
Snowflake announced Cortex AI Gateway, a centralized control layer designed to govern how AI agents access enterprise data, tools, and models. The gateway is part of Snowflake’s effort to position itself as the control plane that decides what AI agents are allowed to do with enterprise data.
Alongside the gateway, Snowflake unveiled a first wave of security integrations with 1Password, Aembit, Linx Security, SailPoint, and Saviynt. This lineup of identity vendors, who often compete with one another, are now aligned around a shared trust model for autonomous agents.
Mayank Upadhyay, Snowflake’s chief security and trust officer, said, “The next era of AI won’t be built through more walled gardens. It will be built through secure agent interoperability.” He argued that if every vendor builds a closed ecosystem of agents, enterprises will recreate the fragmentation they’ve spent years trying to solve.
Decades-old enterprise security models break when AI agents become the actors. Traditional security was built for a world where humans were the actors, but AI agents change that completely. The challenge isn’t that AI creates entirely new security problems, but that AI exposes the blind spots that have always existed.
Nancy Wang, chief technology officer of 1Password, described the failure mode in more visceral terms. When agents first arrived, the default pattern was to give the agent credentials and let it act as a human. However, this approach is dangerous, as an agent can exfiltrate data if it’s subject to a prompt injection.
The audit trail becomes equally useless. For example, if an agent sends a couple million dollars to an offshore account, the audit logs will show that the action was taken by the human who authorized the agent, rather than the agent itself.
Related: Honda discontinues its sole US electric vehicle
Cortex AI Gateway functions as a connective layer for all trusted agent activity. It governs both first-party agents built inside Snowflake and third-party agents built on external platforms. The gateway centralizes access policies, authentication, permissions, and audit logging in a single place.
The gateway also addresses the problem of runaway AI spending. It gives IT and finance teams a unified view of AI consumption, attributes costs to the specific teams, agents, or workloads driving them, and enforces spending limits before bills spiral.
Upadhyay described how those costs compound in practice. “AI is dynamic. Agents can invoke multiple models, call different tools, and execute multi-step workflows, creating consumption patterns that can change from one task to the next.”
The technical centerpiece of the partner integrations is what Snowflake calls dual attribution. By logging both the verified non-human identity of the agent and the specific human who authorized the task, Snowflake ensures task-scoped access and complete auditability for every action taken across the enterprise.
Wang explained how 1Password’s piece works at the protocol level, pointing to emerging standards like OIDC-A. “The human first authorizes the agent to do a specific task, and then the agent receives a delegated task-specific token… as part of that token, that is where you learn of the original delegator identity and also the intent behind the task.”
The intent-preservation problem is subtle, Wang noted, because enterprise tasks decompose into enormous chains of individual operations. Keeping that intent intact across every step in the chain — and flagging the moment an agent deviates from it — is what Snowflake and its partners are ultimately trying to standardize.
Related: Everything to know before using iPhone key fob
Gartner predicts that by 2027, governance gaps discovered only after production incidents will force 40% of enterprises to demote or decommission autonomous AI agents. IDC expects more than 1 billion actively deployed AI agents by 2029, executing roughly 217 billion actions per day.
Analysts now argue agentic platforms should be treated as decision infrastructure, not productivity software. Against that backdrop, the identity layer is becoming the contested ground, and every major vendor is racing toward the same runtime-governance chokepoint.
Snowflake’s differentiator is proximity to the data itself. As Upadhyay put it, security “can’t just be an API proxy sitting in front of an LLM. It has to anchor all the way down into the underlying data layer, enforcing zero-copy boundaries, dynamic data masking, and real-time exfiltration safeguards before an agent ever touches a row of data.”
The rollout now moves to the proving ground. Cortex AI Gateway enters public preview soon, and the five partner integrations enter private preview. Wang described this phase as a deliberate feedback loop — customers on day one get an agent-access broker plus “a full audit log that will show you, for example, what that agent is actually doing,” even when an agent deviates from its intent.
Upadhyay distilled the wager into a single line: “The future of AI won’t be won by the organizations with the most agents, but by the organizations that can govern those agents with the most trust, visibility, and control.” In the agentic enterprise, it turns out, trust isn’t the guardrail — it’s the product.
They are now focused on honoring women in STEAM to bring more talent to the field.


