Agent Gateway Spend Governance: AWS, Snowflake, Google and Microsoft Compared · Enterprise Agentic AI Insights

Agent spend has no owner and agent actions have no sequence record. Compare native gateway controls across AWS, Snowflake, Google and Microsoft, with a free comparator.

The call usually comes from finance, not from security. Somebody in FP&A pulls the cloud invoice, sees a line that has tripled since Q1, and asks a question that sounds simple. Which team is this. The CIO opens the console and finds the honest answer is that the platform can tell you what was spent and roughly what model spent it, but not which agent, which workflow, or which business owner. The spend is real. The owner is a reconstruction project. That is the meeting that is happening on a lot of CIO calendars this month. Nearly half of enterprises now report that AI spending surprises have escalated to board level, a quarter are delaying or cancelling initiatives on unforeseen cost, and a third have already imposed emergency spending freezes. <span class="chip cited"CITED C07</span Here is what changed in the last six weeks, and why it matters more than the invoice. Four platforms, one answer, six weeks Four platform ecosystems, starting from four different products with four different commercial motives, all shipped the same primitive between late June and mid August. A gateway that sits between the agent and the tool it wants to call. <figure class="ariana-chart" role="group" aria-label="Timeline of four platform agent gateway releases between 24 June and 18 August 2026" <svg viewBox="0 0 900 320" xmlns="http://www.w3.org/2000/svg" style="width:100%;height:auto;background:0D0F12;border:1px solid rgba(255,121,0,0.22);border-radius:14px" role="img" aria-label="Timeline showing Google Model Armor on 24 June, Snowflake Cortex AI Gateway in late July, Microsoft Conditional Access for Agents in early August, AWS Bedrock AgentCore temporal policies on 6 August, and Google Gemini Enterprise Agent Platform general availability on 18 August" <text x="30" y="40" fill="07A3D1" font-family="Roboto,Arial,sans-serif" font-size="17" font-weight="600" letter-spacing="1.6"SIX WEEKS, FOUR PLATFORMS, ONE CONTROL POINT</text <line x1="40" y1="150" x2="860" y2="150" stroke="rgba(237,232,227,0.28)" stroke-width="3"/ <g font-family="Roboto,Arial,sans-serif" <g<circle cx="80" cy="150" r="11" fill="07A3D1"/ <text x="80" y="126" fill="rgba(237,232,227,0.72)" font-size="16" font-weight="600" text-anchor="middle"24 Jun</text <text x="80" y="190" fill="rgba(237,232,227,1)" font-size="18" font-weight="600" text-anchor="middle"Google</text <text x="80" y="214" fill="rgba(237,232,227,0.88)" font-size="15" font-weight="500" text-anchor="middle"Model Armor</text <text x="80" y="234" fill="rgba(237,232,227,0.88)" font-size="15" font-weight="500" text-anchor="middle"at the gateway</text</g <g<circle cx="270" cy="150" r="11" fill="FF7900"/ <text x="270" y="126" fill="rgba(237,232,227,0.72)" font-size="16" font-weight="600" text-anchor="middle"Late Jul</text <text x="270" y="190" fill="rgba(237,232,227,1)" font-size="18" font-weight="600" text-anchor="middle"Snowflake</text <text x="270" y="214" fill="rgba(237,232,227,0.88)" font-size="15" font-weight="500" text-anchor="middle"Cortex AI Gateway,</text <text x="270" y="234" fill="rgba(237,232,227,0.88)" font-size="15" font-weight="500" text-anchor="middle"cost attributed per agent</text</g <g<circle cx="460" cy="150" r="11" fill="FF7900"/ <text x="460" y="126" fill="rgba(237,232,227,0.72)" font-size="16" font-weight="600" text-anchor="middle"Early Aug</text <text x="460" y="190" fill="rgba(237,232,227,1)" font-size="18" font-weight="600" text-anchor="middle"Microsoft</text <text x="460" y="214" fill="rgba(237,232,227,0.88)" font-size="15" font-weight="500" text-anchor="middle"Conditional Access</text <text x="460" y="234" fill="rgba(237,232,227,0.88)" font-size="15" font-weight="500" text-anchor="middle"for Agents</text</g <g<circle cx="650" cy="150" r="13" fill="FF4F00"/ <text x="650" y="122" fill="rgba(237,232,227,0.72)" font-size="16" font-weight="600" text-anchor="middle"6 Aug</text <text