Snowflake Makes Data Governance Central to AI Security
Data Governance Becomes an AI Security Priority
Alan Shimel speaks with Mayank Upadhyay of Snowflake during Techstrong TV’s Black Hat 2026 coverage. The conversation explores why AI security and data governance are becoming linked priorities for enterprise teams. Upadhyay explains that Snowflake sits at the center of enterprise data, AI adoption and security operations. That position gives the company a practical view into what organizations need as they move toward agentic AI.
Upadhyay also discusses his move to Snowflake after more than two decades at Google. His background includes work on two-step verification, passkeys, Google Cloud security and zero trust. At Snowflake, he now leads both product security and internal security programs. That combined role shapes his view that security cannot be separated from the data and platforms that power AI.
Agentic AI Needs Better Guardrails
The interview focuses heavily on the risks created by AI agents. Upadhyay describes agents as powerful systems that need clear limits. They may not be malicious on their own, but they can explore systems quickly and act on permissions they should not have. That makes AI security and data governance essential before enterprises scale agentic workflows.
For security teams, the first step is getting the basics right. Upadhyay points to permission cleanup, vulnerability management, open storage buckets and source code risk. These issues are not new. The difference is speed. AI agents can find weak spots faster than people can manually respond.
Security Must Move at AI Speed
Upadhyay argues that defenders need more automation. Human-speed security is not enough when agents can move through systems quickly. He recommends AI-assisted scanning, automated pull request checks and real-time detections that run close to data entry points. Platform engineering teams will play an important role in making that possible.
The discussion also covers deception as a useful control. Upadhyay suggests planting tripwires, fake credentials and other signals that help teams detect unusual agent behavior. These techniques can expose both malicious activity and accidental overreach. They also give security teams faster feedback when agents interact with sensitive systems.
A Short Window to Prepare
The conversation closes with a warning and an optimistic note. Upadhyay believes enterprises have a limited window to prepare for more capable open-weight and proprietary AI agents. He encourages teams to use AI defensively now, improve their security practices and build stronger foundations before the threat landscape accelerates.
For Techstrong TV viewers, the takeaway is clear. AI security, data governance and platform engineering are now connected. Organizations that strengthen those foundations will be better prepared for the agentic era.
Transcript
Hey everyone, we're back here at Black Hat. I don't know why we came back on this show floor here to this chaos, when we had such a nice little setup with our stepper room, but we're here. And I'm here to interview someone from Snowflake.
You may ask, "Snowflake at Black Hat? " I'm glad you asked that because we're going to answer it. Let me introduce you to Mayank Upadhyay.
Thank you, Alan. Really nice to meet you. I did justice to your name?
You did absolute justice to my name. Thank you. Mayunk, thank you for joining us here.
I know it's a little bit crazy on the show floor, but I wanted to talk to you. I asked the question right off the bat, what's Snowflake doing here? But before we get to that, give, if you wouldn't mind, our audience a little bit of your history.
Yeah. No, thank you. Let me tell you a little bit about what I'm doing here, and definitely, yeah, we'll go into what Snowflake's doing here.
So look, I've been in the security industry for a while. I spent 21 years at Google right before coming here. There were a number of interesting efforts I led there, everything from two-step verification, passkeys, to GCP security.
I was leading that for the last few years. And one of the things I realized is that there's Frontier Models doing a tremendous-- Frontier Labs doing a tremendous amount of work when it comes to the consumer side. But I was very interested in the enterprise side.
And you look at Snowflake, it's a super trusted brand with 14,000 customers, 800 of the Fortune 2,000, who've got all the enterprise context in here. Now you take that data, and you take this AI revolution, and the third piece of that trifecta is security. Yeah.
It's a fabulous combination to be doing some cutting-edge work. So that's what brought me here. I joined in January, and I've taken over both the security product aspects as well as the CISO team.
So it's an opportunity for us to redo how we're offering our products, also how we run our own security. So you're actually running internally Snowflake's security- That's right ... in addition to the external Snowflake security.
Exactly. Yeah. Wow.
What a great charter. That is very cool. Yeah.
No, hundred percent. That's a gig. So Mayunk, look, I think everyone on our side knows Snowflake, right?
They probably, one of the leaders of the data revolution, right, of what we can do with data, and data laking, and data management, and everything else. But you're right. When you look at this triangle, if you will, or better yet, the three stool- the three- Yeah, three legs of the stool.
Yeah ... legs of the stool. Two legs seemed a lot stronger and bigger than the third leg, and no one wants a stool that goes like this, right?
We want a stool we can sit on. Yeah. Why now?
Yeah. So look, Snowflake has always been very trusted when it comes to data. Right.
