The prevailing consensus in enterprise AI is that the model is the moat. Every earnings call, every benchmark war, every inference-cost curve treats the foundation model as the strategic unit of value. That consensus took a structural hit over a 72-hour window in late July 2026, when three events landed inside a single news cycle.
Snowflake unveiled Cortex AI Gateway at Black Hat. Cyera agreed to acquire Oasis for $1 billion. Okta paid roughly $200 million for Permiso. Three announcements, no visible coordination, one convergent signal: the competitive center of gravity in enterprise AI is migrating from the model layer to the tool-call layer. The new strategic asset is not the model. It is the gateway sitting between an autonomous agent and every system it touches.
You do not need to believe my read of the tea leaves. Look at where the capital went. The money is not betting on another model release. The money is betting on the layer that governs how agents move through the world.
Context: The USB-C Problem
If you are not deep in the AI infrastructure weeds, MCP — the Model Context Protocol — is the standard connector that lets large language models invoke external tools, query databases, trigger workflows, and read the state of connected systems. Open-sourced by Anthropic in late 2024, it became the de facto transport layer for agent-to-tool communication with terrifying speed. It shares a structural weakness with every fast-adopted standard: it prioritized developer convenience over secure defaults.
By 2026, MCP servers were exposed on the public internet the way Redis and Kubernetes instances were exposed a half-decade earlier. Convenient. Unauthenticated. Weaponizable.
Then came the protocol's largest revision since release: a stateless MCP specification built around scalability and modularity. That revision is the quiet foundation beneath everything Snowflake just announced. A stateful protocol forces gateways to maintain session affinity, making horizontal scaling a distributed-systems nightmare. A stateless protocol lets any gateway instance route any tool call to any server, load-balance transparently, scale arbitrarily, and restart without conversation memory loss. For the engineers reading: statelessness means every request is self-contained. Credentials ride along with each call, and the gateway validates each call independently. This is how web infrastructure scaled in the 2000s. Agent tool calls are getting the same treatment now. That single technical decision converts MCP gateways from proxy utilities into horizontally scalable control planes.
The gateway market was already a multi-sided melee before Snowflake stepped in. MintMCP, TrueFoundry, Lunar.dev, Diagrid, Kong, Obot, and Arcade were attacking from different angles — API management veterans treating agent tool calls as the next evolution of API governance, runtime specialists building enforcement engines, developer-facing orchestration platforms, and protocol-native upstarts. Snowflake's entry changes the field's center of gravity. Not because it invented anything conceptually novel, but because it brought platform credibility, a $1.33 billion quarterly product revenue base, and a distribution channel that reaches exactly the buyers this category needs.
Snowflake also brought capital. It acquired Natoma in May 2026 and integrated the technology into a shipped product by July. A two-month integration window is not vendor-normal speed. That brevity tells me Snowflake acquired code, not just talent — a mature tool-call-level policy engine that could be productized immediately. I have audited enough projects to recognize the pattern: fast shipping is usually borrowed infrastructure. That is not a criticism. In enterprise software, buying the right engine is often smarter than building the wrong one.
The comparison to my own industry is unavoidable. In the blockchain world, the middleware narrative dominated 2021: every protocol was a layer, every bridge was infrastructure, and the market learned the hard way that bridges were not infrastructure but honeypots. The MCP gateway market is younger, but the strategic dynamics are identical. When a new layer gets narrative heat, capital floods in, and technical integrity gets discovered only after the first major failure. The protocol's chaos, monetized as infrastructure — that is the story of this launch cycle.
Core: The Control Plane, Not the Proxy
The technical distinction that matters is this: traditional API gateways authenticate requests to endpoints. Snowflake's Cortex AI Gateway enforces identity, policy, and audit at the granularity of an individual MCP tool call. That is an entirely different security model. The agent is not a user-agent string. It is a first-class entity with its own identity, its own permissions, and its own auditable trail. Every tool call becomes a transaction. Every transaction is logged. Every identity is verifiable at the moment of invocation. This is what the industry means by agent-native access control, and it is the difference between a gateway that manages traffic and a gateway that governs behavior.
