Jacob Thomas, Texas Children’s Hospital & Pratyus Patnaik, Snowflake | theCUBE + NYSE Wired
Watch on YouTubeVideo summary
The discussion centers on a pivotal shift in enterprise technology where AI agents are evolving from passive tools that answer questions to active entities capable of implementing actions across various systems. This transition introduces significant cybersecurity challenges, as organizations must now manage digital employees with full access to databases, APIs, and applications. Jacob Thomas from Texas Children's Hospital highlights the unique stakes in healthcare, where security failures could directly impact patient health rather than just financial data or reputation. Consequently, hospitals face the complex task of balancing innovation with strict regulatory requirements, necessitating robust governance models that can audit every action taken by non-human systems to ensure they operate within authorized boundaries.
To address these risks, Pratyush Patnaik of Snowflake explains how their partnership with Netoma extends enterprise governance beyond static data at rest to cover data in motion between agents and different systems. This solution acts as an "AI gateway," providing dynamic identity perimeters and runtime environments that enforce policies in real-time. Unlike traditional Identity and Access Management (IAM) which relies on static scopes for human users, this new approach requires continuous monitoring and decision-making capabilities at runtime to determine if an agent's current actions are appropriate. The goal is to create a system where access is granted based on immediate context and necessity, effectively turning security from a bottleneck into an enabler that allows safe scaling of AI initiatives across the entire enterprise ecosystem.
A major theme of the conversation is the critical role of cost management and operational efficiency in driving AI adoption, particularly regarding token consumption and inference costs. The speakers argue that while building agents is easy, deploying them wholesale requires careful financial oversight to ensure a strong return on investment. Strategies such as sandboxing environments, utilizing FinOps practices, and optimizing model selection help organizations understand exactly where execution loops occur and how to maximize value. By proving that specific metrics are met and demonstrating clear business value, security teams can alleviate concerns from finance leaders like CFOs, ensuring that the necessary investments in guardrails and monitoring do not stifle technological progress but rather support sustainable growth.
Looking ahead, the industry must prepare for emerging threats such as model escape scenarios, where an AI agent without malicious intent might inadvertently breach security boundaries and compromise other systems. The consensus is that these risks are not new to cybersecurity but represent an evolution of existing challenges that require updated mitigation and compensating controls. Snowflake's future roadmap focuses on efficient intelligence and owning the enterprise context, enabling customers to build bespoke solutions rather than relying solely on off-the-shelf products. Ultimately, the path forward relies heavily on strong partnerships between technology providers and security experts to create a resilient infrastructure that can safely harness the power of AI agents while maintaining strict accountability and auditability in an increasingly complex digital landscape.
Read the full video transcript
Hello out those studio connecting
Silicon Valley and Wall Street.
>> I'm John Furrier co-host of the Cube
here with Dave Vellante my co-host.
>> Welcome to the Cube studio here at the
New York Stock Exchange. I'm Gemma Allen
with NYSE Wired cybersecurity leaders, a
show connecting Silicon Valley to Wall
Street talking to the folks shaping
what's next in tech, business, and
capital markets. Today we're talking
about one of the biggest shifts
happening in enterprise tech right now.
That is AI agents moving from answering
questions to actually implementing
actions creating a hugely new problem
for cybersecurity.
So the question becomes, if you give an
AI agent the keys to your enterprise,
how do you make sure it only opens the
doors it's supposed to? To unpack that,
I'm joined by two folks looking at this
problem from very different sides.
Pratyush Patnaik, head of enterprise AI
security at Snowflake, and Jacob Thomas,
manager of information security at Texas
Children's Hospital. Welcome, folks.
>> Thank you, Gemma.
>> So, a very interesting time, a lot
happening very fast. You've obviously
We're going to get into your journey
into Snowflake, which I know is very new
but also very critical to the road map
that you guys are building. But first
I'm going to start with you, Jacob.
When we think about
children, especially from the
perspective of children's health and
running a hospital as successful and as
iconic, I guess, in the US health care
system as Texas is, the risks that
cybersecurity threats pose are different
from many others, right? It's not just
about finance, it's not just about
image, it's actually about patient
health.
Talk to me a little bit about what has
changed for you with this rise in AI,
everything that we hear about and talk
about every day on the news. Bring me up
to date on what the last three to four
years have been like from your
perspective.
>> Sure.
