News
Snowflake Launches Cortex AI Gateway to Govern Enterprise AI Agents
Snowflake unveiled Cortex AI Gateway, a central platform for controlling the access, costs, and security of AI agents operating inside companies, covering both its own tools and external ones like Claude Code and Cursor.
Contents
Snowflake unveiled Cortex AI Gateway on July 28, 2026, a platform meant to give companies a single control panel over what AI agents are doing inside their systems. The launch coincided with the Black Hat 2026 security conference and addresses two problems increasingly keeping IT departments up at night: AI agents with access to too much data, and AI bills that grow without oversight.
Cortex AI Gateway is designed to act as an intermediary layer between AI agents and the rest of a company's infrastructure. That applies both to tools built inside Snowflake, such as Snowflake CoWork and Snowflake CoCo, and to agents built on external platforms, including Anthropic's Claude Code and Cursor. It's a notable shift for Snowflake, a company until now known mainly for data storage and processing rather than managing other companies' AI tools.
Access and Cost Control
The gateway's main function is managing which models, data, applications, and MCP servers a given agent can access. Companies get a single set of access, authentication, and permission policies instead of configuring each AI tool separately. On top of that comes a full audit log of agent activity: who called which tools and systems, when, and in what order.
The second pillar is cost management. IT and finance teams are meant to get a single view of token consumption across all models and workloads, with the ability to attribute spending to specific teams, agents, or projects, and to set spending limits. It addresses a common problem at companies that rolled out AI agents without any cost control mechanism, where API and token bills can grow at a pace nobody is tracking.
Where the Platform Came From
Cortex AI Gateway is built on technology from Natoma Labs, a company specializing in managing the MCP protocol in enterprise environments that Snowflake acquired in May 2026. That acquisition let Snowflake quickly offer support for more than a hundred MCP servers right at launch, making the gateway one of the more broadly supported platforms of its kind on the market.
Enterprise AI is moving from data interoperability to agent interoperability, and security has to be at the center of that shift - Mayank Upadhyay, Chief Security and Trust Officer, Snowflake
Identity Security Partners
Snowflake simultaneously announced integrations with five identity and access management companies: 1Password, Aembit, Linx Security, SailPoint, and Saviynt, with Okta to follow. They're meant to solve a problem where AI agents today often operate with broad user-level permissions instead of narrow, task-scoped access.
The integration gives third-party agents short-lived, task-scoped access tied to a clear record of the person behind each agent - a 1Password technical representative
Integrations with most partners are heading into private preview for now, while the Okta collaboration isn't set to launch until the fourth quarter of 2026. Cortex AI Gateway's public preview is expected to arrive soon, though Snowflake hasn't given an exact date yet.
What It Means for Businesses
For IT and security teams at companies using Snowflake's tools, this means the possibility of introducing a single point of control over a growing number of AI agents, instead of policing each tool individually. It responds to an increasingly common problem: coding agents and AI assistants today get access to repositories, databases, and internal systems without consistent oversight of what they're actually doing and what that activity costs.
For Polish companies using Snowflake as a data platform, what will matter is when Cortex AI Gateway rolls out beyond the US market and whether the identity provider integrations extend to locally used systems too. The core concept, one gateway controlling agent access regardless of who built the agent, fits a broader market trend: more and more companies are realizing AI agents need their own management layer, similar to the one applications and users have had for years.
