Virtual Round Table · Jul 22

View the event
Snowflake and Databricks Race to Govern the Agents, and Their Own Spend Caps Miss Most of the Bill
Digital Transformation

Snowflake and Databricks Race to Govern the Agents, and Their Own Spend Caps Miss Most of the Bill

Both data platforms are buying and building control layers for AI agents, yet Databricks' new spend caps ignore 50 to 80 percent of a typical enterprise's AI bill. The gap is the story CIOs need to price.

PublishedJuly 18, 2026
Read time5 min read
Share

The Control Layer Becomes the Product

The two dominant enterprise data platforms have arrived at the same conclusion at once: whoever governs the agents governs the account. Snowflake is acquiring Natoma, described as an MCP gateway that connects agents to the APIs, workflows, tickets, databases, and applications where enterprise work happens. Databricks has shipped Unity AI Gateway as its orchestration and policy layer for AI workloads. Both moves reflect a shift from governing static queries to governing autonomous actions that reach across systems.

The logic, as InfoWorld frames Snowflake's reasoning, is that if agents act across systems rather than simply generate responses, then policy enforcement, identity controls, and business accountability must move with them. We agree with the premise and note the strategic prize. The control layer is becoming the stickiest part of the enterprise AI stack, because it holds identity, policy, and audit. A vendor that owns that layer owns the switching cost, which is exactly why both platforms are spending to claim it now.

Connectivity Is Not Accountability

The Model Context Protocol has become the shared plumbing that lets agents reach enterprise systems, and both vendors are building on it. The important caution is that MCP standardizes connectivity while leaving governance unsolved. As the analysis puts it, connectivity alone does not create accountability, approval structures, ownership models, or business controls. An agent that can technically reach a ticketing system, an email server, and a database still needs a policy that says which actions require a human and who answers when one goes wrong.

This is where the two platforms are placing their bets. Snowflake pairs the Natoma gateway with Horizon Context, Data Exfiltration Policies, AI Security Posture Management, and multi-party authorization, aiming to attach business controls to agent access. We read the design intent as correct and the execution as unproven, since embedding details remain undefined. For enterprise buyers the lesson is to separate the marketing of a gateway from the substance of its policy engine, and to ask exactly which actions it can block, log, and require approval for.

The Spend Cap That Misses the Bill

Databricks' Unity AI Gateway is the strongest in-platform AI spend tooling either vendor has shipped, with enforced spend caps, cost attribution by user, team, tool, and use case, and routing that recommends models on a quality-versus-cost basis. On its own terms it is a genuine advance, because most enterprises still cannot attribute AI cost to a team or a use case at all. Finance leaders who have watched inference bills climb without a breakdown will recognize the value immediately.

The limitation is the headline. The gateway governs spend only within Databricks. It does not cover direct Anthropic calls, OpenAI usage, Bedrock traffic, or Snowflake Cortex, which for most enterprises running both platforms represents 50 to 80 percent of the total AI bill. A spend cap that sees a minority of spending is a partial control, and partial controls create false confidence. We would caution any CIO against treating a single-platform gateway as enterprise cost governance when the majority of the bill flows through channels it cannot see.

Advisory Routing Versus Enforced Reality

There is a second caveat worth pricing. The gateway's smart routing is advisory, so its model recommendations do not automatically bind the workload. The bill reflects the code that engineers actually authored, not the cheaper option the gateway suggested. That gap between recommendation and enforcement is common in early governance tooling, and it matters because a control that advises without enforcing depends on discipline that busy teams rarely sustain.

For enterprise leaders the distinction between advisory and enforced controls should be a procurement question, not a discovery after the invoice arrives. We would press vendors on which policies are hard limits and which are suggestions, because the difference determines whether governance actually shapes behavior. An enforced spend cap changes what runs. An advisory one produces a dashboard that explains, after the fact, why the budget was missed. Both have value, and confusing them is how AI cost governance quietly fails.

Why the Control Plane Sits Above the Platform

The uncomfortable conclusion is that neither platform can govern the full agent estate, because the estate spans model providers, clouds, and both data platforms at once. A gateway that governs its own territory well still leaves the majority of agent actions and AI spend outside its view. This pushes the real control plane above any single vendor, into a layer that spans Anthropic, OpenAI, Bedrock, Cortex, and both warehouses with consistent policy, identity, and audit.

We read this as a build-versus-buy decision that most enterprises have not framed yet. Buying deeper into one platform's gateway is convenient and improves governance inside that platform's walls. It does not deliver estate-wide control, and treating it as if it does is the trap. The enterprises that will manage agents at scale are the ones that insist on a vendor-neutral control plane, capture spend and actions across every provider, and use the platform gateways as enforcement points beneath it rather than as the whole answer.

Tagged#news#digital-transformation#enterprise#cio#erp#strategy#governance#snowflake#databricks#unity-ai-gateway#mcp#ai-spend-governance