Pratyus Patnaik of Snowflake and Jacob Thomas of Texas Children's Hospital join host Gemma Allen to examine the transition from question-answering models to agentic artificial intelligence, hereafter AI. Produced with theCUBE Research at the NYSE Wired Cybersecurity Leaders event, the discussion covers agent identities, runtime policy enforcement, Cortex AI Gateway and Natoma, implications for regulated healthcare data and how organizations balance innovation with robust auditability and controls.
Patnaik explains that AI agents require dynamic identity and runtime decisioning rather than static scopes and that end-to-end auditability prevents agent escape. They highlight implications for token efficiency and for scaling secure, accountable agent deployments using solutions such as Cortex AI Gateway and Natoma.
Thomas emphasizes that regulated healthcare environments require role-based access control, hereafter RBAC, governance, financial operations, hereafter FinOps, and compensating controls to protect patient safety while enabling AI. They note the importance of robust audit trails, policy enforcement and FinOps practices to manage enterprise cybersecurity risk across data platforms and healthcare systems.
This segment provides practical guidance on identity and governance for agentic AI, factors to consider when deploying agents in regulated settings, and strategies to preserve data security and compliance while driving innovation.
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
theCUBE + NYSE Wired: Zero Trust Cyber Series. If you don’t think you received an email check your
spam folder.
Sign in to theCUBE + NYSE Wired: Zero Trust Cyber Series.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Register For theCUBE + NYSE Wired: Zero Trust Cyber Series
Please fill out the information below. You will recieve an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for theCUBE + NYSE Wired: Zero Trust Cyber Series.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
theCUBE + NYSE Wired: Zero Trust Cyber Series. If you don’t think you received an email check your
spam folder.
Sign in to theCUBE + NYSE Wired: Zero Trust Cyber Series.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Sign in to gain access to theCUBE + NYSE Wired: Zero Trust Cyber Series
Please sign in with LinkedIn to continue to theCUBE + NYSE Wired: Zero Trust Cyber Series. Signing in with LinkedIn ensures a professional environment.
Are you sure you want to remove access rights for this user?
Details
Manage Access
email address
Community Invitation
Jacob Thomas, Texas Children’s Hospital & Pratyus Patnaik, Snowflake
Pratyus Patnaik of Snowflake and Jacob Thomas of Texas Children's Hospital join host Gemma Allen to examine the transition from question-answering models to agentic artificial intelligence, hereafter AI. Produced with theCUBE Research at the NYSE Wired Cybersecurity Leaders event, the discussion covers agent identities, runtime policy enforcement, Cortex AI Gateway and Natoma, implications for regulated healthcare data and how organizations balance innovation with robust auditability and controls.
Patnaik explains that AI agents require dynamic identity and runtime decisioning rather than static scopes and that end-to-end auditability prevents agent escape. They highlight implications for token efficiency and for scaling secure, accountable agent deployments using solutions such as Cortex AI Gateway and Natoma.
Thomas emphasizes that regulated healthcare environments require role-based access control, hereafter RBAC, governance, financial operations, hereafter FinOps, and compensating controls to protect patient safety while enabling AI. They note the importance of robust audit trails, policy enforcement and FinOps practices to manage enterprise cybersecurity risk across data platforms and healthcare systems.
This segment provides practical guidance on identity and governance for agentic AI, factors to consider when deploying agents in regulated settings, and strategies to preserve data security and compliance while driving innovation.
Jacob Thomas, Texas Children’s Hospital & Pratyus Patnaik, Snowflake
Pratyus Patnaik
Head of Enterprise AI SecuritySnowflake
Jacob Thomas
Manager of Information SecurityTexas Children’s Hospital
search
Gemma Allen
>> Palo Alto studio, connecting Silicon Valley and Wall Street.
Jacob Thomas
>> I'm John Furrier, co-host here with Dave Vellante, my co-host.
Gemma Allen
>> Welcome to theCUBE Studio here at the New York Stock Exchange. I'm Gemma Allen with NYSE Wired Cybersecurity Leaders, a show connecting Silicon Valley to Wall Street, talking to the folks shaping what's next in tech, business, and capital markets. Today we're talking about one of the biggest shifts happening in enterprise tech right now. That is AI agents moving from answering questions to actually implementing actions, creating a huge new problem around cybersecurity. So the question becomes, if you give an AI agent the keys to your enterprise, how do you make sure it only opens the doors it's supposed to? To unpack that, I'm joined by two folks looking at this problem from very different sides. Pratyus Patnaik, Head of Enterprise AI Security at Snowflake, and Jacob Thomas, Manager of Information Security at Texas Children's Hospital. Welcome, folks.