I saw this exact gap during DeFi Summer in 2020. I spent three months dissecting the interoperability risks between Aave, Compound, and Uniswap. The conclusion was uncomfortable: composability arrived first, safety rails arrived later. Flash loans could cascade across protocols because slippage protections were missing, and the systemic vulnerability was only visible after the exploit, never before. MCP is in that same window now. Agents are composing tools, data sources, and permissions faster than the governance layer can mature. The gateway is the industry's attempt to bolt on the safety rails before the exploit, not after.

The stateless spec gives gateways the scaling foundation. Agent identity gives them legal standing. And Snowflake's own history — data governance and permission management at enterprise scale — gives its approach a logical consistency that the smaller vendors cannot easily replicate. Extending data lineage to agent behavior lineage is the predictable, defensible, and genuinely differentiated move. Real-time agent behavior visibility and end-to-end audit trails are becoming the competitive moats in this industry, because every enterprise AI deployment is becoming an agent deployment, and every agent deployment is becoming a liability question that begins with who did what, when, and under whose authority.
The enterprise data plane has been expanding for a decade. First structured data, then unstructured data, then metadata, then lineage. The next expansion is behavioral: what did the agent do, with which tool, under which permission. The gateway that owns this plane owns a new category of intelligence about the enterprise itself. This is why the infrastructure-ization framing matters. It is not security tooling. It is a new data source wearing a security uniform.
Now, about the 72 hours.
Cyera's $1 billion acquisition of Oasis puts agent identity startups in the ten-figure valuation club before most enterprises have even drafted their agent governance policies. That is not a bet on today's revenue. That is a bet on the infrastructure layer becoming mandatory. Okta's roughly $200 million purchase of Permiso reads differently: a defensive acquisition, a public identity giant buying a detection capability to prevent an upstart from growing into a threat. The valuation gap between the two deals is itself data. The market is paying a premium for the company that defends the data plane around agent behavior, while assigning a far lower multiple to pure visibility. Protection outranks detection. Every founder in this space should be studying that pricing signal.
Snowflake chose Black Hat, not a database conference, for its announcement. That is a tell. The gateway is aimed at security budget holders — CISOs, risk officers, compliance leads — the one budget still growing while AI spending tightens elsewhere. It is also a message to the identity ecosystem: Snowflake does not want to fight Okta, SailPoint, and Cyera. It wants to be the table around which they all sit. The seven identity partners announced at launch — 1Password, Aembit, Cyera, Linx Security, Okta, SailPoint, Saviynt — are the furniture of that table. Notably, the list blends legacy IAM giants with emerging agent-security startups. Okta and SailPoint speak the language of the existing identity stack; Cyera and Aembit speak the language of agent-native security. Snowflake is deliberately straddling both dialects, which is exactly where an orchestration play belongs. But straddling is not owning.
Here is the structural tension the launch coverage missed: Okta and Cyera are simultaneously partners and platform competitors to Snowflake. Both are acquiring agent identity capabilities with an urgency that suggests they intend to become platforms themselves. The partnership is a race disguised as a feast. Snowflake is betting it can become the default governance layer before its partners graduate into rivals.
And the race is happening under fire. The NadMesh botnet is targeting MCP servers at a higher priority than Kubernetes clusters, Docker APIs, or Redis instances. That is a remarkable ordering, and it tells us something crucial: the gateway market is not being built because of a hypothetical threat. It is being built because the threat has already demonstrated the vulnerability. This is a defense-industrial response, not a speculative product. That increases the probability of real procurement budgets, not just proof-of-concept pilots. Attackers are scanning for MCP endpoints before they scan for open databases, because MCP endpoints sit connected to everything. That is what an infrastructure attack surface looks like: not a vulnerability, but a topography.
The defenders, meanwhile, inherit a protocol whose default configuration is open. MCP was built for effortless tool invocation, and effortlessness is the enemy of authorization. The gateways that succeed will be the ones that redefine the default — not by adding friction, but by making identity and policy a precondition of every call. That is a cultural shift as much as a technical one, and culture shifts are slow.
The defense is playing catch-up. Fifty-seven percent of organizations report a significant capability gap in security and risk management, while multi-agent workflows are being deployed regardless of readiness. That gap between the technology adoption curve and the security capability curve is the great opening — for gateways, for attackers, and for the infrastructure layer that will inevitably emerge between them.
