Snowflake has introduced the Cortex AI Gateway, a control layer focused on regulating AI agents’ access to enterprise data, tools, and models, including those from competitors such as Anthropic’s Claude Code and Cursor. This launch was accompanied by security integrations with firms like 1Password, Aembit, Linx Security, SailPoint, and Saviynt, forming an unusual alliance of identity vendors typically in competition, now unified under a shared trust framework for autonomous agents.
Declared from its base in Bozeman, Montana, this marks Snowflake’s most assertive effort to transition from being just a data repository to becoming a regulatory entity that defines AI agents’ interactions with data.
Mayank Upadhyay, Snowflake’s chief security and trust officer, emphasized the importance of interoperability over isolated systems in an exclusive VentureBeat interview: “The future of AI lies in secure agent interoperability, not in isolated systems that hinder innovation and scalability,” he stated.
Challenges of Traditional Security Models with AI Agents
The announcement highlights a fundamental shift: traditional enterprise security models, which presumed human actors, are outdated. Upadhyay noted, “Security systems were designed for human actors accessing one application at a time at human speed. AI agents disrupt this paradigm.” He emphasized that AI doesn’t introduce new security issues but highlights existing vulnerabilities.
Organizations have historically struggled with complete visibility over APIs, datasets, and workflows. While these gaps were manageable at human speed, machine-speed agents can exploit these gaps, creating risks. Upadhyay concluded, “Trust in the agentic era requires continuous verification of every agent and interaction.”
Nancy Wang, chief technology officer of 1Password, shared insights on the dangers of granting agents user credentials. She noted the risks of unchecked access, highlighting the necessity for agents to have distinct identities to prevent unauthorized actions.
Details of Cortex AI Gateway and Cost Management
The soon-to-be-released public preview of the Cortex AI Gateway will manage both internal Snowflake agents and third-party agents. It centralizes access policies and audit logging through over 100 Model Context Protocol connectors, the standard for connecting agents to enterprise tools.
The gateway also tackles excessive AI spending by offering a unified view of AI usage, enabling cost attribution and enforcing spending limits to prevent budget overruns. Upadhyay illustrated how dynamic AI consumption patterns can escalate costs, turning minor inefficiencies into significant expenses at scale.
This development follows Snowflake’s acquisition of Natoma in May 2026, a startup known for its centralized MCP gateway that enforced identity and policy at the tool-call level. The acquisition, although modest in financial scale, signaled a strategic shift towards governing AI agent interactions.
Technical Innovations: Dual Attribution and Task-Scoped Access
A key feature of the partner integrations is dual attribution, which logs both agent identity and the human who authorized the task, ensuring accountability for every action. This addresses the question of responsibility when an agent acts.
Task-scoped access ensures agents have only the permissions necessary for specific tasks, addressing concerns over agents’ dynamic and unpredictable nature. Upadhyay emphasized that each agent action should be evaluated in real-time against relevant policies.
Wang described how 1Password’s integration uses emerging standards like OIDC-A to maintain task intent throughout complex operations, ensuring agents act within authorized boundaries.
SailPoint’s Perspective on Identity System Failures
Chandra Gnanasambandam from SailPoint discussed common failures in enterprise identity systems. He noted the difficulties in mapping permissions across numerous non-human identities and highlighted the risks of agents bypassing permissions due to powerful models. Continuous monitoring and intervention are necessary to address these issues.
Gnanasambandam also stressed the importance of understanding data context to mitigate risks, noting that many vendors overlook this crucial aspect.
Collaborative Effort Among Identity Vendors
The collaboration between 1Password, SailPoint, Saviynt, Okta, and Aembit within Snowflake’s trust framework is notable. Despite competing for similar markets, these vendors have joined forces to address the AI security challenge.
Upadhyay explained the collective effort as necessary for solving the agent security challenge across diverse platforms. Wang emphasized the complementary roles of trust and record-keeping in building a robust ecosystem.
Snowflake’s vast customer base and data concentration further strengthen its platform’s appeal, as more third-party agents integrate, enhancing its influence.
Urgency in Agent Governance
Analysts highlight the urgency of addressing governance gaps, with Gartner predicting that by 2027, such gaps may force 40% of enterprises to reduce reliance on autonomous agents. IDC forecasts a significant rise in AI agents and associated IT spending, underscoring the importance of treating agentic platforms as critical decision-making infrastructure.
In this competitive landscape, major vendors like Salesforce, ServiceNow, Microsoft, Google, and Okta are vying for control over runtime governance. Snowflake’s edge lies in its proximity to the data layer, ensuring comprehensive security measures are in place.
The Cortex AI Gateway’s upcoming public and private previews will test these innovations, with Wang inviting complex use cases to validate the system’s robustness. This confidence reflects a pivotal moment as companies acknowledge that machine identity verification will shape the future of AI governance. Upadhyay concluded, “Success in the AI era will belong to those who can govern agents with the greatest trust and control.”