Jacob Thomas
>> Thank you, Gemma.
Gemma Allen
>> So a very interesting time, a lot happening very fast. You've obviously— we're going to get into your journey into Snowflake, which I know is very new, but also very critical to the roadmap that you guys are building. But first, I'm going to start with you, Jacob. When we think about children, especially from the perspective of children's health, and running a hospital as successful and as iconic, I guess, in the US healthcare system as Texas Children's is, the risks that cybersecurity threats pose are different from many others, right? It's not just about finance, it's not just about image, it's actually about patient health. Talk to me a little bit about what has changed for you with this rise in AI, everything that we hear about and talk about every day on the news. Bring me up to date on what the last 3 to 4 years have been like from your perspective.
Jacob Thomas
>> Sure. So Texas Children's just to level set, we're the largest pediatric hospital in America, right? We have over 1,200 beds. So we're sitting on a ton of data, right? And the question really comes down to how do we use that data efficiently? For us, it is absolutely a game-changing event for us to start looking at it from an AI scope. And for us, it really just comes down to leveraging it in a way where we increase and get better patient outcomes, better patient experience, those kind of things, right? And we really can't do that without really leveraging AI. But when we first started our journey in that space, we found that we can't just go and grab a model out of Hugging Face and just run off of it, right? So we had to really invest in our research partners and bring in a lot of investments around building models. So that's kind of where we're at. We're exiting from that stage and starting to connect it to LLMs and taking that to the next factor of connecting it to our user base.
Pratyus Patnaik
>> Yeah.
Gemma Allen
>> So we hear a lot about AI agents, right? This whole concept that has become ubiquitous, really, with technology and the future of tech. And some folks compare it to software, some folks compare it to an actual digital employee, right? Which I think is where Natoma and that journey comes in. It's an interesting analogy because employees have credentials, they have access, they also can be cut off if need be, right? Just if they're being manipulated or whatever we see happen. But we know that in the world of agents, everything's happening at huge scale. Let's talk a little bit about Natoma, the journey, and I guess the business alignment and the commercial alignment with Snowflake.
Pratyus Patnaik
>> Absolutely, absolutely. For us, Gemma, when we started the company, it was, we, working with partners like Jacob, saw the shift happening where the AI was becoming capable enough to not just answer questions but take actions. That means the agents, the AI systems had to get access to different applications, databases, APIs, and that meant providing an identity perimeter to them, assigning an identity, making sure they are doing what they're authorized to do. Having a runtime environment to enforce the policies as needed, which naturally makes sense for Snowflake. If you think of it this way, Snowflake is the AI and data platform for the world, which is trusted by 13,000+ enterprises today. With Natoma, Snowflake is able to extend the same governance, same trust, not just to data at rest within Snowflake, but also to data in motion between your agents and your different enterprise systems. So that's what we were able to provide. I can answer the question in another way also, but Snowflake is also one of the most progressive companies when it comes to consuming AI, finance department, M&A integrations, IR, everything is done agentically. And, Snowflake was using Natoma and they saw the value and probably thought about taking it to their customers. And then it's a win-win-win for everyone.
Gemma Allen
>> So Snowflake's had an interesting year here in the markets here on Wall Street. We look at the stocks every day, and earlier this year you guys had a ripping day on the street. And one of the analysts was very clear in saying this is not just about some big deal with Amazon, this is actually about what they're building themselves from the perspective of Cortex, right, on that AI gateway.
Pratyus Patnaik
>> Absolutely.
Gemma Allen
>> It sounds super exciting, especially to all your customers, but we know that again there is a level of risk If you have agents talking to multiple systems at scale, how do you actually completely control and manage that?
Pratyus Patnaik
>> Yes.
Gemma Allen
>> So from your perspective, Jacob, I'm sure you're also like every other industry under pressure to keep pace with the speed of AI, but to do it in a safe way. What does it fundamentally change for you? Are you talking about scaling more data access to more digital employees and agents across? Your ecosystem. Talk a little bit about what that agentic layer in Snowflake can actually fundamentally shift in a digital worker's life at Texas Children's.
