On the opening day of Snowflake Summit 26 in San Francisco, the cloud data platform giant made one of its most strategically significant announcements in years: a definitive agreement to acquire Natoma, an enterprise Model Context Protocol (MCP) governance platform. The move signals Snowflake's intent to become the trusted control plane for the agentic enterprise — extending its data governance authority not just to queries and tables, but to every action an AI agent takes on behalf of a business.
The Shadow AI Problem Snowflake Is Racing to Solve
The promise of AI agents is compelling — systems that no longer merely answer questions, but make decisions and take actions across every application, inbox, and workflow a business runs on. Yet for enterprises, that promise has collided with a hard reality: most of the employees experiencing agentic productivity today are doing so entirely outside IT's purview.
Employees have been connecting their own MCP servers and plugging agents into data sources without approval — creating exactly the kind of shadow AI risk that keeps CISOs awake at night. Proprietary data potentially flows to unvetted models. Agents access systems they have no business touching. And unlike human users, agents behave differently: they can explore paths, call APIs, and attempt workflows in ways that require clear boundaries and continuous oversight.
Snowflake's answer is Natoma — a centralized MCP gateway that enforces identity, policy, and audit controls at the tool-call level, making it possible to give people the magic of agentic productivity while maintaining a single point of control over what those agents can access and do.
"AI agents are quickly becoming part of how enterprises operate, but intelligence without governance creates risk. Agents don't just need access to data. They need the right context, permissions and policy guardrails to operate safely inside the enterprise."— Sridhar Ramaswamy, CEO, Snowflake
What Natoma Brings: Governed MCP at the Tool-Call Level
Natoma's platform serves as the control and governance fabric for enterprise AI agent connections. For every action routed through Natoma, the platform provides full visibility into who requested the action, what permissions they hold, and whether the action is permitted — extending accountability to the new surface area of tool calls and cross-application workflows.
Following close, Natoma's capabilities will be integrated into Snowflake's AI Data Cloud, enabling customers to securely connect Cortex Agents, Snowflake Intelligence, and Cortex Code to the enterprise systems they use daily — spanning SaaS applications, cloud environments, VPCs, and on-premises infrastructure — all through governed MCP servers. Users will be able to correlate and enrich trusted Snowflake data with real-time context from Slack, email, CRM platforms, Jira, internal APIs, and databases.
Snowflake has already been running Natoma internally. Mayank Upadhyay, Snowflake's Chief Security and Trust Officer, noted the immediate productivity gains: the platform now summarises unread emails, searches across Slack and Google Drive, and surfaces relevant information without context-switching across five different tools — all within a governed environment. The intent is for this experience to scale across Snowflake's entire enterprise customer base.
Why Analysts Say Governed MCP Is the Next Battleground
Industry analysts are broadly supportive of the acquisition's strategic rationale. Phil Fersht, CEO of HFS Research, was direct: "MCP is becoming the connective tissue for enterprise agents, but without identity, policy, privileged access controls, and auditability, it can quickly become a shadow AI risk." He argued that simply supporting MCP is insufficient — the real value lies in governed MCP with verified servers, identity-aware authorisation, policy enforcement, and gateway control.
Robert Kramer, managing partner at KramerERP, reinforced the distinction: "MCP is a protocol, not a governance model by itself. It can standardise connections, but it can also standardise risk if access is too broad, tools are poorly governed, or agents are trusted too quickly." The watchpoints, analysts say, include identity-aware permissions, least-privilege access, audit trails, human-in-the-loop approval for high-risk actions, data leakage controls, and clear ownership when an agent makes a wrong decision.
For Michael Ni, principal analyst at Constellation Research, the acquisition reflects something bigger: Snowflake's bid to own the AI control plane entirely. "Data platforms won the analytics era. Whoever governs agents, context, and autonomous actions wins the agentic era. Natoma gives Snowflake the missing layer between insight and execution," Ni observed.
"Data platforms won the analytics era. Whoever governs agents, context, and autonomous actions wins the agentic era. Natoma gives Snowflake the missing layer between insight and execution."— Michael Ni, Principal Analyst, Constellation Research
