Snowflake's Cortex AI Gateway puts agent activity logs and token attribution on the same control plane—because if finance can't see which workflow burned the tokens, nobody is governing AI.

Via SiliconANGLE: Snowflake debuts Cortex AI Gateway to govern and monitor enterprise AI agents
Finance is finally asking which agent burned the tokens. On July 28, 2026, Snowflake introduced Cortex AI Gateway—a control layer meant to connect, govern, and monitor AI agents as they reach models, tools, Model Context Protocol (MCP) servers, and internal systems. The product pitch is enterprise plumbing. The business lesson is smaller and sharper: if you cannot attribute AI spend to a workflow, you cannot govern it.
Snowflake cast the gateway as connective tissue for the “agentic enterprise,” the point where autonomous software stops merely retrieving information and starts acting across corporate data and applications. Traditional security stacks were not built for that cross-system thrashing. Without a consistent view of what agents did—and what those agents cost—boards get slide decks and invoices get mysteries.
That mystery is already a management problem for owner-led firms. A Claude Code session, a Cursor agent, an internal CoWork helper, and a half-documented Zap chat can all look like “AI spend” on the credit card. Only one of them might be producing ROI. The rest are ambient burn.
Cortex AI Gateway’s answer, per SiliconANGLE’s reporting, is end-to-end activity logs plus token attribution across models, teams, and workloads—with spending limits finance and IT can enforce. You do not need to be a Snowflake shop for that principle to matter. You need someone who can answer, in plain English: which workflow spent what, under whose authority, and against which budget.
Agents stopped being demos the moment they started calling tools. Cortex AI Gateway is designed to govern agents built inside Snowflake—including CoWork and CoCo—alongside third-party agents on platforms such as Claude Code and Cursor. SiliconANGLE reports support for more than 100 MCP servers, with centralized access policies, authentication, and permissions deciding which models, data, applications, and tools each agent can touch.
The product builds on Snowflake’s May agreement to acquire Natoma Labs, an MCP governance startup. Natoma’s technology is positioned as an enterprise-grade MCP platform for brokering secure connections between agents and the systems they act on. In other words: the industry is admitting that “connect everything” without a broker is how you get silent data walks and surprise bills.
Access control is only half the story. The gateway keeps a single log of which agent did what, which tools and systems it reached, and the order of steps it followed. It also tracks token consumption, attributes those costs to the agents driving them, and lets teams set spending limits—a hedge against runaway bills when agents run at scale.
Snowflake’s chief security and trust officer, Mayank Upadhyay, framed the shift bluntly: enterprise AI is moving from data interoperability to agent interoperability, and security has to sit at the center. Agent interoperability only works, he argued, when enterprises can trust how agents from different platforms access data, invoke tools, and take action on behalf of users. Closed agent ecosystems are not the future he is selling; a trusted control plane is.
Snowflake also announced a first wave of secure third-party agent access integrations with identity and security vendors Aembit, Linx Security, SailPoint, Saviynt, and 1Password (AgileBits). The common blind spot they target: an agent operating under a user’s broad credentials, so nobody can tell which agent reached which data and under whose authority. Generally available security updates cover AI risk posture, verified agent identity, and sensitive-data shielding; task-scoped session controls remain in private preview. Cortex AI Gateway itself is due in public preview soon, with the third-party access integrations following in private preview.
You do not need Snowflake’s stack to borrow the operating discipline. Owner-led SMEs can treat agent spend attribution as a weekly control, not a future enterprise project.
The point is not to become a platform company. The point is to make “which agent burned the tokens?” a boring, answerable question.
"Enterprise AI is moving from data interoperability to agent interoperability, and security has to be at the center of that shift." — Mayank Upadhyay, Snowflake chief security and trust officer
Attribution without ownership decays into another dashboard nobody opens. AgentsROI’s Managed AI Operations is built for the boring middle: monitoring what runs, optimizing what pays, and governing what would otherwise drift—so token spend maps to workflows instead of mystery invoices.
For firms that need a senior decision owner without a six-figure hire, a Fractional AI Officer sets the operating tempo: which agents are allowed, which MCP paths are in scope, where spending limits live, and how finance gets a weekly answer that is not marketing theater.
We stay vendor-neutral. Cortex AI Gateway may be the right control plane for Snowflake-centric enterprises. Owner-led firms often need the same outcomes—activity visibility, spend attribution, access discipline—without waiting for a public preview or a platform migration. Stop guessing; start governing what runs. Someone needs to own the operating tempo.
If your AI bill is rising faster than your confidence in what produced it, that is not a model problem. It is an operations problem.
Snowflake’s July 28 announcement is another signal that agent interoperability and cost control are arriving as the same product conversation. Public preview for Cortex AI Gateway is coming; some controls remain private. The durable takeaway for SMEs is already clear: attribute AI spend to workflows, log agent activity, and put a human owner on the operating tempo.
If you cannot say which agent burned the tokens, you are not governing AI—you are sponsoring it. Want a plain-English read on your agent paths, MCP exposure, and monthly burn? Start with Managed AI Operations, or bring in a Fractional AI Officer to own the cadence.
This article summarizes publicly reported information and is for general informational purposes only. It does not constitute legal, tax, financial, investment, security, or compliance advice. AgentsROI.ai is not a law firm, accounting firm, or registered investment adviser. Facts, pricing, statistics, and product capabilities cited here reflect the sources listed at the time of writing and may change. Readers should verify current information independently and consult qualified professionals regarding obligations specific to their industry, jurisdiction, and circumstances—including applicable New York State and New York City requirements. AgentsROI.ai may have commercial relationships with vendors mentioned; where material, such relationships are disclosed. Nothing in this article is an endorsement of any specific AI product, model, or provider.