IT Brief UK - Technology news for CIOs & IT decision-makers
United Kingdom
Snowflake launches AI gateway for secure agent access

Snowflake launches AI gateway for secure agent access

Wed, 29th Jul 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Snowflake has launched Cortex AI Gateway2 and a set of AI security products aimed at enabling trusted interoperability between AI agents.

The gateway is designed to give organisations a single place to manage how AI agents access models, tools, enterprise systems, and data, while tracking AI spending. It covers both agents built within Snowflake's own platform, including Snowflake CoWork and Snowflake CoCo, and external agents developed on other platforms such as Claude Code and Cursor.

The announcement reflects a broader shift in enterprise AI from single tools to networks of software agents operating across multiple systems. That shift has created new security and governance questions for companies putting AI into production, especially when agents can access sensitive data or take actions on behalf of employees.

According to Snowflake, Cortex AI Gateway can support more than 100 MCP servers and is intended to centralise policies, authentication, permissions, and controls for agent access. It also provides a record of agent activity and tools to attribute spending to teams, workloads, or individual agents.

The platform also routes requests to approved AI models, allowing customers to balance quality, latency, availability, and cost under a single control layer. For many corporate users, a central challenge has been the lack of clear oversight when different teams use different models and services across the business.

Snowflake has tied the launch to its earlier acquisition of Natoma, whose enterprise MCP technology is now being folded into the Snowflake platform. The deal gave Snowflake technology designed to link AI agents securely across enterprise systems.

Partner integrations

Alongside the gateway, Snowflake introduced an initial group of integrations with 1Password, Aembit, Linx Security, Okta, SailPoint, and Saviynt. These are intended to help customers govern and audit third-party agents across different security platforms.

The issue is becoming more urgent as companies adopt external agents that may act under a user's authority while operating outside a single vendor's environment. In practice, that raises questions about attribution, identity, and the exact scope of access an agent should receive for a given task.

Snowflake's approach is based on limiting access to what a specific task requires, rather than allowing an agent to inherit a user's full privileges. The integrations are also intended to give security teams clearer records of which agent accessed what data, on which platform, and under whose authority.

"Enterprise AI is moving from data interoperability to agent interoperability, and security has to be at the centre of that shift," said Mayank Upadhyay, Chief Security and Trust Officer, Snowflake.

"Agent interoperability only works when enterprises can trust how agents from different platforms access data, invoke tools, and take action on behalf of users. Snowflake provides the visibility, governance, and control capabilities needed to make that interoperability secure for production AI. The future of the agentic enterprise will not be built in closed agent ecosystems, and Snowflake is the trusted control plane that enables secure enterprise work," Upadhyay said.

Customer response

Some customers and partners used the launch to highlight the operational concerns emerging around agent-based AI.

"At Meltwater, we help organisations make sense of fast-moving external data and turn insights into action. As AI becomes more embedded in that work, security and trust are critical to delivering value," said Aditya Jami, Chief Technology Officer, Meltwater.

"We see Cortex AI Gateway as a step towards ensuring our agents can securely connect to the right data and tools, helping us deliver trusted AI-powered insights faster while maintaining the security and control our customers expect," Jami said.

Thomson Reuters also pointed to the need for governance as AI tools move deeper into day-to-day work.

"At Thomson Reuters, building trusted AI for professionals requires strong security, governance, and visibility into how AI systems access data, use tools, and take action," said Caitlin Halferty, Head of Data & Analytics, Thomson Reuters.

"As AI becomes more deeply embedded in professional workflows, organisations need the ability to protect sensitive information and maintain clear controls without limiting innovation. Snowflake's continued investment in AI security and governance supports the kind of trusted foundation enterprises need as they move agentic AI into production," Halferty said.

Security focus

Snowflake said the broader set of security updates includes tools to help teams assess AI risk, verify agent identity, protect sensitive data, apply context-based controls, and restrict agent sessions to the scope needed for a task. Some of the products are available now, while others remain in preview.

The company also cited BlackRock and Thomson Reuters as users strengthening security, visibility, and control as they expand AI use. The emphasis on zero-trust principles shows how established cybersecurity models are being adapted to software agents that can act continuously across services rather than through a single user login.

Several partners echoed that point, arguing that AI agents create a new category of identity inside the enterprise that requires tighter control over authorisation, shorter-lived credentials, and clearer records of actions taken.

"One of the biggest gaps in building a secure agentic enterprise is not knowing what your agents can connect to or what they're allowed to do with that access," said Ely Kahn, Chief Product Officer, Okta.

"Through our work with Snowflake and our broader effort to advance Cross App Access as an open protocol for secure AI agent connections, our joint customers can bring third-party AI agents within the identity perimeter. Together, we're helping ensure agents can operate within centralised identity policy, where every action is logged, and access is tightly scoped, before unlocking valuable enterprise data in Snowflake," Kahn said.