They call it a gateway. The name suggests a harmless door, a threshold you pass through. But after watching two identity acquisitions close in seventy-two hours, I have come to see gateways as something more dangerous: the new architecture of corporate power. When Cyera announced its $1 billion acquisition of Oasis, and Okta followed with roughly $200 million for Permiso, the market was not buying models. It was buying access control over AI agents. The code compiles, but does it heal? That question moved from philosophy to balance sheet in the same week that Snowflake introduced Cortex AI Gateway. This is not a product story. It is a power story. And the protagonist is not Snowflake, but the thin, mostly unacknowledged layer of software that decides whether an agent is allowed to call a tool, read a file, or execute a transaction.
To understand why gateways matter, you need to understand MCP. Model Context Protocol is Anthropic's open standard for connecting AI applications to external tools. For a long time it was a convenience layer. Developers could expose a database, an API, or a spreadsheet to an agent with a few lines of configuration. Then the ecosystem grew. Agents began navigating enterprise systems, triggering workflows, and moving money. The protocol became the nervous system of the modern enterprise, and the seam became a security boundary. A stateless specification revision followed, the largest since the protocol's launch, focused on scalability and modularity. It marked a turning point: MCP was no longer a developer tool; it was infrastructure.
Snowflake entered the market with a clear narrative: data interoperability is over, agent interoperability is the next ten years. Cortex AI Gateway is the productification of that narrative, built on the acquisition of Natoma, an identity-aware policy engine. The idea is to enforce identity, policy, and audit at the tool-call layer. In plain terms, an agent requests a tool call; the gateway intercepts the request, verifies who the agent is, checks what it is allowed to do, and writes a record that a human auditor can later inspect. It is governance as infrastructure. And it is a hard problem.
The Architecture Is a Commitment
From my experience auditing identity architecture for tokenized assets, I have learned that a gateway is not a single box. It is a relationship. Cortex AI Gateway inherits Natoma's capability to map tool calls to identity, policy, and audit. On paper, that is exactly what an enterprise needs. In practice, the unsolved questions are alarming. Does the gateway sit at the edge of the model, between the agent and its tools? Or is it inline on the request path, adding latency to every function call? Does it support streaming tool calls and streaming audit logs, or does it batch events after the fact? There are no public throughput numbers. There are no independent benchmarks. There is no documentation of how a stateless MCP protocol coordinates with the stateful requirements of policy enforcement.
This silence is not a normal startup delay. Silence is the loudest indicator of systemic rot. I have seen this pattern before: a product launches with a beautiful governance narrative, and the operational details are absent because the engineering team is still working on them. The code compiles, but does it heal? Not if it cannot audit itself.
The Centralization Paradox
The critical technical question is not whether MCP gateways can enforce identity. It is what happens when the gateway itself becomes the bottleneck. Every agent in the enterprise needs to call tools, and every call now passes through one policy engine. That creates a centralized chokepoint with a beautiful audit dashboard. The security team finally has visibility. The attacker has a target. If the gateway is compromised, every agent's tool access can be observed, altered, or blocked.
This is the same paradox we have seen in DeFi. Liquidity fragmentation is sold as a problem requiring a new aggregator, but the aggregator itself becomes the largest pool of concentrated risk. Gateways are the new aggregators. They are single points of failure wearing a compliance badge. The industry pretends this is decentralization because the model is open, but the control plane is closed. That is not infrastructure. That is a trust monopoly.
This reminds me of the Layer2 sequencer debate. For two years, we were promised decentralized sequencing. What shipped was a centralized sequencer with a decentralized escape hatch. The gateway market is walking down the same road. It will take years before enterprises admit that the gateway is just another party they need to trust. A gateway infrastructure that cannot be independently audited is not a solution. It is a new trust layer wearing a security jacket.
The Managed Gateway Pivot
Commercialization confirms the direction. Snowflake's quarterly product revenue is $1.33 billion. That gives it an enterprise sales force, a cloud platform, and the patience to wait out rivals. It also gives it a powerful bundling option. Cortex AI Gateway can be attached to existing data cloud subscriptions, reducing the friction of buying a new security product. The seven identity partners — 1Password, Aembit, Cyera, Linx Security, Okta, SailPoint, Saviynt — are not only integrations. They are channels. Each one opens a path to a different enterprise security budget.
