Snowflake has launched
Cortex AI Gateway, a central control layer for managing how AI agents connect to enterprise data, applications, models, and tools. The gateway will work with agents built inside Snowflake, including Snowflake CoWork and Snowflake CoCo. It will also cover third-party agents created on platforms such as Claude Code and Cursor. Cortex AI Gateway builds on technology Snowflake acquired when it bought the enterprise Model Context Protocol platform
Natoma in May.Bringing AI controls together
AI agents often need access to several systems to complete one task. An agent may query a database, call an application, use an MCP server, and send requests to different AI models. Companies are now trying to manage that activity through separate tools for identity, model access, data security, and MCP connections. Snowflake wants Cortex AI Gateway to bring those controls into one place.
Artin Avanes, head of core data platform at Snowflake, told ChannelE2E, “Today, most solutions address a specific piece of the AI stack. AI gateways typically focus on routing inference requests to models. Identity platforms focus on authenticating users, applications, and services. MCPs help secure communication between agents and the tools they invoke."
Snowflake sees the gateway as a layer that sits across those tools rather than replacing them.
“Cortex AI Gateway is designed to operate one layer above those individual capabilities as the enterprise AI interoperability layer and trusted control plane for AI agents. Rather than governing only model access, identity, or MCP connections independently, it provides a centralized control plane for governing how AI agents interact across models, tools, MCP servers, enterprise applications, and data, regardless of where those agents originate,” Avanes said.
The gateway will centralize authentication, permissions, and access policies. It will also create a record of what each agent did, which systems it accessed, and the steps it took. Snowflake said the product will support more than 100 MCP servers.
Connecting AI governance with data governance
Many Snowflake customers already use the platform to manage data access, security policies, and workloads. Cortex AI Gateway will allow them to apply those same controls to AI agents.
“And unlike standalone AI gateways, Cortex AI Gateway is seamlessly integrated with Snowflake’s platform, powering the AI Data Cloud, where organizations already govern and secure their enterprise data estate. This enables enterprises to extend existing security and governance policies to AI agents, controlling how they access and interact with models, tools, MCP servers, enterprise applications, and data, rather than managing AI governance separately from the data governance framework already in place,” Avanes said.
This would give security, IT, and data teams a shared view of agent access and activity. It could also reduce the number of separate policies companies need to maintain as they add more models and agent platforms.
“We believe enterprises need a common control plane that spans the entire AI ecosystem, rather than separate governance mechanisms for every model, agent framework, or enterprise system,” Avanes said.
Tracking AI costs by agent and team
Cortex AI Gateway will also help companies track and control AI spending. As more teams build agents, usage can spread across different models, departments, and cloud services. Companies may struggle to identify which agents are using the most resources or why costs are rising.
The gateway will attribute AI consumption to individual agents, teams, and workloads. IT and finance teams will be able to set spending limits and route requests to approved models based on cost, quality, latency, and availability.
“Because AI usage is governed within the same platform where enterprise data and workloads run, organizations gain end-to-end observability into AI consumption, can attribute costs to specific agents and teams, and can put controls in place to manage spend as agentic workloads grow,” Avanes said.
This puts spending controls alongside security policies and activity monitoring. Companies can see what an agent accessed, what it did, and how much it cost from the same platform.
Securing access for third-party agents
Snowflake also announced integrations with 1Password, Aembit, Linx Security, Okta, SailPoint, and Saviynt. These are meant to address a common problem with third-party agents. Many agents operate through a user’s credentials and may inherit all of that person’s permissions, even when the task requires limited access. Snowflake wants companies to give agents task-scoped access. An agent would receive only the permissions needed for a specific job and only for as long as those permissions are required.
“With Snowflake’s approach to secure third-party agent access, organizations can move beyond the traditional model of agents operating with broad user credentials and gain clearer visibility into which agents accessed what data, through which platform, and under whose authority,” Avanes said.
The controls are also designed to show who authorized an agent, which platform it came from, and what data or tools it used. The 1Password, Aembit, Linx Security, SailPoint, and Saviynt integrations are expected to enter private preview soon. Snowflake plans to place the Okta integration in private preview in the fourth quarter of 2026.
The MSP opportunity
Cortex AI Gateway also gives MSPs and MSSPs a base for building managed AI governance services.
“As customers move from AI experimentation to production, many will naturally look to trusted partners to help operationalize governance across increasingly complex AI environments,” Avanes said.
MSPs could help customers set policies, monitor usage, and manage costs across different AI platforms.
“Cortex AI Gateway gives MSPs a foundation to help customers establish consistent governance for AI activity, providing visibility and control across models, tools, MCP servers, enterprise systems, and data sources. By leveraging Cortex AI Gateway as part of their managed services offerings, MSPs can help customers apply governance policies, monitor agent activity, and manage AI consumption across their environments, while maintaining the flexibility to use the models and agent frameworks that best fit their business needs,” Avanes said.
That work could include agent inventories, access reviews, policy updates, and monthly reports on AI usage and spending.
MSSPs could handle the security side. They could watch for unusual agent behavior, review unauthorized actions, and investigate cases where an agent went beyond its approved task.
“As AI agents become more interconnected across enterprise platforms, MSPs and MSSPs will become critical partners in helping organizations operationalize trust and governance for agentic workflows,” Avanes said.
“MSPs and MSSPs can help customers translate these capabilities into operational practices by defining appropriate access policies, ensuring agents have task-scoped permissions, monitoring agent activity, and helping investigate anomalous or unauthorized actions,” he added.
Service providers could also help customers apply the same rules across several agent platforms and identity systems.
“As agent ecosystems become more distributed, service providers can help organizations maintain consistent governance across different platforms and agent frameworks, enabling customers to embrace AI innovation while preserving the security, identity, and access controls required for enterprise adoption,” Avanes said.
Snowflake has also added other AI security features alongside Cortex AI Gateway. The updates include tools for assessing AI risk, verifying agent identities, and protecting sensitive data. Snowflake is also adding controls that limit an agent session to the task it was approved to complete.