Snowflake wants to be the gate your agents walk through.
Cortex AI Gateway is a single control point for what agents may access: models, data, MCP servers and tools, with fine-grained authorisation, end-to-end action audit trails and cost-based routing guardrails.

Bit’s takeaway
What changed
Snowflake launched Cortex AI Gateway at Black Hat 2026. It centralises authorisation across more than a hundred MCP servers, captures tool calls and system interactions in real time for audit ('which systems an agent touched and in what sequence'), routes requests on cost, latency and capability with budget guardrails, and covers first-party and third-party agent platforms including Bedrock, Azure AI Foundry, ChatGPT and Claude.
Why it matters
The MCP ecosystem made it easy to hand agents tools; it did not make it easy to say which agent may use which tool on which data. An auditable gate answers the question incident reviews keep asking, what did the agent actually do, but that only holds for traffic that goes through it, and shadow agents will not volunteer.
Who should care
- Data platform teams governing agent access to warehouses
- Security teams needing an audit trail of autonomous actions
What to do
Write the policy before the platform: for one agent you already run, list which tools and data it may touch, and start logging its actions anywhere durable. If you cannot reconstruct yesterday's agent activity today, that gap is the priority, whoever's gateway eventually closes it.
The human take
Tools change fast. Your judgment matters more.
A person defines which agent may touch which data and reads the audit trail; the gateway records and enforces, it does not decide.
Affected guidance
Put this to work
Verified facts
- Snowflake launched Cortex AI Gateway at Black Hat 2026: centralised authorisation across more than a hundred MCP servers, real-time capture of agent tool calls for audit, and cost-based routing with budget guardrails across first- and third-party agent platforms.Checked
Sources and method