So, Texas Children's is, just to level
set, we're the largest pediatric
hospital in America, right? We have over
1,200 beds. So, we're sitting on a ton
of data, right? And the question really
comes down to how do we use that data
efficiently?
For us, it it is absolutely a a
game-changing event for us to start
looking at it from an AI scope.
Um and for us, it really just comes down
to
leveraging it in a way where we increase
and get better patient outcomes,
uh better patient experience, those kind
of things, right? And we really can't do
that without really leveraging AI. But,
when we first started our journey in
that space, we found that um we can't
just go and grab a model out of like
hugging face and just like run off of
it, right? So, we had to really invest
in our research partners and bring in
like a lot of investments around
building models.
Uh so, that's kind of where we're at.
We're exiting from that stage and
starting to connect it to LLMs and
taking that to the next factor of like
connecting it to our user base.
Yeah.
>> So, we hear a lot about AI agents,
right? This whole concept that has
become ubiquitous really with technology
and the future of tech and some folks
compare it to software, some folks
compare it to an actual digital
employee, right? Which I think is where
Netoma and that journey comes in.
It's an interesting analogy because
employees have credentials, they have
access, they also can be cut off if
needed to be, right? Just if they're
being manipulated or whatever we see
happen. But, we know that in the world
of agents, everything's happening at
huge scale.
Let's talk a little bit about Netoma,
the journey, and I guess the business
alignment and the commercial alignment
with Snowflake.
>> Absolutely. Absolutely. For us, Gemma,
when we started the company, it was we
working with partners like Jacob saw the
the shift happening where
the AI was becoming capable enough
to not just answer questions, but take
actions. That means the agents, the AI
systems had to get access to different
applications, databases, APIs, and that
meant providing an, you know, identity
perimeter to them, assigning an
identity, making sure they are doing
what they're authorized to do, having a
runtime environment to enforce the
policies as needed. Uh which
naturally makes sense for Snowflake. If
you think of it this way, Snowflake is
the AI and data platform of the world,
which is trusted by 13,000 plus
enterprises today.
With Netoma,
Snowflake is able to extend the same
governance, same trust, not just to data
at rest within Snowflake, but also to
data in motion between your agents and
your different enterprise systems. So,
that's what we were able to provide. I
can answer the question in
another way also, but
Snowflake is also one of the most
progressive companies when it comes to
consuming AI, you know, finance
department, M&A integrations. IR,
everything is done agentically, and you
know, Snowflake was using Netoma, and
they saw the value, and probably thought
of they thought about taking it to to
their customers. And you know, it's a
win-win win for everyone.
>> So, Snowflake's had an interesting year
here on the market, here on Wall Street.
We look at the stocks every day, and
earlier this year you guys had a ripping
day on the street, and one of the
analysts, you know, was very clear in
saying this is not just about some big
deal with Amazon. This is actually about
what they're building themselves from
the perspective of Cortex, right? And
that AI gateway.
>> Absolutely.
>> It sounds super exciting, especially to
all your customers, but we know that
again, there is a level of risk, right?
If you have agents talking to multiple
systems at scale,
>> Yeah.
>> how do you actually completely control
and manage that?
>> Yes.
>> So, from your perspective, Jacob, I'm
sure you're also, like every other
industry, under pressure to keep a pace
with the speed of AI, but you do it in a
safe way. What does it fundamentally
change for you? Are you talking about,
you know, scaling more data access to
more digital employees and agents across
your ecosystem. Talk a little bit about
what that agentic layer and and
Snowflake can actually fundamentally
shift in additional workers' life at
Texas Children's.
>> So, don't forget in healthcare we're
heavily regulated, right? So, we we have
to take all of what he was talking about
around our back level controls for every
single one of those data points, right?
And then consider who it is that's
actually touching those things, whether
it's non-human systems versus, you know,
human loop components, right? All of
these components come into play and then
we have to be able to produce that as a
check, right? And it's a check and
balance conversation, right? So, all of
those components has to be mapped out in
some way, right? And that's where we see
the value in something like the Cortex
AI gateway, right? Um I I ultimately
look at it from the perspective of
we're in cyber, we're always known as
the people that tell everybody no,
right? We can't do that. Going into the
innovative areas that we're going into,
right? So, it really comes down to
having the appropriate controls in
place. Those controls come with these
kind of solutions. And that's why we
were speaking to them early on about a
year plus or so, right? Cuz I knew this
is kind of coming around the corner. Um
and once we started exiting and started
going into the LLM space, the next
component will be agentics and that will
come very quickly. Uh so, we have to be
ready for those conversations.