Jacob Thomas
>> So don't forget, in healthcare we're heavily regulated, right? So we have to take all of what he was talking about around RBAC-level controls for every single one of those data points, right? And then consider who it is that's actually touching those things, whether it's non-human systems versus human-in-the-loop components, right? All of these components come into play and then we have to be able to produce that as a check, right? It's a check and balance conversation, right? So all of those components have to be mapped out in some way, right? And that's where we see the value in something like the Cortex AI Gateway, right? I ultimately look at it from the perspective of we're in cyber, we're always known as the people that tell everybody no, right? We can't do that going into the innovative areas that we're going into, right? So it really comes down to having the appropriate controls in place. Those controls come with these kinds of solutions, and that's why we were speaking to them early on, about a year plus or so. Right. Because I knew this is kind of coming around the corner. And once we started experimenting and started going into the LLM space, the next component will be agentics, and that will come very quickly. So we have to be ready for those conversations.
Gemma Allen
>> So we think about what's really shifting from the perspective of agents accessing data, right? We know that maybe not systems independently have acted before, but we have had APIs in place. We've had software operating. There's been interoperability, or at least a quest for it, for quite a while. We've had IAM. You know, is this essentially from your perspective like IAM 2.0? Like, how do you really define this category?
Pratyus Patnaik
>> So to break it down, you know, we have had IAM. Those are robust solutions out there in the market, but You have had the humans. We come with accountability. If I'm doing something, I'm accountable for my action. You had workloads, which were deterministic pieces of code someone had written to go do something. Now you have agents that fall somewhere in between. I think you started by saying we are moving from AI as software to AI as a workforce, where a model, an LLM, reasons, decides what it needs to do. So the identity that we've assigned to these agents. So when it comes to human workers, you have authentication. When you come in, you know who is who, what you can do. But when it comes to agents, you cannot give them static scopes. When they're doing something, a runtime decision has to be made given the circumstances, does this access make sense? Can the agent do this? Is it— has something changed that we need to yank out that permission, those things have to be done at runtime. I think that's the biggest shift that we'll have to adjust to as agents come and run your enterprise.
Gemma Allen
>> When we think about MCP, which is the fundamentals that this is built upon, right? Traditionally, there was a little bit of skepticism around how secure is that world, right? what does that actually mean? How can you truly lock something down if you have systems talking to each other at such scale? But now it's the buzzword of the era, right? Like inference, we hear about MCP all the time. There's so much excitement. What do you think it truly means, though, from the perspective of security? And I'm going to put this to you, Jacob, especially when you think about a world whereby, you have a larger attack surface, right? You have a larger attack vector if you have agents talking to each other at the pace and speed and scale that technologists make us believe is going to happen tomorrow.
Jacob Thomas
>> Correct. Yeah, that attack surface was never an issue for us in the past. Mostly because we were working on probabilistic models and then moving into deterministic with a future scope of going in the other direction. Right. But as you start introducing MCP into that conversation, it starts to become a bigger problem for us. Right. But it's not really a problem from an innovative standpoint. In fact, it makes things a lot better. So we are looking at it from the same kind of perspective, which is what all needs that level of access? Is it over-permissive? Is it not over-permissive? Right. How do we tweak that to the exact necessities that we need, and then kind of approach it from that perspective. So having something sit there and look at that actual workflow and understand that workflow so that we can come back and say, okay, this is exactly what you need, and then you can just turn everything else off. Is it still running? Beautiful. That's exactly what we want.
Gemma Allen
>> Right. Let's talk about cybersecurity broadly for a second as a bottleneck or an enabler of innovation, right, of change. Because there is misuse in this too, right? Things, especially at a hospital, have to be exceptionally secure for a very, very good reason, right? But we also talk about the ways in which cyber can sometimes slow the technology race somewhat. How do you guys think about that bottleneck? Like, what is your response to feedback that maybe it's not so much about the model, it's about the actual pace of usage, pace of access? Now, what are your thoughts specifically?
