Snowflake Inc. on Tuesday unfurled the Cortex AI Gateway, a centralized control layer designed to give enterprises a unified way to manage, secure, and track artificial intelligence (AI) agents operating across internal databases, models, and third-party systems.
The launch marks a strategic push to solve the security and visibility challenges created by the rise of the agentic enterprise. While early corporate AI focused on simple data retrieval, autonomous agents now actively perform complex tasks, execute workflows, and interact across disparate software environments. Traditional security models struggle to govern these cross-system actions, leaving organizations blind to what agents are doing — and how much compute budget they are burning.
Cortex AI Gateway functions as a single control plane. It governs agents built natively within Snowflake — such as its CoWork and CoCo tools — alongside popular third-party systems like Claude Code and Cursor. Supporting more than 100 Model Context Protocol (MCP) servers, the gateway centralizes permissions, authentication, and access rules to determine exactly which files, tools, and models an agent can touch.
The system relies heavily on technology acquired from MCP governance startup Natoma Labs Inc. earlier this year, using its infrastructure to broker secure connections between agents and enterprise assets. Beyond access control, the gateway maintains an end-to-end audit log detailing an agent’s step-by-step actions and monitors token consumption across teams. Financial and IT administrators can set spending caps to prevent unexpected budget overruns as agent deployments scale.
“Enterprise AI is moving from data interoperability to agent interoperability, and security has to be at the center of that shift,” said Mayank Upadhyay, chief security and trust officer at Snowflake. “The future of the agentic enterprise will not be built in closed agent ecosystems, and Snowflake is the trusted control plane that enables secure enterprise work.”
To bolster its zero-trust approach, Snowflake also announced integrations with key identity and security providers, including 1Password, Aembit, Linx Security, Okta, SailPoint and Saviynt. The partnerships target a critical vulnerability: agents running under a human user’s broad credentials without granular oversight. Through these integrations, companies can grant short-lived, task-scoped credentials, ensuring agents only access the specific data required for a job.
Early adopters, including media intelligence firm Meltwater N.V., view the framework as a crucial enabler for expanding AI use cases without sacrificing compliance.
Snowflake confirmed that Cortex AI Gateway will enter public preview soon, with third-party security integrations following in private preview. Broader security updates, including AI risk posture evaluation tools and agent identity verification, are available now.