>> So, when we think about what's really
shifting from the perspective agents
accessing data, right? We know that
maybe not systems independently access
data before, but we have had APIs in
place, we've had software operating with
the interoperability or at least a
request for it for quite a while. We've
had IAM, you know, is this essentially
from your perspective like IAM 2.0? Like
how do you really define this category?
>> So, to break it down,
you know, we have had IAM, those are
robust uh solutions out there in the
market, But you have
you've had the humans.
We come with accountability. If I'm
doing something, I'm accountable for my
action. You've had workloads which were
deterministic piece of code someone had
written to go do something. Now you have
agents that fall somewhere in between. I
think you started by saying we're moving
from AI as a software to AI as a
workforce where
a model and LLM reasons decides what it
needs to do. So the
identity that we assign to these agents.
So when it comes to human or workload,
you at authentication when you come in,
you we know who is who, what you can do.
But when it comes to agent, you cannot
give them static
scopes. When they're doing something, a
runtime decision has to be made in the
given the circumstances, does this
access make sense? Can the agent do
this? Is it has something changed that
we need to yank out that permission?
Those things have to be done at runtime.
I think that's the biggest shift that
we'll have to adjust to as agents come
and run your enterprise.
>> When we think about MCP, which is the
fundamentals that this is built upon,
right?
Traditionally, there was a little bit of
skepticism around how secure is that
world, right? Like what does it actually
mean? How can you truly lock something
down if you have systems talking to each
other at such scale? But now it's the
buzzword of the year, right? Like in
France, we hear about MCP all the time.
There's so much excitement. What do you
think it truly means though from the
perspective of security? And I'm going
to put this to you, Jacob. Especially
when you think about a world whereby,
you know, you have a larger attack
surface, right? You have a larger attack
vector if you have agents talking to
each other at the pace and speed and
scale that technologists make us believe
is going to happen tomorrow.
>> Correct. Yeah, the attack surface was
never an issue for us in the past.
Mostly because we were working on
probabilistic models and then moving
into deterministic and and with the
future scope of going on, you know, the
other direction, right?
But as you start introducing MCP into
that conversation, it starts to becomes
a bigger problem for us, right? But it's
not really a problem from an innovative
standpoint. In fact, it makes things a
lot better. So,
we are looking at it from the same kind
of perspective, which is what all needs
that level of access? Is it over
permissive? Is it not over permissive,
right? Well, how how do we tweak that to
the exact necessities that we need? And
then kind of approach it from that
perspective. So, having something sit
there and look at that actual workflow
and understand that workflow so that we
can come back and say, "Okay, this is
exactly what you need." And then you can
just turn everything else off. Is it
still running? Beautiful. That's exactly
what we want.
>> Right. Let's talk about cybersecurity
broadly for a second. Is it a bottleneck
or an enabler of inference, right? Of
change. Cuz there's mixed views in this,
too, right? Things, especially at a
hospital, have to be exceptionally
secure for a very, very good reason,
right? But we also talk about the pace
by which cyber can sometimes slow the
technology race so much. How do you guys
think about that bottleneck? Like, what
is your response to feedback that maybe
it's not so much about the model,
>> Mhm.
>> it's about the actual pace of usage,
pace of access. You know, what are your
thoughts specifically?
>> I'll I'll try to break it down into two
parts, but first of all, models have
been capable, at least when it comes to
enterprise workflows, for a while. Yes,
they
cannot discover drugs just yet, but they
can do everything we do within an
enterprise. What's stopping
a broad-scale rollout of AI within an
enterprise is two parts. Uh until now,
it was mostly security and governance.
Uh it's very easy to build agents. You
can ask an agent to build an agent now.
When when you need to deploy and give
them wholesale access to everything in
the system, that's when things get
tricky. That's when, you know, security
side or the IT side will come in, you
know, wanting to know, "What is this
agent? What is it trying to do?
What did it do in the last 6 weeks?
Where is the audit trail? Those become a
question. So, essentially
part one for AI to go from pilot to to
full broad full scale broad roll out.
Number one is just
taking security, governance, identity,
access control seriously. The governance
should not be review access review
process. It should be part of the
infrastructure.
The second part here now that is I think
top of mind today for most of folks is
cost, you know, cost have blown up.
