Quick Facts

  • Snowflake introduced Cortex AI Gateway on July 28, 2026, at Black Hat USA, with public preview coming soon.
  • The gateway governs AI agents from third-party platforms including Amazon Bedrock, Azure AI Foundry, ChatGPT, Claude Code, and Cursor.
  • Snowflake research found 57% of employees use nonapproved AI tools, including 66% of C-level leaders.

Snowflake on Tuesday launched Cortex AI Gateway, a centralized control layer that governs how AI agents access enterprise data, tools, and models. The company announced the product at Black Hat USA 2026 alongside a set of AI security tools covering MCP governance, agent identity controls, and data exfiltration prevention.

The gateway supports more than 100 Model Context Protocol servers, which have become the standard connectors for wiring AI agents to enterprise systems. It centralizes access policies, authentication, permissions, and audit logging in a single place, covering both Snowflake’s own tools and third-party agents from platforms including LangChain, LlamaIndex, Amazon Bedrock, and Azure AI Foundry.

Cost control is a core design goal. The gateway gives IT and finance teams a unified view of AI consumption, attributes spending to specific teams or workloads, and enforces limits before bills escalate.

Snowflake Chief Security and Trust Officer Mayank Upadhyay framed the problem as a foundational shift in enterprise security. “Traditional security was built for a world where humans were the actors. AI agents change that completely,” he said. “In the agentic era, trust can’t be a one-time decision made at login. It has to be continuously verified through every agent, every action, and every interaction across the enterprise.”

The launch builds on Snowflake’s May 28 acquisition of Natoma, an enterprise MCP platform for AI agents. CEO Sridhar Ramaswamy said at the time: “AI agents are quickly becoming part of how enterprises operate, but intelligence without governance creates risk.”

Alongside the gateway, Snowflake announced a first wave of security integrations with 1Password, Aembit, Linx Security, SailPoint, and Saviynt. Those integrations target a common blind spot in which agents operate under a user’s broad credentials, making it difficult to trace which agent accessed which data and under whose authority. The integrations are expected to enter private preview soon. An Okta integration is planned for private preview in Q4 2026.

The stakes are real. Snowflake’s own survey of 2,050 business and technology leaders found that 96% of organizations face significant challenges scaling AI, despite reporting roughly $1.49 in returns for every dollar invested. Twenty-two percent of middle managers and individual contributors called data governance “very challenging” to enforce.

Caitlin Halferty, Head of Data and Analytics at Thomson Reuters, said the company needs strong security and visibility as AI becomes embedded in professional workflows. “Organizations need the ability to protect sensitive information and maintain clear controls without limiting innovation,” she said.

Michael Ni, Principal Analyst at Constellation Research, put the competitive stakes bluntly. “Data platforms won the analytics era. Whoever governs agents, context, and autonomous actions wins the agentic era. Natoma gives Snowflake the missing layer between insight and execution.”

Snowflake shares traded at $272.92 at the time of the announcement, up 25.9% year to date. The company remains unprofitable, carrying a net income margin of -23.8%.

Read more: Snowflake launches Cortex AI Gateway to control AI agents and prevent runaway enterprise costs

This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.