Pratyus Patnaik
>> I'll try to break it down into two parts. But first of all, models have been capable, at least when it comes to enterprise workflows, for a while. Yes, they cannot discover drugs just yet, but they can do everything we do within an enterprise. What's stopping a broad-scale rollout of AI within an enterprise is two parts, and till now it was mostly security and governance. Uh, it's very easy to build agents. You can ask an agent to build an agent now. When— but when you deploy and give them wholesale access to everything in the system, that's when things get tricky. That's when, security side or the IT side will come in, wanting to know What is this agent? What is it trying to do? What did it do in the last 6 weeks? Where is the audit trail? Those become a question. So essentially, part 1 for AI to go from pilot to full-scale broad rollout, number 1 is just taking security, governance, identity, access control seriously. The governance should not be a review, access review process. Should be part of the infrastructure. The second part here now is, I think, top of mind today for most folks is cost. Costs have blown up. This is where Cortex at least helps, where we have a semantic view of the data and we have proven numbers where we bring down the token efficiency and the inference efficiency is what I would call by a magnitude that makes scaling out the AI across the enterprise easy. And then we're not just doing— with Natoma, we're not just doing the data part in Snowflake, but across your enterprise ecosystem, number one. Number two is also it's not tied to Cortex, but to every AI you might be using.
Gemma Allen
>> Let's stay on cost for a second. It's an interesting conversation, right? We know that in technology, Snowflake, AWS, all of these huge titans of industry, they're also huge line items on a P&L, right? Like in any company. And with everything that's happening so quickly, especially from the perspective of tech and inference, there is certainly a lot of conversations happening around consumption and tokenization. I'm going to put this to you, Jacob. Tricky question, but how do you think about that from the perspective of your own kind of evangelism of this kind of tech futuristic picture that we all foresee? How do you think about the role of head of money, of security and a CFO, those conversations must be becoming closer and more regular than they've ever been.
Jacob Thomas
>> Partnerships is the answer to that question, right? So we partner considerably to understand just the tokenomics of it all, right? And it really just comes down to sandboxing that environment first, letting them run their models, letting them run their queries and everything else, right? Understanding the harness component of it to understand where exactly the execution loops are taking place. And then are we really getting the value out of it, right? So there are these conversations that take place, there's people and process behind the technology too, right? So we have to make sure all of these things are in place and then that delivers the ROI for us, right? It's an investment at the end of the day, there's gonna be spend, you can't avoid that, right? But really it just comes down to, do we meet these specific metrics, right? And understand the success criteria around that. If you can pitch that in a way that makes sense, everybody will buy in, right? That was our take on it. We invested heavily in that space and then we built those guardrails out. We invested in FinOps as well. That really helped push these things forward. And there was— if we hadn't done that, I'm pretty sure we would have gotten a lot of sticker shock from our CFO, right? All of those concerns were alleviated by doing these specific kind of things, right? But again, it's people and process behind the technology for sure.
Pratyus Patnaik
>> Also, the world is changing so rapidly now with all the open weight models. There are ways to optimize your token consumption for the task at hand. You shouldn't be going to GPT-5 to check weather or simple tasks. Even older models are capable of doing some of the tasks that are repetitive. Now you can bring back your good old macros in some scenarios where things have to be done in a very deterministic way. So a lot of investment happening in making sure folks understand there is a direct correlation between the token spend and the business value being delivered.
Gemma Allen
>> Okay, last question. Some folks say that inference actually is a huge threat to cyber, right? Because we have keystroke logging. We have all sorts of activities happening that we probably didn't predict or plan for 5 to 10 years ago. What are your thoughts in terms of the additional threat vectors that are evolving in this world? What sorts of thoughts are you maybe planning for or having, or even what's keeping you up at night that perhaps wasn't 3 to 5 years ago?
Jacob Thomas
>> personally, for me, that was always there. it's not like it suddenly just showed up, right? and that's the reason why we have a good governance model behind everything, right? You have to understand that there's mitigating controls and compensating controls. If you plan for that correctly, you can reduce the attack surface and then reduce the ability for the threat actor to do those kind of things, right? That's always been our approach. That is not unique to AI. That's specific to anything in our cyber stack, right? So we just continue down that road to keep it simple.
Pratyus Patnaik
>> Yeah, I'll add one more thing to it. So as Snowflake, obviously we have to protect Snowflake, something to the tune of what Jacob just said. But the other thing we are beginning to get concerned about is our agents escaping and doing things. recently you heard that scenario where a model with no malintent, just trying to do the task it was assigned, escaped out and hacked another company. That has become a reality now and we need to have proper guardrails, proper monitoring, proper auditability to stop those things from happening too. That's something that's keeping Snowflake
Gemma Allen
>> up And I think it's keeping us all awake at night, right? We just saw earlier a model or a bad actor had hacked someone's phone and contacted the PM of England just this morning, right? So there's all sorts of crazy stuff happening right now out there. But staying on Snowflake and this relationship and this partnership for the last question, talk about what's ahead. I know this is a relatively new acquisition. Exciting one. Core capability brings a lot of technical know-how and need, I think, to the Snowflake model overall. You guys are old friends though, right? This is an old partnership. Talk about what the next kind of year out looks like, because I don't think we can think past that.
