Cortex AI gateway creates a central runtime control layer for enterprise AI agents
Snowflake is moving AI governance into the point where agent actions actually run. Cortex AI Gateway is designed to track activity, apply policies, control access, route requests, and manage costs across Snowflake and third-party AI agents.
The product uses governance policies defined in Snowflake’s Horizon Catalog. It also incorporates technology Snowflake acquired through its purchase of Natoma earlier in May. The goal is to give enterprises one execution layer for agents that need access to AI models, business applications, data, tools, and Model Context Protocol (MCP) servers. MCP is a standard that allows AI applications to connect to external tools and data sources.
This distinction matters. An AI agent does more than generate text. It can call software tools, retrieve company data, interact with other systems, and execute a sequence of actions. Governance therefore has to cover what happens during execution.
Artin Avanes, Head of Core Data Platform at Snowflake, said Cortex AI Gateway “acts as an execution layer.” According to Avanes, its purpose is to provide “a trusted control plane” for how agents securely access models, tools, MCP servers, enterprise systems, and data.
For CIOs, the central issue is control as the number of agents and AI providers grows. Separate controls for each model, agent, and application increase administration and make policy enforcement inconsistent. Snowflake’s approach is to place those controls within the same broader environment where customers already govern enterprise data.
The opportunity is clear, but so is the implementation requirement. A central gateway creates value only if important agent traffic actually passes through it. Agents or applications that bypass the control layer can leave gaps in monitoring and policy enforcement. Executives evaluating the product should therefore focus on coverage across their existing AI architecture, including third-party services, rather than assuming centralization alone delivers complete governance.
Runtime evidence fills the main governance gap in agentic AI
The core governance problem is visibility into actions. Many existing AI gateways route requests to models and record prompts. That can work for conventional generative AI applications, but autonomous agents introduce a broader control problem because they can perform multi-step tasks across several systems.
Michael Leone, Principal Analyst at Moor Insights & Strategy, identified this limitation directly. He said, “Most enterprises cannot see or govern agent activity consistently across models, tools, MCP servers, and enterprise systems, as most AI gateways just route models and log prompts.”
Cortex AI Gateway is intended to extend monitoring beyond that model-level view. Enterprises need to establish which agent performed an action, who authorized that agent, which resources it used, and what happened at each stage of execution. Those records can support security investigations, audits, access reviews, troubleshooting, and policy enforcement.
Stephanie Walter, Practice Lead of AI Stack at HyperFRAME Research, framed this as a requirement for reliable control. “Enterprises need to know which agent acted, who authorized it, what resources it used, and what happened at each step,” Walter said. “Without that runtime evidence, firms cannot reliably secure, audit, or contain agentic workflows.”
That last point is important for executives. An agent can have legitimate access to individual systems while still producing an undesirable sequence of actions. Static permissions alone do not explain what happened after access was granted. Runtime records provide the evidence needed to reconstruct the sequence and determine whether actions complied with policy.
This also changes what executives should demand from AI governance platforms. Prompt logs are no longer enough. Governance needs identity, authorization, resource usage, and action-level traceability across the full workflow. As agent deployments grow, the operational requirement is not simply to know what models employees use. It is to know what agents are allowed to do and what they actually did.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.
Combining AI governance and FinOps gives CIOs direct control over AI costs
AI spending becomes harder to manage when every model and agent generates usage-based charges. Model and agent providers are moving toward consumption-based pricing, so costs depend on actual use rather than a predictable fixed fee.
Cortex AI Gateway addresses governance and financial operations, or FinOps, through the same control layer. FinOps is the practice of tracking, allocating, and optimizing technology spending based on actual consumption. In an AI environment, this can mean identifying which agent, application, team, or workflow consumed a resource and connecting that usage to its cost.
This design has a practical benefit. Security governance and cost governance need much of the same information. Both require records of identity, activity, resource consumption, and individual transactions. A shared control layer can use those records to enforce access policies while also determining where AI spending occurs.
Michael Leone, Principal Analyst at Moor Insights & Strategy, said embedding agent governance and related FinOps where enterprise data is already governed could reduce the governance burden as deployments scale. This is central to Snowflake’s strategy. Rather than asking CIOs to operate another independent management environment, Cortex AI Gateway applies these controls alongside Snowflake’s existing data-governance capabilities.
Scott Bickley, Advisory Fellow at Info-Tech Research Group, described combining FinOps and governance as a “logical” move because the two functions need “much of the same” data and traceability logs. He also identified consumption pricing as an important source of complexity. CIOs need to know who is consuming AI resources, what that activity costs, and whether the spending complies with company policy.