Agent identity is the precondition for production deployment. The entire narrative pushes that way. But identity for non-human entities is conceptually messier than the marketing acknowledges. Three years of Soulbound Token discourse in my own industry taught us why persistent on-chain identity stalls: nobody wants a permanent, immutable record of actions and liabilities rendered in a public format. Agents cannot object, but the institutions deploying them can and will. They will demand identity that is provable at the moment of interaction yet revocable at the moment of failure. That is a harder problem than the spec sheets reflect, and it suggests gateway vendors are selling into a problem that is still being defined.
There is also a commercial logic beneath the security narrative. The gateway is not a standalone product. It is a funnel. Every policed tool call routes through Snowflake's platform, generating data consumption, compute consumption, and platform lock-in. In the same way that a blockchain's middleware layer is only as valuable as the settlement layer beneath it, the MCP gateway's commercial viability is tied to the data platform beneath it. The gateway is a governor, but it is also a toll booth. And toll booths, historically, compound.
The competitive question is not whether Snowflake beats the specialists, but whether the integration platform wins or the protocol-native specialist wins. Kong, with its API management heritage, is the most direct threat because it already owns the policy-driven governance muscle memory in enterprise IT. MintMCP and Arcade are protocol-native: they live inside the MCP ecosystem, and their roadmap is unconstrained by a data-platform balance sheet. Historical precedent is mixed. In cloud infrastructure, integration platforms usually win the enterprise default; in developer tools, protocol natives win the hearts. Both collect revenue.
This brings me back to my 2024 work on institutional entry. When I collaborated with traditional finance lawyers on Chain-Link Compliance ahead of the Spot Bitcoin ETF approvals, the insight was that adoption follows translation. Institutional buyers do not need more technology; they need technology framed in the language of custody, liability, and audit. Snowflake's gateway is the same translation layer for AI agents. It takes a chaotic ecosystem of autonomous, tool-calling entities and presents it to institutional auditors in the vocabulary they already trust: identity, policy, and logbooks. That is why the security framing at Black Hat matters more than any benchmark.
For the blockchain audience, the relevance is direct. The AI-agent economy I have been tracking in 2026 is already transacting on-chain. Agents hold wallets, sign transactions, and move stablecoins based on model decisions. An ungoverned agent is not just an operational risk; it is a financial risk. The MCP gateway, by extension, becomes a financial compliance layer for the machine economy. And the identity protocols that failed to gain traction as human identity rails — the Soulbound Token dreams, the self-sovereign identity narratives — deserve a second look, because their customer was wrong. The substrate was never the problem. The customer is the agent. And the agent cannot object to a tokenized identity.
What the Launch Documents Do Not Tell You
One of the first things I learned auditing ICO whitepapers in 2017 is that the amplitude of claims is inversely proportional to the specificity of technical disclosure. The strategic coherence of Snowflake's launch narrative is undeniable. The documentation gaps are equally undeniable.
There is no public pricing model. The gateway will likely be packaged inside the Cortex platform as a metered module — per call, per agent, per managed connection — but we do not know. Pricing models for infrastructure still forming tend to be arbitrary. During DeFi Summer, I found that Aave and Compound's interest rate parameters were arbitrary — they bore no organic relationship to real market supply and demand. They were parameters, not prices. I suspect gateway pricing will display the same arbitrariness until genuine capacity markets emerge. Nobody knows what a policed tool call should cost, so the first pricing sheets will be invented, not derived.

There is no published latency overhead per tool call. Enforcement has a cost. In a high-frequency invocation environment, the difference between five milliseconds and fifty milliseconds is the difference between viable and unusable. Unknown.
There is no indication whether the gateway supports non-MCP protocols — OpenAI Tool Calling, Google's A2A. If Cortex AI Gateway only speaks MCP, its horizontal ambitions are actually vertical. The protocol-standard war is not over, and a gateway that bets on the wrong horse is a gateway that gets replaced.
There is no disclosure of Snowflake's acquisition price for Natoma. That is a missing data point for any rigorous evaluation of the commercial model.
These gaps do not invalidate the thesis. They mean the thesis is not yet an audit trail. It is a hypothesis.
The Contrarian Angle: The Choke Point Paradox
The gateway is a single point of failure dressed in the language of risk management.
Every major infrastructure innovation in my 22 years of covering this industry has created a new attack surface at precisely the layer it was designed to secure. Firewalls got firewalled. Proxies got proxied. The gateway will concentrate trust, and concentrated trust is a target. Compromise the gateway and you compromise every downstream tool call routed through it — the control plane becomes the kill plane. The industry will respond with gateway-specific hardening, WAF-style protections, and zero-trust segmentation around the gateway itself. But that is defense in depth for a chokepoint that is, by design, the single most attractive target in the architecture.
