Snowflake announced Cortex AI Gateway and a suite of enterprise AI security features at Black Hat 2026. Cortex AI Gateway, built on the acquired Natoma technology, acts as a centralized MCP gateway governing how AI agents — both Snowflake-native and third-party (Amazon Bedrock, Azure AI Foundry, Claude Code, Cursor, LangChain, etc.) — access models, data, and tools. Key capabilities include wide model catalog support, access governance and sprawl control, observability and tracing, and intelligent model routing for cost optimization. On the security side, Snowflake is moving Agent Identity, Restricted Session Scope, and Ransomware Protection via Multi-Party Approval to GA, while launching Data Exfiltration Prevention, Context-Aware Access Policies, and a CoCo CLI VM Sandbox into preview. These features aim to address the growing enterprise AI attack surface created by autonomous agents combining data access, system execution, and data movement.