Pratyus Patnaik
>> You want to go first?
Jacob Thomas
>> Sure. Yeah. From a cybersecurity standpoint, we're investing, we're doubling down on the Snowflake component. So we're looking at different solutions that they're going to start beta testing with us. I can't speak too much into that, but the goal is to really dive in with the concept of data analytics at the end of the day, right? So an SIEM/SOAR product is essentially a data mine for a cybersecurity team, right? We can essentially do the same thing with the Snowflake data lake as well. So that's the gist of it. We're going to go down that road and explore those paths.
Pratyus Patnaik
>> I'll keep it simple too. For Snowflake, number one is efficient intelligence for our customers. Number 2 is owning the enterprise context. We have the data, either data parked at Snowflake or in motion with the Cortex AI Gateway. How do we make it much more valuable to our customers? And as we are entering this agentic era, we are beginning to hear a lot of DIY where customers want to own and build bespoke software for what they need to do versus buying something off the shelf. And enable partners like Jacob to build that efficiently and at scale.
Gemma Allen
>> Well, that's an interesting point to end on because you need to meet partners where they're at, right across all industries, especially one as critical as children's health. So, gents, thank you so much for joining us on NYSE Wired.
Pratyus Patnaik
>> Thank you so much, Gemma.
Pratyus Patnaik
>> Thank you, Gemma. Appreciate the opportunity.
Gemma Allen
>> I'm Gemma Allen here at theCUBE Studio at the NYSE. This is Cybersecurity Leaders. Thanks for watching.
Jacob Thomas, Texas Children’s Hospital & Pratyus Patnaik, Snowflake
search
Gemma Allen
>> Palo Alto studio, connecting Silicon Valley and Wall Street.
Jacob Thomas
>> I'm John Furrier, co-host here with Dave Vellante, my co-host.
Gemma Allen
>> Welcome to theCUBE Studio here at the New York Stock Exchange. I'm Gemma Allen with NYSE Wired Cybersecurity Leaders, a show connecting Silicon Valley to Wall Street, talking to the folks shaping what's next in tech, business, and capital markets. Today we're talking about one of the biggest shifts happening in enterprise tech right now. That is AI agents moving from answering questions to actually implementing actions, creating a huge new problem around cybersecurity. So the question becomes, if you give an AI agent the keys to your enterprise, how do you make sure it only opens the doors it's supposed to? To unpack that, I'm joined by two folks looking at this problem from very different sides. Pratyus Patnaik, Head of Enterprise AI Security at Snowflake, and Jacob Thomas, Manager of Information Security at Texas Children's Hospital. Welcome, folks.
Jacob Thomas
>> Thank you, Gemma.
Gemma Allen
>> So a very interesting time, a lot happening very fast. You've obviously— we're going to get into your journey into Snowflake, which I know is very new, but also very critical to the roadmap that you guys are building. But first, I'm going to start with you, Jacob. When we think about children, especially from the perspective of children's health, and running a hospital as successful and as iconic, I guess, in the US healthcare system as Texas Children's is, the risks that cybersecurity threats pose are different from many others, right? It's not just about finance, it's not just about image, it's actually about patient health. Talk to me a little bit about what has changed for you with this rise in AI, everything that we hear about and talk about every day on the news. Bring me up to date on what the last 3 to 4 years have been like from your perspective.
Jacob Thomas
>> Sure. So Texas Children's just to level set, we're the largest pediatric hospital in America, right? We have over 1,200 beds. So we're sitting on a ton of data, right? And the question really comes down to how do we use that data efficiently? For us, it is absolutely a game-changing event for us to start looking at it from an AI scope. And for us, it really just comes down to leveraging it in a way where we increase and get better patient outcomes, better patient experience, those kind of things, right? And we really can't do that without really leveraging AI. But when we first started our journey in that space, we found that we can't just go and grab a model out of Hugging Face and just run off of it, right? So we had to really invest in our research partners and bring in a lot of investments around building models. So that's kind of where we're at. We're exiting from that stage and starting to connect it to LLMs and taking that to the next factor of connecting it to our user base.
Pratyus Patnaik
>> Yeah.
