As AI pilots give way to large-scale deployments, Snowflake pitches its data cloud as the central control layer for enterprise AI agents, unifying models, applications, security and governance to unlock ROI from production-grade GenAI.

As enterprises move artificial intelligence from pilots and proof-of-concepts into production, Snowflake is positioning its data platform as an “agentic control plane” that brings together enterprise data and context, AI models, applications, security, and governance as companies increasingly deploy AI agents.
“The important thing to note is that we moved on from that phase of POC pilots and all of that. Today, when we speak to customers, a lot of them are moving to production,” Vijayant Rai, MD, India, Snowflake, said in a conversation with Fortune India on the sidelines of the company’s annual event in Mumbai.
The company said 13,600 customers were using AI functionality on its platform in the first quarter, compared with a few thousand in the same quarter a year earlier. As adoption moves into production, enterprises are increasingly looking at how agents should be authenticated, what they should be allowed to do and how their actions can be traced.
Rai said Snowflake sees the move towards agentic enterprises as involving data and context, AI models and enterprise applications, with security and governance tying these elements together. “We believe that Snowflake is right now positioned as the agentic control plane where all of this comes together,” Rai said.
The executives said that while access to increasingly capable AI models is becoming easier, enterprises are finding that the quality and context of their own data can determine whether those models deliver useful outcomes.
“Data is foundational to AI. We believe there’s no AI strategy without a data strategy,” Rai said. “What AI, though, has done is it has accelerated that conversation.”
This is particularly relevant in India, where traditional enterprises still have significant amounts of data on-premise and are at different stages of cloud migration. “When people start experimenting quickly with the excitement of AI and models, they very quickly discover that their data is not in shape. They need to do something about it,” Rai said.
Snowflake’s approach is to bring the model to the data rather than moving enterprise data to the model. The company said AI systems need to be grounded in business context, including enterprise data, business rules, semantics, permissions and security.
“When the model is grounded on contextual and semantically valid data, then there’s a lot more you can derive from the model,” Rangarajan Srirangam, senior regional vice president of Solution Engineering-India, Snowflake, said. “The principle is that content without context is just commotion.”
Snowflake’s 2026 The ROI of Gen AI and Agents report separately found that 65% of global respondents considered breaking down AI data silos challenging or very challenging. Preparing data to be AI-ready and measuring and monitoring data quality were each cited by 62% as challenges. On average, respondents said only 20% of their unstructured data and 32% of their structured data was AI-ready.
Snowflake said its security architecture is built around a “defence in depth” approach, with controls across authentication, authorisation and AI-specific safeguards. It has introduced “agent identity” to distinguish AI agents from human users, while role-based access controls determine what an agent can access and what actions it can perform. “Authentication is fundamental. We both identify the user as well as the agent. For agents, we specifically brought this capability called agent identity,” Srirangam said.
Snowflake also has AI-specific safeguards under its Cortex AI Guardrails framework to address threats such as prompt injection, alongside controls for token consumption, budgets and service-level limits. The platform can also audit and trace agent activity.
Rai said greater AI adoption would not eliminate the need for human oversight, particularly around decisions and the business context provided to AI systems. “Things like critical thinking, decision making, all of that will remain in the realm of the human still,” Rai said. “You will still need to have somebody who’s creating the semantic layer for it, what all is this supposed to understand for my business.”
As deployments scale, Snowflake executives said the question is shifting from whether AI can improve productivity to whether it can deliver measurable business outcomes.
“Why you don’t get ROI is either because some business outcome has not been tied to a technical outcome, or the technical outcome has not been correctly tied to an AI outcome,” Srirangam said. “Or the third and most important problem is that the AI outcome is not getting achieved.”
He said the issue is often not the model itself but the context in which it operates. “Usually it doesn’t get achieved, not because the model is not good. The models are as good as they can be, but because the model is not grounded on meaningful context,” Srirangam said.
Snowflake’s research found that 92% of global early adopters reported positive returns from GenAI, while respondents that quantified their returns reported an average return of 49%, up from 41% in the previous year’s research. Separately, 32% said they already had agentic AI solutions in production.
In India, 71% of respondents said they had quantified positive GenAI ROI, compared with 61% globally. The report also found that 66% of Indian respondents were already using agentic AI or had definitive plans to deploy it within 12 months, versus 56% globally.
Data sovereignty is also becoming part of enterprise AI conversations, with requirements differing across customers and industries, Srirangam said.
He said Snowflake gives customers the choice of whether to allow cross-region inference, deployment and data replication depending on their requirements. “Some customers, by requirement, would like to have it within the region. Some customers do not have such a requirement and they do not mind going cross-region,” Srirangam said.
Asked about agents going beyond their intended tasks amid recent concerns around frontier models operating outside controlled environments, Srirangam said enterprises need to apply the principle of least privilege. “Sometimes an agent does more than what it is supposed to do not because the agent hacked and found a vulnerability. It is more because the agent was given more permissions than it was supposed to have,” Srirangam said.
“If an agent is primarily going to generate a report, it should not be given write permission. If an agent is primarily going to generate data, store data and create a report, it probably should not have delete functions.”