Enterprise AI Security: Agentic Controls and MCP Governance
Captured source
source ↗Enterprise AI Security: Agentic Controls and MCP Governance
Skip to content
Blog / Product and Technology / Snowflake Launches Cortex AI Gateway and Advanced AI Security at Black Hat 2026
JUL 28, 2026 / 5 min read Product and Technology Snowflake Launches Cortex AI Gateway and Advanced AI Security at Black Hat 2026
Radhika Janardanan +1
AI security concerns have surged from 17% in 2024 to 48% in 2026 according to The Linux Foundation’s 2026 State of Tech Talent Report — a critical shift given that while 97% of organizations are committed to implementing AI, 57% face a significant capacity gap in security and risk management. By combining data access, system execution and data movement into a single profile, autonomous agents have been dramatically expanding the enterprise attack surface. A patchwork of application-layer fixes and legacy monitoring tools is no longer enough. To safely scale enterprise AI, security must be built directly into the data and control planes.
At Black Hat 2026, Snowflake is delivering that foundation and announcing Cortex AI Gateway and major production-ready AI security advancements.
Agent interoperability layer: Extending Snowflake governance with Cortex AI Gateway
With the rapid rise of autonomous agents, teams are quickly leveraging standards like MCP to connect LLMs to databases, internal tools and SaaS environments. However, decentralized adoption creates unmanaged sprawl, fractured user experiences and severe security liabilities, leaving organizations vulnerable to unvetted servers, tool hijacking and data exfiltration. As enterprises scale autonomous agents across models, tools and platforms, they're running into a hard problem: fragmented access, no visibility into what agents are doing and AI costs spiraling out of control.
By integrating Natoma — a centralized MCP gateway that enforces identity, policy and audit at the tool-call level — into the Snowflake ecosystem, the Cortex AI Gateway is the connective layer for all trusted agent activity. It enables enterprises to realize new levels of governed agent interoperability, while giving enterprises visibility and control over AI consumption costs.
Cortex AI Gateway governs how AI agents — both first-party tools (like Snowflake CoCo and CoWork) and third-party ecosystems (such as Amazon Bedrock, Azure AI Foundry, ChatGPT, Claude Code, Cursor, custom LangChain or LlamaIndex apps, and others) — access models, data, MCP servers and enterprise tools. Enterprises can govern MCP tool usage with Tools by Cortex AI Gateway through a centralized gateway, giving teams control and visibility into who requested the action, what permissions they have and whether the action is allowed.
As the first milestone on our AI gateway roadmap, Cortex AI Gateway provides the core infrastructure needed to unify tool access, security and governance for enterprise agents. It extends Snowflake’s rigorous data governance framework to agent traffic.
Cortex AI Gateway delivers three things enterprises need to scale agents safely:
Control: Grant, restrict and audit model and tool access from a single endpoint. Instead of manually configuring each new agent type, teams can manage permissions centrally with fine-grained authorization.
Wide Model Catalog (private preview): Bring the models you need under one roof — GPT, Gemini, Claude, Grok, Mistral, GLM and more — and run them in your geography, helping keep data within the region it needs to stay in.
Access Governance and Sprawl Control (private preview): This reduces the need for administrators to manually configure connections for dozens of emerging agent types. Instead, teams can grant, restrict and audit tool access from a single endpoint.
Govern Every Agent Connection (private preview): Experience streamlined access and data policies, authentication, fine-grained authorization and permissions across 100+ MCP servers (including BYO and VPC connect), automatic discovery and monitoring of shadow AI and MCPs.
Visibility: Agent actions are captured in real time: which tool was called, which system it touched, in what order and by whom. Audit trails give security and compliance teams the evidence they need without instrumenting each agent individually.
Observability and Tracing (private preview): Agent tool calls can be securely captured in real time, providing the comprehensive audit trails required for usage tracking, troubleshooting and forensics.
Agent Action Auditability (private preview): Access an end-to-end record of agent actions, including which systems it touched and in what sequence.
Cost and performance: Route requests automatically to the right model based on cost, latency, capability and other requirements. Enforce spending limits by team, agent or workload before costs run away.
AI Cost Control (private preview): Get a unified view of AI consumption by team, agent or workload; manage and apply budget guardrails; route to cheaper models for simpler tasks without sacrificing quality.
Intelligent Model Routing (private preview): Automatically route agent requests to the right model based on cost, latency, capability and data residency requirements, so enterprises get better output without overpaying or sending sensitive data to the wrong region including prompt management.
AI security stack: Transitioning to production-grade
Complementing our new AI MCP gateway capabilities, we are transitioning a set of native, enterprise-grade security capabilities to general availability (GA) and public preview. These defense-in-depth features help your AI workloads and data remain protected in production environments.
Securing agent identity and sessions
Agent Identity (GA): Security and governance teams can now have greater visibility into agent activity. Teams can enforce data access policies that apply specifically when an agent is in the session, helping keep sensitive data protected even when the agent runs on behalf of a privileged user. We have also added dedicated agent identity tracking in Account Usage views for auditing.
Third-Party Agent Identity: We are extending these robust identity frameworks to third-party agents through integrations with leading security innovators such as 1Password, Aembit, Cyera, Linx Security, Okta, SailPoint and Saviynt. This means the same governance policies you apply to Snowflake-native agents can be extended to cover external AI tools.
Restricted Session Scope (GA soon): Restricted Session Scope limits...
Excerpt shown — open the source for the full document.