Second: the stateless spec solves scaling, not authentication. Identity remains external to the protocol, which means the gateway layer carries that burden. And the gateway layer is exactly what the attackers are hunting. The industry is standardizing the wire protocol while fighting off weaponized scans of its exposed servers. Botnets iterate faster than enterprise security committees.
Third: the legal overhang. Runlayer v. Rippling, the first significant MCP intellectual property litigation, is already moving through the courts. Its outcome will ripple through procurement teams. Enterprise legal departments will demand IP indemnification, breach notification standards, and audit obligation granularity that most gateway vendors are not equipped to offer. That friction delays adoption and favors the biggest balance sheets — which is, not coincidentally, Snowflake.
Fourth, and this is where I earn my skepticism: the middleware-layer narrative is structurally identical to the Web3 middleware narrative I watched inflate and deflate in 2021 and 2022. Everyone was a layer. Everyone was infrastructure. The survivors had usage and fees. The rest had narrative infrastructure — the protocol's whitepaper and its technical reality diverged, and the charts turned red.
I held the same discipline in May 2022, when I argued algorithmic stablecoins were a narrative dead end and published The Stablecoin Tether Point two weeks before FTX's collapse validated the thesis. The thesis held firm when the charts turned red, because it was built from the economic model, not from the narrative. The question today is whether MCP gateways are built from a technical model or from a narrative. The inputs are real: the spec is real, the attack is real, the acquisitions are real. But a product with no pricing, no latency data, and no protocol breadth is unfinished infrastructure.
There is also a valuation question the market is not asking: is agent identity in a bubble? When a category's first billion-dollar acquisition happens before the category has a standardized metric — before we even have an agreed definition of agent identity — the multiple is anchored not to fundamentals but to the fear of being late. That is precisely the dynamic that produced 2021's bridge valuations, with consequences we do not need to revisit.
There are alternative paradigms the celebratory coverage excludes. Decentralized authorization layers. Agent-to-agent communication that bypasses centralized gateways. Peer-to-peer tool invocation where the gateway is an optional routing hint, not a mandatory control plane. Those architectures do not fit into a Snowflake sales deck, so they are absent from the narrative. Their absence is not evidence that they do not exist. It is evidence that the narrative has blinders.
And do not forget the compute question. The gateway itself is logic-heavy, not calculation-heavy. It does not require GPU clusters; it requires identity resolution, policy evaluation, and audit logging. That means it can be deployed serverless, scaled horizontally, and priced elastically. The cost curve is favorable — which is precisely why the economic model is not the bottleneck. The bottleneck is trust. And trust is not a pricing function.
Takeaway: The Gates Will Be Tested
What do we watch, then?
First, whether Snowflake publishes technical documentation, pricing, and a GA timeline within the next quarter. Second, whether Cyera and Okta ship actual products from their acquisitions within three to six months. Third — and most important — whether the NadMesh-class botnets evolve faster than the defense. The infrastructure-ization of MCP is underway. The standardization, the capital allocation, the attack surface, the enterprise demand: all confirmed. But the difference between infrastructure and narrative is survivability. A gateway that cannot survive an adversarial traffic spike, a protocol that cannot enforce identity at scale without a third-party control plane, a security model with no measured enforcement cost — that is not infrastructure. That is a proxy with good public relations.
The agents are coming. The market is certain of that. The gates will be tested — by attackers, by procurement, by the next market correction, by the first catastrophic failure. That is where we learn whether the infrastructure held, or whether it was another contract waiting for a bullet. I have been on the other side of that test enough times to know the price of pretending the test will not come.
Twenty-two years into this industry, I have learned to treat every infrastructure narrative as a claim against the future. The claim here is that autonomous agents require a governed perimeter, and that the perimeter is a product. It may even be true. But claims get audited, and audits come in red ink.
Watch the protocol standards committee. Watch the cloud giants. AWS and Azure have been silent on MCP gateways, and silence from hyperscalers is never permanent. Watch the open-source community for an Envoy-for-MCP project that becomes a de facto standard. And watch the first enterprise breach report that mentions a gateway in its timeline of compromise. That report will tell us more about this market than any launch keynote.