TLDRocket
Sign in

Snowflake debuts Cortex AI Gateway to govern and monitor enterprise AI agents

SiliconANGLE Duncan Riley Covered by 2 sources

Snowflake launched Cortex AI Gateway, a control panel that watches what AI agents do inside a company's systems. It matters because businesses are letting AI agents touch real data now, and nobody had a good way to track them.

Snowflake wants to be the traffic cop for the messy new world of AI agents. The company's new Cortex AI Gateway acts as a single checkpoint that sits between autonomous agents and everything they touch: models, internal databases, third-party tools, and the growing pile of Model Context Protocol servers that let AI systems reach into corporate software. It's not just Snowflake's own agents, either. The gateway also governs outside agents built on platforms like Claude Code and Cursor, connecting to more than 100 MCP servers in the process.

The timing traces back to May, when Snowflake bought Natoma Labs, a startup that specialized in MCP governance. That acquisition now forms the backbone of the gateway, giving Snowflake an enterprise-grade way to broker connections between agents and the systems they're allowed to act on. Mayank Upadhyay, the company's chief security and trust officer, framed the shift bluntly: enterprise AI is moving past simple data access into agents actually taking action, and that requires a different kind of security architecture than the one most companies already have bolted on.

What makes this more than a rebranded access-control tool is the accounting layer. The gateway logs every step an agent takes, which tools it called, which systems it reached, and in what order, then ties token usage back to specific agents, teams, and workloads. That's a direct response to a problem a lot of companies are quietly dealing with right now: agents that rack up enormous compute bills with no one able to say exactly why. Finance and IT teams get spending caps built in, which sounds mundane until you consider how easily an unsupervised agent loop can burn through a budget in an afternoon.

Snowflake also rolled out a set of identity integrations with Aembit, Linx Security, SailPoint, Saviynt, and 1Password, aimed at a specific blind spot: agents that operate under a person's full login credentials, making it nearly impossible to tell whether the agent or the human actually did something. 1Password's Nancy Wang described the fix as giving agents short-lived, task-specific access instead of standing permissions. Aembit's approach kills long-lived credentials outright, while Saviynt checks an agent's intent at runtime before letting it proceed. Meltwater, an early customer, says the appeal is straightforward: let its agents move fast without loosening the guardrails its own clients expect.

Some pieces are ready now, including risk-scoring tools and verified agent identities. Others, like limiting a session strictly to one task, remain in private preview. The full gateway is headed to public preview shortly, with the identity partnerships trailing behind in private preview of their own.

My take

This is basically an admission that enterprises let AI agents loose faster than they built any way to supervise them, and now vendors are racing to sell the seatbelt after the crash. Fine — better late than never. But watch the vendor lock-in angle here: Snowflake calling itself the 'trusted control plane' for an open agent ecosystem is a little rich coming from a company that obviously wants every agent's traffic routed through its own gateway.

Read more about this at: SiliconANGLE

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.