This is the managed service pivot. The article concludes that adopting managed gateway infrastructure may be the only way to scale proxy operations safely. I agree, but I would add a warning: managed means centralized, centralized means auditable only by those who control the ledger, and the ledger is not a blockchain. It is a database. The economics favor the platform vendor. The governance favors whoever owns the logs. When I drafted ethical governance guidelines for tokenized assets in 2024, I fought for transparent algorithmic auditing clauses. I learned that the hardest clauses are not about the model. They are about who has the right to see the audit trail. Cortex AI Gateway will be measured by that same standard.
We still do not know whether the product will be priced per call, per seat, or bundled into the existing data cloud subscription. That absence of pricing detail is itself informative. Snowflake is not selling a utility; it is selling a platform relationship. The customer does not buy a gateway. The customer buys an operating system for enterprise AI. Whether that is good or bad depends on who can read the logs.
Identity M&A Is a Proxy for Protocol Value
The market is already crowded. We now have API management platforms like Kong, agent runtimes like Diagrid, dedicated MCP gateways like MintMCP, proxy platforms like Lunar.dev, agent platforms like Obot, and security identity platforms like Arcade. Add the hyperscale clouds with their built-in agents, and the battlefield is enormous.
The competitive advantage is no longer the ability to provide a gateway. It is the ability to provide real-time agent behavior visibility and end-to-end audit tracking. Snowflake is not entering this market to fight every vendor. It is entering to own the enterprise point of view. The platform advantage is the customer base. The protocol-native advantage belongs to the smallest, fastest startups. My suspicion is that Snowflake is willing to lose the gateway product and still win the data cloud lock-in. If a gateway is how enterprises wire AI into their data, Snowflake would rather own the wiring than the switchboard.
The $1 billion Cyera-Oasis deal and the Okta-Permiso acquisition happened in a single week. That is not a coincidence. Traditional identity vendors realized they cannot build MCP-native security in time, so they bought it. The premium on first-generation MCP security assets reflects a window, not a moat. The same thing happened in crypto when exchanges bought custody providers overnight. Speed becomes more important than architecture when the protocol burns.
Attackers, Lawyers, and the Adoption Gap
Meanwhile, NadMesh, the botnet, has declared MCP its top attack surface. That means the adversary is prioritizing the same layer as the enterprise. There is a race between defense infrastructure and exploitation infrastructure, and the exploitation side has a head start.
A new legal case, Runlayer v. Rippling, has been filed in the Southern District of New York, the first major intellectual property dispute over MCP. No one goes to court over infrastructure that does not matter. The combination is rare: attackers, lawyers, and corporate security teams are all looking at the same seam. That seam is the gateway.
The adoption gap is another silence. The statistic that 57% of organizations report significant security and risk management skill gaps is buried in the article. I want to pull it out and scream it. A gateway does not reduce the need for human judgment; it increases the consequences of misconfiguration. If the policy engine is configured by someone who has never thought like an adversary, the audit log becomes evidence of trustlessness, not trust. Deploying a gateway without deploying sophisticated defenders is like encrypting a vault and leaving the key under the mat.
The code compiles, but does it heal? No. It just looks responsible.
The Open Standards Question
The biggest unspoken risk is that the entire gateway ecosystem is built on a protocol no one controls. MCP is driven by Anthropic. Snowflake, Okta, and Cyera are building walls on someone else's land. If Anthropic changes the governance model, or the open source license tightens, the gateway layer is exposed. This is not a hypothetical. The history of open protocols is full of moments when a contributor becomes a gatekeeper and the ecosystem loses its breath.
What would a healthier gateway architecture look like? It would have a public, machine-readable policy language. It would have signed audit logs that can be verified without the vendor's permission. It would have an open standard for expressing the provenance of a tool call. It would allow a company to deploy several gateways from different vendors and verify them against the same immutable audit record. In other words, it would look like the decentralized systems we claim to believe in.
The Blockchain Parallel
For a blockchain-native audience, the most useful way to understand Cortex AI Gateway is to treat it as a permissioned smart contract engine for AI tools. It is not a smart contract on a public chain. It is a smart contract executed in a private database, with a proprietary oracle layer and a commercial dispute resolution forum. That does not make it useless. But it makes it a trust holder, not a trustless system.
In 2017, I refused to pitch technical whitepapers to venture capitalists. Instead, I wrote a 40-page manifesto called The Moral Architecture of Trust. The market thought I was naive. But the message was simple: cryptography does not create trust; it creates conditions in which trust can be verified. The same is true for gateways. An encrypted audit log is not proof of safety. It is proof of a claim that safety may be verified. The difference between a blockchain and a database is not that the database is wrong; it is that the database's authority is implicit, while the blockchain's authority is contestable. The gateway industry is choosing the database. That does not make it evil. It makes it fragile.