When you look at everything that's going on in the AI world, there's really, it's like this Russian doll. Everybody's saying, "Look, there's a model. " Right.
And ultimately people are talking to the data, so that solid foundation of data governance is important, right? So this is the time when you've got to help people think through all three of those. " Right.
" Yes. Right? And if you've been following the news in the last couple of weeks, it's all over the place.
No, I haven't been following anything. So, if you see what's going on with the Hugging Face situation, it's actually very timely we're having this conversation. So I call these two sides of the same coin.
How do you govern and manage your agents internally, and then how do you protect yourself from agents outside who may inadvertently be attacking you, right? Or maliciously, right? It could be either one of those.
So here's my take. And again, this comes from 30 plus years in this. If a hacker designs an agent to do malicious stuff, is the agent malicious or was the hacker malicious?
Yeah. There are no bad dogs or bad children. There's bad parents and bad- Yeah.
That's right ... But the flip side of that is when we look at the Hugging Face- Yeah ... and the recent Anthropic similar, right?
Whether you believe that was marketing or not. The agents themselves weren't malicious. Yeah.
It was the people that didn't do a good job of putting the guardrails in, of containing them. Yeah. But this is the problem we have.
I was just talking to the fellow in G Rittenhouse over at AWS, who's running their agentic AI security. And it's about the govern-- There's two aspects. Yeah.
And I think you hit them both. One is about the governance. Yeah.
I don't care whose agent it is. Yeah. Is it an agent I wrote?
Is it a third-party agent I've engaged? Yeah. Is it a partner's agent?
Yeah. If you're going to interact with my infrastructure- Yeah ... I have rules.
Yeah. I have rules that you got to- You've got to abide by. Yeah ...
And I think that's what's missing. Yeah. Look, I don't think in this particular case anybody was malicious.
No. I think there was good intent, and companies are working closely to get just the learnings from there and spread it to the community. We can talk about those as well.
Mm-hmm. But, I think agents are like little puppies. Yeah.
You lay down the treats and you tell them what path to follow, and they'll just do it. Right. Right?
So they're not really malicious per se. You can sort of point them in the wrong goal to accomplish what you want, and sometimes they get confused. Like in this particular case, it was an agent that was evaluating a cyber arena, right?
Yeah. It's trying to figure out how to break out of it. And it didn't realize that it broke out of the simulation and was in the real world, and it was doing- But sometimes you don't know it's in a simulation.
Yeah. That's right. We may be in a simulation.
It's the whole Matrix argument, though. That's right. I like that.
So, I think it's both a responsibility for you to have the right guardrails around your own agents, like what do you do there? Make sure you've got the right telemetry where you're seeing exactly what the trajectory and what the traces are that your agents are doing. You're continuously monitoring it.
But on the flip side, if somebody else's agent is attacking you, there's a number of things you can do there. And so, I think it's worth talking about, what are the learnings coming out of it from a security architecture perspective? What should people be doing?
And as I read about this, I've basically broken it down to two things, like every other good thing in the security world. You've got preventative stuff and you've got detective stuff. Absolutely.
So in this case, there's one more third leg which I'm going to add, which is the deception stuff, okay? Because these little puppies can be deceived pretty easily. Yes.
So let's talk about each of those. So the preventative side, it's back to the basics. Yeah.
People have said vulnerability management. Well, guess what? Vulnerability management has to be continuous now.
You can't have like a patch Tuesday, right? No. You've got to be fixing things on the spot.
You've got to left shift this as developers are writing code. And that's long overdue, right? A hundred percent.
I did a security company. We came out with a vulnerability management program in 2003. Yeah.
Not much has changed. It's scanning and putting it on a list to patch. Well, the good news now is that you can have AI that is scanning PRs, so before the PRs are merged, you can actually stop the developer.
I think that's a really important change that's happening now, and everybody has to take that seriously. The second aspect about cleaning up sort of things which have always been broken is over-permissioning. This is when somebody's been at a job for five years, they've switched their roles but their permissions were never removed.
Right. They were just continuously added. Absolutely.
Now, when this person deploys an agent, the agent suddenly inherits all these permissions, right? And you give the agent a task, and now the agent's going to look under every rock. It's going to try and use every permission it has to do whatever it can to get to that goal.
And if you over-permission the agent, it's going to have unintended side effects. Yeah. So it's super important that permission cleanup is happening.
This is back to one of those most important things, back to basics. Back to basics. It starts with zero trust.
This is the third conversation today I've had on the same subject. You can't leave your common sense and your 30-plus years of security best practices- That's right ... at the door when you walk into this agentic group.
That's a very interesting statement there, which I like. These vulnerabilities have always been around, and what agents are doing is sort of putting a spotlight on those now, right? Yeah.
