from isolated assistants into active participants that collaborate across enterprise data platforms, applications, and tools, creating an urgent need for a unified control plane that can govern their access and actions at scale.
Traditional security architectures were built for human users and static systems, leaving organizations without consistent ways to control which models, data, MCP servers, and tools each agent can reach or to audit the full sequence of steps an agent takes.
Fragmented AI usage across multiple models, teams, and workloads has made AI consumption costs difficult to track, attribute, and control, increasing the risk of runaway spending as agent activity expands.
Enterprises require secure interoperability for third-party agents built on external platforms such as Claude Code and Cursor, yet many vendor ecosystems remain closed or lack standardized identity, access, and audit controls.
Security and identity teams need task-scoped, short-lived access for agents rather than broad inheritance of user permissions, so that agents only receive the minimum privileges required for a specific job.
Organizations lack a single place to observe end-to-end agent activity, making it hard to answer basic questions about which agent acted, what systems it touched, and whether the action complied with policy.
The move from data interoperability to agent interoperability demands that trust, visibility, and governance sit at the center of every cross-system interaction if production-scale agent deployments are to succeed.
Leading security and identity vendors are beginning to integrate with data platforms to close the visibility and control gaps that arise when agents operate across organizational boundaries.
Customers in highly regulated and data-intensive industries are insisting on zero-trust principles, verified agent identities, and clear cost oversight before they will allow agentic AI into critical workflows.
What AI Security Looked Like Before
Before platforms like Snowflake’s Cortex AI Gateway emerged, enterprise AI security for agentic systems was fragmented, reactive, and poorly suited to the realities of production-scale agent deployments. Organizations typically managed AI agents through a patchwork of existing identity and access management tools, custom integrations, and model-provider safety features that were never designed for autonomous, cross-system agents. Access controls were often inherited from human user accounts, meaning agents frequently received far broader permissions than any single task required. Visibility into agent activity was limited to scattered logs or application-level traces, making it difficult to reconstruct the full sequence of actions an agent took across data platforms, tools, and MCP servers.
Cost management was equally incomplete. AI consumption was tracked in silos by team, model, or workload, with little ability to attribute spending to specific agents or enforce real-time limits. Third-party agents operating on external platforms such as Claude Code or Cursor often sat outside the enterprise security perimeter entirely, creating blind spots around identity, authorization, and data access. Security teams struggled to answer basic questions: which agent acted, under whose authority, what systems it touched, and whether the action complied with policy. Governance was frequently applied after the fact rather than enforced at the moment of access. As a result, many enterprises limited agent adoption to low-risk use cases or delayed production deployments because they could not confidently control security, auditability, and cost across an increasingly complex agent landscape.
What AI Security Looks Like Now
With the introduction of Snowflake’s Cortex AI Gateway and supporting AI security innovations, enterprise AI security is shifting toward a centralized, trust-based control plane designed specifically for the agentic era. Cortex AI Gateway acts as the connective layer for both first-party and third-party agents, enabling organizations to govern how agents access models, tools, MCP servers, data, and enterprise systems from a single point of control. Access policies, authentication, permissions, and routing decisions are centralized, while every agent action is recorded in an end-to-end activity trail that gives security and operations teams the visibility needed to operate agents safely at scale.
Cost management is no longer an afterthought. The gateway provides a unified view of AI consumption, attributes costs to the teams, agents, or workloads driving them, and supports spending limits that help prevent runaway usage before it occurs. Intelligent routing further optimizes quality, latency, and cost by directing requests to enterprise-approved models. New integrations with leading identity and security vendors — including 1Password, Aembit, Linx Security, Okta, SailPoint, and Saviynt — extend consistent governance to third-party agents, enabling task-scoped, short-lived access and clearer human-to-agent attribution. The overall model moves from fragmented, reactive protection to proactive, zero-trust control that supports secure agent interoperability across the enterprise while maintaining the visibility, auditability, and cost oversight required for production AI.
Our Take
AI Security Take
Snowflake’s launch of Cortex AI Gateway and related AI security innovations marks a clear step toward making the agentic enterprise both secure and operationally manageable. As AI agents move from isolated tools to active participants that collaborate across data platforms, applications, and external systems, the absence of a unified control plane has become one of the biggest barriers to production adoption. Cortex AI Gateway directly addresses that gap by centralizing access governance, activity visibility, and cost control for both first-party and third-party agents.
The most important shift is architectural. Instead of securing each agent or each model in isolation, Snowflake is positioning the gateway as the connective layer that enforces policy at the point of access, records every action, and provides a single view of consumption. Combined with new integrations from identity and security partners, this creates a path toward consistent, task-scoped governance for agents that would otherwise inherit broad user permissions or operate outside the enterprise perimeter. The result is a more practical model for zero-trust security in an environment where agents act continuously and at machine speed.
For security and platform leaders, the practical value lies in the combination of control and enablement. Organizations can expand the use of agents across critical systems while maintaining clear answers to fundamental questions: which agent is acting, what it can reach, under whose authority, and at what cost. Those that continue relying on fragmented tooling and human-centric identity models will face growing risk and operational friction as agent volumes increase. Those that adopt centralized gateways with strong identity, data, and cost controls will be better positioned to scale agentic AI with confidence.
Snowflake’s announcement reinforces a broader industry trend: the future of enterprise AI security will be defined by platforms that treat agent interoperability, runtime governance, and cost transparency as first-class requirements rather than afterthoughts. Enterprises that prioritize these capabilities now will gain both risk reduction and a clearer path to realizing the business value of production-scale agents.