Gemma Allen
>> So we hear a lot about AI agents, right? This whole concept that has become ubiquitous, really, with technology and the future of tech. And some folks compare it to software, some folks compare it to an actual digital employee, right? Which I think is where Natoma and that journey comes in. It's an interesting analogy because employees have credentials, they have access, they also can be cut off if need be, right? Just if they're being manipulated or whatever we see happen. But we know that in the world of agents, everything's happening at huge scale. Let's talk a little bit about Natoma, the journey, and I guess the business alignment and the commercial alignment with Snowflake.
Pratyus Patnaik
>> Absolutely, absolutely. For us, Gemma, when we started the company, it was, we, working with partners like Jacob, saw the shift happening where the AI was becoming capable enough to not just answer questions but take actions. That means the agents, the AI systems had to get access to different applications, databases, APIs, and that meant providing an identity perimeter to them, assigning an identity, making sure they are doing what they're authorized to do. Having a runtime environment to enforce the policies as needed, which naturally makes sense for Snowflake. If you think of it this way, Snowflake is the AI and data platform for the world, which is trusted by 13,000+ enterprises today. With Natoma, Snowflake is able to extend the same governance, same trust, not just to data at rest within Snowflake, but also to data in motion between your agents and your different enterprise systems. So that's what we were able to provide. I can answer the question in another way also, but Snowflake is also one of the most progressive companies when it comes to consuming AI, finance department, M&A integrations, IR, everything is done agentically. And, Snowflake was using Natoma and they saw the value and probably thought about taking it to their customers. And then it's a win-win-win for everyone.
Gemma Allen
>> So Snowflake's had an interesting year here in the markets here on Wall Street. We look at the stocks every day, and earlier this year you guys had a ripping day on the street. And one of the analysts was very clear in saying this is not just about some big deal with Amazon, this is actually about what they're building themselves from the perspective of Cortex, right, on that AI gateway.
Pratyus Patnaik
>> Absolutely.
Gemma Allen
>> It sounds super exciting, especially to all your customers, but we know that again there is a level of risk If you have agents talking to multiple systems at scale, how do you actually completely control and manage that?
Pratyus Patnaik
>> Yes.
Gemma Allen
>> So from your perspective, Jacob, I'm sure you're also like every other industry under pressure to keep pace with the speed of AI, but to do it in a safe way. What does it fundamentally change for you? Are you talking about scaling more data access to more digital employees and agents across? Your ecosystem. Talk a little bit about what that agentic layer in Snowflake can actually fundamentally shift in a digital worker's life at Texas Children's.
Jacob Thomas
>> So don't forget, in healthcare we're heavily regulated, right? So we have to take all of what he was talking about around RBAC-level controls for every single one of those data points, right? And then consider who it is that's actually touching those things, whether it's non-human systems versus human-in-the-loop components, right? All of these components come into play and then we have to be able to produce that as a check, right? It's a check and balance conversation, right? So all of those components have to be mapped out in some way, right? And that's where we see the value in something like the Cortex AI Gateway, right? I ultimately look at it from the perspective of we're in cyber, we're always known as the people that tell everybody no, right? We can't do that going into the innovative areas that we're going into, right? So it really comes down to having the appropriate controls in place. Those controls come with these kinds of solutions, and that's why we were speaking to them early on, about a year plus or so. Right. Because I knew this is kind of coming around the corner. And once we started experimenting and started going into the LLM space, the next component will be agentics, and that will come very quickly. So we have to be ready for those conversations.
Gemma Allen
>> So we think about what's really shifting from the perspective of agents accessing data, right? We know that maybe not systems independently have acted before, but we have had APIs in place. We've had software operating. There's been interoperability, or at least a quest for it, for quite a while. We've had IAM. You know, is this essentially from your perspective like IAM 2.0? Like, how do you really define this category?
Pratyus Patnaik
>> So to break it down, you know, we have had IAM. Those are robust solutions out there in the market, but You have had the humans. We come with accountability. If I'm doing something, I'm accountable for my action. You had workloads, which were deterministic pieces of code someone had written to go do something. Now you have agents that fall somewhere in between. I think you started by saying we are moving from AI as software to AI as a workforce, where a model, an LLM, reasons, decides what it needs to do. So the identity that we've assigned to these agents. So when it comes to human workers, you have authentication. When you come in, you know who is who, what you can do. But when it comes to agents, you cannot give them static scopes. When they're doing something, a runtime decision has to be made given the circumstances, does this access make sense? Can the agent do this? Is it— has something changed that we need to yank out that permission, those things have to be done at runtime. I think that's the biggest shift that we'll have to adjust to as agents come and run your enterprise.
