2026-08-12
The Convergence Happened in the Catalogue
Within seven weeks in mid-2026, Snowflake and Databricks independently moved AI governance into their data catalogues. The convergence that matters is not between models, it is between AI and the data stack, and it has already shipped.
On 2 June 2026, Snowflake announced that its data catalogue would begin issuing verified identities to AI agents, so that no agent could reach enterprise data or take an action without one. Fourteen days later, Databricks announced that its data catalogue would govern models, agents, MCP services and skills using the same framework it already applied to tables. The two companies were not answering each other. They arrived at the same architectural conclusion separately, and it is the most consequential thing that has happened in enterprise AI this year.
The convergence that gets discussed is the one between models. The convergence that matters is the one between artificial intelligence and the data stack, and it is no longer a forecast. It shipped.
What the record says
It is worth setting out the sequence precisely, because the dates do most of the work.
At Snowflake Summit 26 on 2 June, Snowflake positioned Horizon Catalog as, in its own words, the universal AI catalog for enterprise data. Two capabilities carried the announcement. Horizon Context exists so that every person, tool and agent draws on the same definition of a business term, on the reasoning that an agent recommending a price rise from a revenue figure defined three different ways will confidently recommend the wrong thing. Agent Identity, now generally available, gives each agent a verified identity before it can reach data or act, enforces role-based permissions, and maintains a complete audit trail of every agent activity. Christian Kleinerman, the company's EVP of Product, framed it as trust ceasing to be an afterthought once intelligence becomes autonomous. BlackRock is named as a customer already using Horizon Context.
At Data and AI Summit on 16 June, Databricks extended Unity Catalog, its data governance layer, to register, secure and audit models, external model providers, MCP services, agents and skills through the same governance framework organisations already use for data. A companion product, Unity AI Gateway, enforces policy at the moment of action rather than the moment of access: allow, deny, or require approval for pushing code, writing to a sensitive folder, or returning regulated data. It also does something more prosaic and more revealing. It sets hard spend caps.
On 28 July, Snowflake shipped its own gateway. Cortex AI Gateway governs how agents reach models, tools and MCP servers, supports more than a hundred of them, attributes cost, enforces spending limits, and produces an end-to-end record of what each agent did. It is built on Natoma, an enterprise MCP platform Snowflake acquired in May. Mayank Upadhyay, its Chief Security and Trust Officer, described the shift as one from data interoperability to agent interoperability, and claimed the position of trusted control plane outright.
Seven weeks, two companies, one architecture. Read the partner lists and the point sharpens. Okta, SailPoint and Saviynt appear on both. The identity governance vendors are being wired into the data platform, not into the model layer.
The strongest case that this is marketing
That case deserves stating properly before it is answered, because it is not a stupid one.
Two data companies have every commercial reason to insist that AI is fundamentally a data problem. That is the thing they sell. Vendors have been renaming existing products after whatever is fashionable for forty years, and a catalogue with the word agent added to the datasheet is precisely what that looks like. Meanwhile the capability that actually changed the world is being built somewhere else entirely, by laboratories that do not sell warehouses. And the Model Context Protocol, now the standard way to connect a model to a system, arguably makes the platform underneath irrelevant. If anything can plug into anything, the plumbing is a commodity and there is no moat to defend.
That argument is right about the mechanism and exactly backwards about the consequence.
Why the protocol argument fails
On 9 December 2025, Anthropic donated MCP to the Linux Foundation, which established the Agentic AI Foundation to house it alongside Block's goose and OpenAI's AGENTS.md. More than ten thousand MCP servers had been published by then. The platinum members are Amazon Web Services, Anthropic, Block, Bloomberg, Cloudflare, Google, Microsoft and OpenAI. Snowflake, Oracle, SAP, Salesforce, IBM, Cisco and Okta sit in the gold tier. The connection layer between AI systems and enterprise data is now neutral, standardised infrastructure owned by nobody in particular.
Which is exactly why connection has stopped being the difficult part, and permission has become it.
Notice what the two vendors are actually selling. Snowflake's gateway governs third-party agents developed on external platforms, built by other companies and running models Snowflake does not own. Databricks ships managed MCP services for Google Drive, Jira, Confluence, Slack, GitHub and SharePoint, none of which it owns either. Neither is charging for the pipe. Both are charging for the ledger: the record of which agent, acting on whose behalf, touched what, and whether it was permitted to.
The model was never going to be the advantage
The 2026 AI Index, published by the Stanford Institute for Human-Centered AI in April, contains the number that settles this. Across evaluations in tax, mortgage processing, corporate finance and legal reasoning, the top fifteen models are separated by as little as three percentage points. On broad knowledge benchmarks the spread between the first and the fifteenth is just over four points. As of March 2026 the leading American model held a lead of 2.7 per cent over the leading Chinese one, down from a substantial American lead in 2023 that had already narrowed to near parity by early 2025.
To be fair to the other side of this, the same chapter records that agents still fail roughly one in three attempts on structured benchmarks, and that robots succeed at only 12 per cent of real household tasks. This is not a story about the technology being finished. It is a story about where the scarce thing sits, and the scarce thing is plainly not the model, because a competitor can be within three points of yours by close of business.
The part that should make every executive sit up
McKinsey's 2026 AI Trust Maturity Survey, published on 25 March and covering roughly 500 organisations surveyed between December 2025 and January 2026, reports average responsible AI maturity rising to 2.3 from 2.0 the year before. Underneath that average sits the finding that matters. Data and technology is the strongest of the five dimensions measured. Governance and agentic controls are the weakest, and they are the weakest in every region.
Nearly two-thirds of respondents named security and risk as the top barrier to fully scaling agentic AI, well ahead of regulatory uncertainty and well ahead of technical limitations. The share of organisations reporting an AI incident held steady at roughly 8 per cent, but almost 60 per cent of those who experienced one rated their own response as merely satisfactory or worse. Organisations with an explicitly accountable function averaged 2.6 on maturity. Those without averaged 1.8.
Read those together and the picture is not ambiguous. Firms have built the pipes and not the permissions. What is holding AI back in most companies is not the capability of the model, and it is not, whatever the current fashion for blaming Brussels, the rulebook. It is that nobody can say what happened.
What follows
Five things, and none of them are exotic.
The AI platform decision is now a data platform decision. Running them as two separate procurements produces two separate answers to the same audit question.
One catalogue. Every additional one is a place where the answer to "who accessed this" differs from the answer next door.
Agents need identity in the same sense employees do: scoped to the task, time limited, and attributable to the person on whose behalf they act. Both vendors have now built precisely that, which tells you the standing-credential model has already failed somewhere expensive.
Treat AI consumption as a governed line item. Two competitors shipping hard spending caps within seven weeks of each other is not product vision. It is customers opening invoices.
And whoever owns data lineage in your organisation now owns AI governance, whether the organisation chart has caught up or not.
Firms spent 2024 and 2025 choosing models. That choice is converging towards not mattering, and the two vendors closest to the problem have moved their entire product strategy onto the assumption that it already does not. What is left is the unglamorous question underneath. When an agent acts in your name, can you name it, scope it, and account for it afterwards? Your catalogue already knows the answer. The question is whether you do.