x="650" y="190" fill="rgba(237,232,227,1)" font-size="18" font-weight="600" text-anchor="middle"AWS</text <text x="650" y="214" fill="rgba(237,232,227,0.88)" font-size="15" font-weight="500" text-anchor="middle"Temporal policies</text <text x="650" y="234" fill="rgba(237,232,227,0.88)" font-size="15" font-weight="500" text-anchor="middle"and rate limiting</text</g <g<circle cx="830" cy="150" r="11" fill="07A3D1"/ <text x="830" y="126" fill="rgba(237,232,227,0.72)" font-size="16" font-weight="600" text-anchor="middle"18 Aug</text <text x="830" y="190" fill="rgba(237,232,227,1)" font-size="18" font-weight="600" text-anchor="middle"Google</text <text x="830" y="214" fill="rgba(237,232,227,0.88)" font-size="15" font-weight="500" text-anchor="middle"Agent Platform</text <text x="830" y="234" fill="rgba(237,232,227,0.88)" font-size="15" font-weight="500" text-anchor="middle"general availability</text</g <text x="40" y="292" fill="rgba(237,232,227,0.72)" font-size="15" font-weight="500"Sources C01, C03, C04, C05, C06. Chips carried in the source list below.</text </g </svg <figcaptionFour ecosystems arrived at the same primitive between 24 June and 18 August 2026: a gateway between the agent and the tool.</figcaption </figure - 24 June. Google's Model Armor becomes enforceable at the Agent Gateway layer, screening every prompt and response passing through for injection and sensitive data leakage, without touching agent code. Agent Identity gives each agent a trackable persona with end to end mTLS, and Identity-Aware Proxy plus IAM validate that identity before a tool call is allowed. <span class="chip verified"VERIFIED C04</span - Late July. Snowflake launches Cortex AI Gateway at Black Hat 2026, built on its May acquisition of Natoma. It enforces identity, policy and audit at the tool call level, and it attributes token cost to the team, the agent or the workload that drove it, with spending limits that stop runaway usage before it lands. <span class="chip verified"VERIFIED C03</span - Early August. Microsoft completes the rollout of Conditional Access for Agents and ID Protection for Agents into Microsoft Agent 365 and Microsoft 365 E7. Agent 365 becomes the registry and control plane, Entra Agent ID stays the identity foundation. <span class="chip verified"VERIFIED C06</span - 6 August. AWS adds temporal policies and rate limiting to Bedrock AgentCore. Temporal policies evaluate each request in the context of the agent's prior actions inside a session, on the explicit premise that a single tool call can be safe alone and harmful given what preceded it. They can enforce workflow sequencing, require a tool argument to match a prior call's output, require human approval before a privileged action, and enforce data freshness. Rate limiting caps requests, inference tokens and concurrent connections per user or per group. <span class="chip verified"VERIFIED C01</span - 18 August. Google announces general availability of the Gemini Enterprise Agent Platform, with agents holding state across days on dedicated Agent Identity credentials that log every operation. <span class="chip cited"CITED C05</span Four vendors do not converge on the same architecture by accident. They converged because the tool call turned out to be the only place where the two questions the enterprise is actually asking can both be answered. Whose budget did this consume, and can we defend what it did. The primitive that answers both questions The reason the gateway wins is that a tool call is the first moment where an agent stops being a conversation and starts being an action with a cost and a consequence. Attach an identity to that moment and finance gets attribution. Attach a policy to that moment and risk gets a control. Attach a log to that moment and the audit function gets evidence. One record, three departments, which is why this stopped being a security purchase and became a platform feature inside two quarters. The economics push hard in the same direction. Agentic tasks consume somewhere between 5 and 30 times the tokens of a single chatbot turn for the same job, and Gartner

Open the formatted article on Ariana.Digital →