Snowflake has introduced a multi-layered security framework designed to protect AI agents from manipulation and prevent unauthorized actions. The company's approach addresses growing concerns about autonomous systems that can act on behalf of users without proper constraints or oversight.
The framework begins at the data layer, where Snowflake deployed indirect prompt injection protection that uses a large language model to detect and neutralize malicious prompts before they reach the AI agent. According to Mayank, a Snowflake team member leading the initiative, this protection operates without adding latency to system performance. The technology analyzes incoming data to identify attempts to trick or manipulate the AI agent through embedded instructions.
Beyond data-layer defenses, Snowflake introduced Agent Identity, a system that separates agent permissions from user permissions. This distinction allows organizations to constrain what autonomous agents can do even when acting on behalf of authorized users. The framework includes MCP (Model Context Protocol) governance, which restricts which external SaaS applications an agent can communicate with, preventing unauthorized integrations or data exfiltration attempts.
The security model relies heavily on Snowflake's native data governance controls, which Mayank emphasized as the foundation for all AI security measures. Since AI agents ultimately interact with organizational data, the framework requires that data access policies and permissions be properly configured before agents can operate safely. This approach treats data governance as a prerequisite rather than an afterthought in AI agent deployment.
For high-risk operations, Snowflake recommends implementing multi-approval requirements as a final safeguard against both errors and compromised accounts. The current standard requires two administrators to approve sensitive actions like deleting backup data, reducing the likelihood that a single compromised account could cause catastrophic damage. Mayank suggested this threshold may increase as threats evolve and organizations deploy more powerful autonomous agents.
Source: https://cybermagazine.com/articles/snowflakes-mayank-upadhyay-on-securing-ai-agents