Gemma Allen
>> When we think about MCP, which is the fundamentals that this is built upon, right? Traditionally, there was a little bit of skepticism around how secure is that world, right? what does that actually mean? How can you truly lock something down if you have systems talking to each other at such scale? But now it's the buzzword of the era, right? Like inference, we hear about MCP all the time. There's so much excitement. What do you think it truly means, though, from the perspective of security? And I'm going to put this to you, Jacob, especially when you think about a world whereby, you have a larger attack surface, right? You have a larger attack vector if you have agents talking to each other at the pace and speed and scale that technologists make us believe is going to happen tomorrow.
Jacob Thomas
>> Correct. Yeah, that attack surface was never an issue for us in the past. Mostly because we were working on probabilistic models and then moving into deterministic with a future scope of going in the other direction. Right. But as you start introducing MCP into that conversation, it starts to become a bigger problem for us. Right. But it's not really a problem from an innovative standpoint. In fact, it makes things a lot better. So we are looking at it from the same kind of perspective, which is what all needs that level of access? Is it over-permissive? Is it not over-permissive? Right. How do we tweak that to the exact necessities that we need, and then kind of approach it from that perspective. So having something sit there and look at that actual workflow and understand that workflow so that we can come back and say, okay, this is exactly what you need, and then you can just turn everything else off. Is it still running? Beautiful. That's exactly what we want.
Gemma Allen
>> Right. Let's talk about cybersecurity broadly for a second as a bottleneck or an enabler of innovation, right, of change. Because there is misuse in this too, right? Things, especially at a hospital, have to be exceptionally secure for a very, very good reason, right? But we also talk about the ways in which cyber can sometimes slow the technology race somewhat. How do you guys think about that bottleneck? Like, what is your response to feedback that maybe it's not so much about the model, it's about the actual pace of usage, pace of access? Now, what are your thoughts specifically?
Pratyus Patnaik
>> I'll try to break it down into two parts. But first of all, models have been capable, at least when it comes to enterprise workflows, for a while. Yes, they cannot discover drugs just yet, but they can do everything we do within an enterprise. What's stopping a broad-scale rollout of AI within an enterprise is two parts, and till now it was mostly security and governance. Uh, it's very easy to build agents. You can ask an agent to build an agent now. When— but when you deploy and give them wholesale access to everything in the system, that's when things get tricky. That's when, security side or the IT side will come in, wanting to know What is this agent? What is it trying to do? What did it do in the last 6 weeks? Where is the audit trail? Those become a question. So essentially, part 1 for AI to go from pilot to full-scale broad rollout, number 1 is just taking security, governance, identity, access control seriously. The governance should not be a review, access review process. Should be part of the infrastructure. The second part here now is, I think, top of mind today for most folks is cost. Costs have blown up. This is where Cortex at least helps, where we have a semantic view of the data and we have proven numbers where we bring down the token efficiency and the inference efficiency is what I would call by a magnitude that makes scaling out the AI across the enterprise easy. And then we're not just doing— with Natoma, we're not just doing the data part in Snowflake, but across your enterprise ecosystem, number one. Number two is also it's not tied to Cortex, but to every AI you might be using.
Gemma Allen
>> Let's stay on cost for a second. It's an interesting conversation, right? We know that in technology, Snowflake, AWS, all of these huge titans of industry, they're also huge line items on a P&L, right? Like in any company. And with everything that's happening so quickly, especially from the perspective of tech and inference, there is certainly a lot of conversations happening around consumption and tokenization. I'm going to put this to you, Jacob. Tricky question, but how do you think about that from the perspective of your own kind of evangelism of this kind of tech futuristic picture that we all foresee? How do you think about the role of head of money, of security and a CFO, those conversations must be becoming closer and more regular than they've ever been.