When trust becomes a database, the company that owns the database owns the truth. In times of crisis, that owner will face the same accusations we leveled against banks and exchanges after 2008 and 2022. The exact same cycle is already visible in the early MCP lawsuits. Runlayer v. Rippling is not a fringe case. It is a signal that the protocol has become economically valuable enough to fight over. If we do not build independent audit mechanisms before the next crash, the silence after the crash will be even louder.
After the Terra collapse in 2022, I spent six weeks offline, recording fourteen case studies of financial trauma caused by algorithmic promises. One lesson followed me: the complexity of the system was designed to distract from the centralization of its control. The gateway industry is not algorithmic stablecoins. But it is algorithmically enabled trust. The best way to honor the lessons of the crash is to ask, before every architecture diagram, who is the ultimate authority and can we audit them?
What Enterprises Should Ask
So, what should an enterprise ask before buying a gateway? First, where is the audit log stored? Who can modify it? How long is it retained? Is it stored in a format that supports cryptographic verification? Second, what happens when the gateway goes down? If an agent cannot call a tool because the gateway is offline, is that an availability attack? Third, can the gateway detect a malicious MCP server, or does it merely record the damage? Fourth, does the gateway support policy arbitration when multiple identity sources disagree? Okta says one thing, SailPoint says another, Cyera says a third. Who wins? The answer cannot be 'the vendor's cloud.' Finally, is the gateway in the path or out of the path? If it is out of the path, it is a monitoring tool. If it is in the path, it is a transaction processor. Those are completely different risk profiles.
I have asked these questions to the founders of three MCP gateway startups. The response is usually a pause, a smile, and a promise to send documentation. Trust is not encrypted; it is woven. Woven into every access decision, every audit record, every crisis response. Trust is not encrypted; it is woven. Woven into every access decision, every audit record, every crisis response.
The Contrarian Angle
The contrarian angle is that Snowflake's move may actually be a recognition of exhaustion, not strength. The data cloud is mature. The frontier has shifted upward from storage to application governance. That is why the company needs Cortex AI Gateway. But a gateway controlled by one vendor, or by a coalition of seven identity vendors, is not the decentralization we are promised in open protocols.
I say this as someone who has seen VCs manufacture the liquidity fragmentation narrative to sell new DeFi products. MCP gateway infrastructure is a real technical need, but the narrative that every enterprise must buy a dedicated gateway may be manufactured for the same reason: to create a new product category in a market that is already too complex. The real winner may be the one who can guarantee audit integrity, not the one with the biggest dashboard.
There is also a quieter cultural issue. The teams building these gateways are overwhelmingly homogeneous. I launched a mentorship program called Women of the Chain, and I have seen how homogenous decision-making creates blind spots. A security product designed by people who all think alike will miss the attacker who thinks differently. The gateway layer is not exempt. Diversity is not a branding exercise; it is a reconnaissance advantage. When a product is built by a single way of seeing, it becomes fragile in exactly the place it cannot see.
Another way to put this is that a gateway is not only a technical artifact. It is an expression of institutional values. If the people designing the access rules have no idea how a warehouse worker, a nurse, or a journalist would use an agent, the rules will be wrong in ways that no penetration test will find. The most dangerous vulnerability is not a SQL injection. It is an assumption baked into the policy language by someone who has never been outside the room.
The market wants to sell gateways as neutral infrastructure. But there is no neutral infrastructure. There are only structures that make their value assumptions visible and structures that hide them. The gateway hides them behind an audit log. The question is not whether the gateway can log everything. The question is whether the log can be questioned.
What Comes After the Gateway
MCP gateway infrastructure is the new bank vault. We have to decide who holds the keys. The next generation of trust will not be built by encryption alone. Trust is not encrypted; it is woven. It is woven by transparent audits, by open standards, by identity systems that do not become surveillance systems, and by organizations that treat security as a craft rather than a checkbox.
The gateway is necessary. It is not sufficient. Feminine wisdom asks not 'what can we build?' but 'who are we becoming?' I would like to believe we are becoming the kind of industry that demands to see the audit logs before it celebrates the announcement. Until then, the market will keep racing toward the gateway, and the silence will keep growing.