Because they will find those and exploit them. Absolutely. You talked about deception.
Yeah. Are we talking about deceiving the agents in terms of what they're doing or... Yeah.
So I'm talking about deceiving the agents because like I said, these agents are like puppies, so you can lay out treats to them. You can say, "Hey, guess what? " And they'll go and try using those credentials, and you can set up tripwires, and you will learn that there's an agent there.
Absolutely. So I think that is It's still relatively new- Yeah ... in terms of this.
And I call that an emerging best practice. That's right. Yeah.
Because we've got to be setting those up throughout. Yeah. Let's get back to Snowflake, if you don't mind.
You came in here with a great charter, internally and externally. How do you change the culture of a company that wasn't a "security company" before to now be, if not a security-first company, a security company? Look, Snowflake has always been really solid about security.
Our customers trust us immensely with security of the data, right? Right. But what's happening now is there's an additional dimension, which is the AI world is evolving so fast, so we're at the bleeding edge of creating new paradigms around security AI.
So this is more of a thought leadership and getting your employees to also use AI so then they realize how they can secure their own use of it and how our customers might want to use it, right? So there's a lot of internal encouragement where we have a team that's called our frontier security team, who's explicitly creating our cyber harness and enabling every team inside Snowflake to use this for securing their workflows. Mm-hmm.
We have automatic PR gates, which will look at every pull request you're doing and try to educate you on what may be wrong with it. There's a number of things there. It's all about getting into that automation mindset, because finding and fixing things at human speed is not going to cut it when you've got agents attacking you, right?
So it's all about getting people to feel the urgency and also have them feel supported, that you've created the right tooling for them so they can migrate to these new kinds of automations. I love it. I got two more areas I want to touch on.
com. The fastest growing segment in the platform engineering space is data management. Yeah.
Right? Creating a platform that allows data management to, within guardrails, go as fast as you want at AI scale, AI speed. For our platform engineers out there, what should they be doing from an agentic AI perspective to do that at AI scale, at AI speed?
Look, data and platform are the foundation of this. If you don't have those basics right, you're going to be toast, because agents will find those vulnerabilities at a speed where no human can keep up, right? So I go back to this framework of get your basics correct, make sure you've cleaned up permissions, make sure if you've got known vulnerabilities, you push your teams to fix them.
Your open storage buckets, excessive permissions, or source code that needs to be patched, push very hard for that. The second thing I would say, detections are very important. A lot of detections are used to working at some sort of periodic cadence, maybe every five, 10 to 15.
If an agent is breaking in, that's not going to cut it. So you need to have real-time detections which are happening and streaming. Your platform team is going to be very key to enable your security team to deploy these real-time detections very close to those entry points or very close to where the data is.
So you folks are going to have to help your security teams with this. And the third thing, like I said, just deploy deception techniques around the different parts of the platform. So think a little bit creatively, think out of the box on how you can help work with your security team on this.
I think this is a great time for everybody to feel energized. There's a lot of concern out there about how the world is going to collapse because of AI. I'm actually very optimistic.
I think a lot of the holes which we wanted to fix in security go, the cage now, we actually have a shot at fixing them because we are prioritizing these things and because we have AI tools to help find and fix these things. So that's what I would say. Excellent.
One more topic for you. I think in retrospect, we're going to look at this Hugging Face and the Anthropic thing as benign, because there were upstanding companies, meaning OpenAI and Anthropic, who were pretty transparent about what happened here. I worry about all of these open-weight models as they proliferate into the market, and you're going to have companies who maybe aren't as ethical or aren't as transparent using open-weight model agents that wind up doing harm.
Yeah. Look, I think that genie's going to be out of the bottle soon. Oh, yeah.
You've got maybe a three to six-month window. At most. So use this three to six-month window to get ahead of the curve and fix your own security practices, try to deploy as much AI, maybe even open-made models to work for you.
Right? I'm not against. I actually think these open-made models are complimentary to proprietary models.
It allows security teams to deploy this in a way where your sensitive data remains within your boundary. It also allows you to fine-tune these models for your environment. So work with them, or get a solution from a vendor, but get ahead of that curve.
You've got three to six months to do that. So I think this is the time, and I love the fact that you're working to get this message out right now. I love it.
Mayuk, we have to move on. But you know what? First of all, congratulations.
Welcome to Snowflake. Thank you. Number two, I'd love to stay in touch with you on this because I think you've got a great view on it, number one, and number two, I think this is really something our audience is- I'm very happy to help.
I think this is a moment where the entire industry is evolving really fast, and I'm happy to help spread the message. I love it. All right.
We're here at Snowflake at Black Hat. We're going to be moving and grooving here on the show floor. We'll be back with more.
You're watching Techstrong TV.