Snowflake today unveiled the Cortex AI Gateway and several AI security innovations that lay the foundation for trusted interoperability between secure agents, enabling organizations to securely scale their agent-based businesses.

Cortex AI Gateway addresses two of today’s biggest barriers to enterprise AI adoption by helping organizations protect AI agents while providing centralized visibility and control over AI consumption costs.

As AI agents increasingly collaborate across enterprise data, applications, and platforms, they introduce unprecedented security and governance risks while driving growing AI consumption across diverse models and workloads. Traditional security architectures were not designed for this level of agent activity between different systems, and organizations often lack a centralized way to govern the use of AI.

This requires a new security and cost model where trust enables interoperability in every AI interaction. Today, Snowflake solidifies the foundation for a secure agent ecosystem, where agents can interoperate across the entire enterprise with the trust, visibility, control, and cost oversight that businesses need.

Snowflake introduces the Cortex AI Gateway, a critical advancement that enables enterprises to securely control, orchestrate, and govern both first-party AI agents built within Snowflake—such as Snowflake CoWork and Snowflake CoCo—and third-party AI agents built on external platforms such as Claude Code and Cursor. Cortex AI Gateway provides enterprises with a unified foundation for governing how agents access models, tools, MCP servers, and enterprise systems; intelligently route agent requests; and optimize AI consumption between different models and workloads. As a result, teams gain greater visibility and control over AI access, agent activity, and token usage, helping to prevent runaway AI costs.

Cortex AI Gateway builds on Snowflake’s acquisition of Natoma, bringing the capabilities of Natoma’s enterprise MCP platform directly into Snowflake’s platform for secure, enterprise-grade agent interoperability. Snowflake also announced new integrations for secure third-party agent access⁴ with Aembit, 1Password, Linx Security, Okta, SailPoint and Saviynt, setting a new standard for how enterprises govern and audit AI agents across the security ecosystem.

“Enterprise AI is moving from data interoperability to agent interoperability, and security must be at the heart of that transition,” said Mayank Upadhyay, Chief Security and Trust Officer at Snowflake. “Agent interoperability only works when enterprises can trust the way agents on different platforms access data, invoke tools, and take action on behalf of users. Snowflake provides the visibility, governance, and control capabilities necessary to make that interoperability secure for AI in production. The future of the agent-based enterprise will not be built on closed ecosystems, and Snowflake is the trusted control plane that enables secure enterprise work.”

Powering centralized AI portal

For AI agents to deliver real business value, they need secure access to models, data, applications, and tools that provide full business context. Today, those resources are fragmented across multiple systems and providers, forcing teams to create and maintain custom connections while managing access, activity, and costs through disconnected controls.

Cortex AI Gateway solidifies Snowflake’s role as a secure layer of AI interoperability for the agent-based enterprise, establishing the portal that helps organizations centrally govern how AI agents access and use models, data, applications and tools. For organizations like Meltwater, Cortex AI Gateway offers a path to making agents more useful, observable, and ready for production environments.

“At Meltwater, we help organizations make sense of rapidly evolving external data and transform information into action. As AI becomes more integrated into that work, security and trust are critical to delivering value,” said Aditya Jami, Chief Technology Officer at Meltwater. “We see the Cortex AI Gateway as a step toward ensuring our agents can securely connect to the right data and tools, helping us deliver trusted AI-powered insights faster, while maintaining the security and control our customers expect.”

Cortex AI Gateway enables companies to:

  • Govern Every Agent Connection
  • See and Understand Every Agent Action
  • Keep AI consumption costs under control

Optimize model selection and performance: Businesses need the flexibility to use multiple models, while ensuring that each request is directed to the appropriate model for that task. Cortex AI Gateway intelligently routes requests to enterprise-approved models, optimizing quality, cost, latency, and availability while maintaining centralized governance.

Advances in secure access

For AI agents to deliver meaningful business value, they must operate securely across platforms. However, many providers still default to closed ecosystems, making it difficult for third-party agents to operate across organizational boundaries. Security is the key to unlocking that interoperability, establishing the trust, identity, and access controls that agents need to work securely across multiple platforms.

Snowflake is laying the foundation for secure third-party agent access across the entire security ecosystem, with the first wave of integrations from leading security vendors such as 1Password, Aembit, Linx Security, Okta, SailPoint and Saviynt.

To enable enterprises to deploy third-party agents with consistent security and control, these integrations are designed with the following goals:

Make third-party agents governable: Enterprises can now move beyond the blind spot of agents acting under broad user credentials. With the new integrations, security teams have a clearer view of which agent accessed which data, through which platform, and under whose authority.

Allow limited agent access to the task: Third-party agents should not inherit all the permissions that a user has just because they are acting on their behalf. Snowflake’s approach limits agent access to only what the task requires, creating a more secure model for using agents across the enterprise’s data ecosystem.

Extend consistent governance across agent ecosystems: These integrations represent an important milestone for the security industry by helping to pave a path toward secure agent interoperability between different platforms.