The main constraint is attribution. A total AI bill says little about whether the spending creates business value. Executives need to connect consumption to specific agents, workloads, teams, and business processes. A runtime gateway can improve that visibility if it captures enough of the organization’s AI activity and provides sufficiently detailed usage records.
The gateway can reduce developer overhead, but only if it replaces existing complexity
Cortex AI Gateway could remove several infrastructure tasks from application teams. Developers commonly need credentials for different AI providers, logging systems, usage and cost tracking, and access controls. Snowflake aims to consolidate these functions within one application layer.
Scott Bickley, Advisory Fellow at Info-Tech Research Group, said a well-implemented gateway should simplify development by consolidating provider credentials, logging frameworks, cost and usage instrumentation, and access-control mechanisms. That can reduce the amount of supporting infrastructure each development team must configure and maintain.
The potential business benefit is broader than developer convenience. Standard controls can make new AI applications easier to approve and operate. Security teams can apply consistent access rules. Finance teams can obtain standardized consumption records. Development teams can spend less time reproducing governance functions for individual applications.
But centralization can also create a new dependency. Bickley warned that the gateway could become a bottleneck if developers are forced to use multiple gateway products. Instead of removing complexity, overlapping governance layers could add integration work and delay development.
This is the key implementation test for technology leaders. A gateway should replace fragmented controls rather than sit on top of them without removing anything. CIOs and CTOs should examine how Cortex AI Gateway works with existing API gateways, identity systems, security controls, observability platforms, and AI-provider gateways before standardizing on it.
They should also consider the effect of central policy enforcement on development workflows. Strong controls are valuable, but policy changes, approvals, or gateway failures can affect many applications when enforcement is centralized. Enterprises need clear ownership, reliable operations, and processes that allow legitimate development work to proceed without bypassing governance.
The public preview will test whether cortex AI gateway can deliver enterprise-scale governance
Snowflake plans to put Cortex AI Gateway into public preview soon.
Enterprises should use this period to test the product against real agent workflows. The most important question is coverage. Cortex AI Gateway needs to govern activity across Snowflake and third-party agents, AI models, tools, Model Context Protocol (MCP) servers, enterprise applications, and data sources. Gaps in that coverage would reduce the value of centralized governance.
Executives should also test whether the gateway provides the level of traceability described by analysts. That includes identifying the agent taking an action, the user or system that authorized it, the resources consumed, and the sequence of actions performed. These records need to be useful for security investigations, compliance reviews, operational troubleshooting, and cost attribution.
Cost control deserves equal attention. Consumption-based AI pricing can distribute spending across providers, agents, applications, and business units. During the preview, CIOs should determine whether Cortex AI Gateway can connect that consumption to specific workloads and enforce spending policies without creating excessive administrative work.
Developer impact is another key measure. The product has the potential to consolidate credentials, logging, access controls, and cost instrumentation. But Scott Bickley, Advisory Fellow at Info-Tech Research Group, warned that gateways can become bottlenecks if developers must work with multiple overlapping products. Enterprises should therefore measure integration effort, approval times, operational complexity, and any effect on application performance.
The public preview also gives Snowflake an opportunity to demonstrate whether the technology acquired through Natoma can operate effectively as part of its broader data and AI platform. Snowflake’s decision to integrate agent controls with Horizon Catalog indicates a strategy of keeping AI governance close to existing enterprise data governance rather than operating it as a separate function.
Key takeaways for leaders
- Centralize AI agent control: Cortex AI Gateway puts runtime tracking, access policies, request routing, and cost controls into one layer. CIOs should assess whether it can govern both Snowflake and third-party AI environments without leaving visibility gaps.
- Demand runtime evidence: Prompt logs are insufficient for agents that can act across tools and enterprise systems. Require traceability that shows which agent acted, who authorized it, what resources it used, and what happened at each step.
- Connect governance with AI spending: Consumption-based pricing makes accurate cost attribution essential. Leaders should evaluate whether the gateway can link agent activity to spending and enforce financial policies across teams and workloads.
- Reduce developer complexity rather than add to it: Consolidating credentials, logging, usage tracking, and access controls could reduce engineering overhead. Test whether Cortex AI Gateway replaces existing controls or creates another layer developers must manage.
- Use the public preview to validate the claims: Snowflake has not disclosed pricing, customer adoption, performance benchmarks, or quantified savings. Enterprises should test governance coverage, cost attribution, integration effort, reliability, and developer impact before committing to broad deployment.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.