Jacob Thomas
>> Partnerships is the answer to that question, right? So we partner considerably to understand just the tokenomics of it all, right? And it really just comes down to sandboxing that environment first, letting them run their models, letting them run their queries and everything else, right? Understanding the harness component of it to understand where exactly the execution loops are taking place. And then are we really getting the value out of it, right? So there are these conversations that take place, there's people and process behind the technology too, right? So we have to make sure all of these things are in place and then that delivers the ROI for us, right? It's an investment at the end of the day, there's gonna be spend, you can't avoid that, right? But really it just comes down to, do we meet these specific metrics, right? And understand the success criteria around that. If you can pitch that in a way that makes sense, everybody will buy in, right? That was our take on it. We invested heavily in that space and then we built those guardrails out. We invested in FinOps as well. That really helped push these things forward. And there was— if we hadn't done that, I'm pretty sure we would have gotten a lot of sticker shock from our CFO, right? All of those concerns were alleviated by doing these specific kind of things, right? But again, it's people and process behind the technology for sure.
Pratyus Patnaik
>> Also, the world is changing so rapidly now with all the open weight models. There are ways to optimize your token consumption for the task at hand. You shouldn't be going to GPT-5 to check weather or simple tasks. Even older models are capable of doing some of the tasks that are repetitive. Now you can bring back your good old macros in some scenarios where things have to be done in a very deterministic way. So a lot of investment happening in making sure folks understand there is a direct correlation between the token spend and the business value being delivered.
Gemma Allen
>> Okay, last question. Some folks say that inference actually is a huge threat to cyber, right? Because we have keystroke logging. We have all sorts of activities happening that we probably didn't predict or plan for 5 to 10 years ago. What are your thoughts in terms of the additional threat vectors that are evolving in this world? What sorts of thoughts are you maybe planning for or having, or even what's keeping you up at night that perhaps wasn't 3 to 5 years ago?
Jacob Thomas
>> personally, for me, that was always there. it's not like it suddenly just showed up, right? and that's the reason why we have a good governance model behind everything, right? You have to understand that there's mitigating controls and compensating controls. If you plan for that correctly, you can reduce the attack surface and then reduce the ability for the threat actor to do those kind of things, right? That's always been our approach. That is not unique to AI. That's specific to anything in our cyber stack, right? So we just continue down that road to keep it simple.
Pratyus Patnaik
>> Yeah, I'll add one more thing to it. So as Snowflake, obviously we have to protect Snowflake, something to the tune of what Jacob just said. But the other thing we are beginning to get concerned about is our agents escaping and doing things. recently you heard that scenario where a model with no malintent, just trying to do the task it was assigned, escaped out and hacked another company. That has become a reality now and we need to have proper guardrails, proper monitoring, proper auditability to stop those things from happening too. That's something that's keeping Snowflake
Gemma Allen
>> up And I think it's keeping us all awake at night, right? We just saw earlier a model or a bad actor had hacked someone's phone and contacted the PM of England just this morning, right? So there's all sorts of crazy stuff happening right now out there. But staying on Snowflake and this relationship and this partnership for the last question, talk about what's ahead. I know this is a relatively new acquisition. Exciting one. Core capability brings a lot of technical know-how and need, I think, to the Snowflake model overall. You guys are old friends though, right? This is an old partnership. Talk about what the next kind of year out looks like, because I don't think we can think past that.
Pratyus Patnaik
>> You want to go first?
Jacob Thomas
>> Sure. Yeah. From a cybersecurity standpoint, we're investing, we're doubling down on the Snowflake component. So we're looking at different solutions that they're going to start beta testing with us. I can't speak too much into that, but the goal is to really dive in with the concept of data analytics at the end of the day, right? So an SIEM/SOAR product is essentially a data mine for a cybersecurity team, right? We can essentially do the same thing with the Snowflake data lake as well. So that's the gist of it. We're going to go down that road and explore those paths.
Pratyus Patnaik
>> I'll keep it simple too. For Snowflake, number one is efficient intelligence for our customers. Number 2 is owning the enterprise context. We have the data, either data parked at Snowflake or in motion with the Cortex AI Gateway. How do we make it much more valuable to our customers? And as we are entering this agentic era, we are beginning to hear a lot of DIY where customers want to own and build bespoke software for what they need to do versus buying something off the shelf. And enable partners like Jacob to build that efficiently and at scale.
Gemma Allen
>> Well, that's an interesting point to end on because you need to meet partners where they're at, right across all industries, especially one as critical as children's health. So, gents, thank you so much for joining us on NYSE Wired.
Pratyus Patnaik
>> Thank you so much, Gemma.
Pratyus Patnaik
>> Thank you, Gemma. Appreciate the opportunity.
Gemma Allen
>> I'm Gemma Allen here at theCUBE Studio at the NYSE. This is Cybersecurity Leaders. Thanks for watching.