Uh this is where Cortex at least helps
where we have semantic view of the data
that you know, we have proven numbers
where you know, we bring down the the
token
efficiency and the intel- intelligent
efficiency is what I would call
by a magnitude that's makes
scaling out the AI across the enterprise
easy. And then, you know, we're not just
doing with Naturopath, we're not just
doing it in the data park in Snowflake,
but across your enterprise ecosystem.
Number one, number two is also it's not
tied to Cortex, but to every app you
might be using.
>> Let's stay on cost for a second. This is
an interesting conversation, right? We
know that, you know, in technology,
Snowflake, AWS, all of these huge giants
of industry, they're also huge line
items on a P&L, right? Like an Anaplan
company. And with everything that's
happening so quickly, especially from
the perspective of tech and inference,
there is certainly, you know, a lot of
conversations happening around
consumption, around tokenization.
I'm going to put this to you Jitesh a
tricky question, but how do you think
about that from the perspective of, you
know, your own kind of evangelism of
this kind of tech futuristic picture
that we all foresee? How How do you
think about like the role of a
head of, you know, man- of security and
a CFO? Like those conversations must be
becoming closer and more regular than
they've ever been.
>> Partnerships is is the the answer to
that question, right? So, we we partner
considerably
to understand just the tokenomics of it
all, right? And
it really just comes down to sandboxing
that environment first, letting them run
their models, letting them run their
queries and everything else, right?
Understanding the harness component of
it to understand where exactly the
execution loops are taking place. And
then, are we really getting the value
out of it, right? So,
there are these conversations that take
place, you know, there's people and
process behind the technology, too,
right? So, we have to make sure all
these things are in place, and then that
then delivers the ROI for us, right? Um
it's an investment at the end of day.
There's going to be spend. You can't
avoid that, right? But, really it just
comes down to
do we meet these specific metrics,
right? And understand the success
criteria around that. If you can
pitch that in a way that makes sense,
everybody will buy in, right? That's
That was our take on it. We invested
heavily in that space, and then we built
those guardrails out. We We invested in
FinOps as well.
Uh that really helped push these things
forward, and
there was If we hadn't done that, I'm
pretty sure we would have gotten a lot
of sticker shock from our CFO, right?
All of those things were concerns were
alleviated by doing these specific kind
of things, right? But, it again, it's
people and process behind the
technology.
>> For sure.
>> Also, the world is changing so rapidly
now with all the open weight models,
there are ways to optimize your token
consumption for the task at hand. You
know, you shouldn't be going to people
five to check whether or our simple
task. Even older models are capable in
doing
some of the tasks that are repetitive.
Now, you can bring bring back your, you
know, good old macros in some scenarios
where things have to be done in a very
deterministic way. So, a lot of
investment happening in in making sure
folks are spending
there is a direct correlation between
the token spend and the business value
being delivered.
>> Okay, last question.
Some folks say that inference actually
is a huge threat to cyber, right?
Because we have like key you know,
keystroke logging, we have all sorts of
activities happening that we probably
didn't predict or plan for 5 to 10 years
ago.
>> [snorts]
>> What are your thoughts in terms of the
additional threat factors that are
evolving in this world? Like what sorts
of thoughts are you maybe planning for
or having or even, you know, people are
keeping up at night that perhaps wasn't
like 3 to 5 years ago?
>> I mean, personally for me, that was
always there. Uh it's not like it
suddenly just showed up, right? Uh
and that's reason why we have
a good governance model behind
everything, right? You have to
understand that there's mitigating
controls and compensating controls. If
you plan for that correctly, you can
reduce the attack surface and then
reduce the ability for the threat actor
to do those kind of things, right? Um
that's have always been our approach. Uh
that is not unique to AI. That's that's
specific to anything in our cyber stack,
right? So, we just continue down that
road.
To keep it simple.
>> Keep it simple.
>> I'll add one more thing to it. Uh so, at
Snowflake, obviously we are we have to
protect Snowflake. Something to the tune
of what what Jacob just said. But, the
other thing we're beginning to get
concerned about is our agents escaping
and doing things. You know, recently you
heard the scenario where a model uh
with no mal intent, just trying to do
the task it was assigned, escaped out
and hacked another company.
That has become a reality now, [snorts]
and we need to have proper guardrails,
proper monitoring, proper auditability
to stop those things from happening,
too.
>> That's something that's keeping
Snowflake
>> I think it's keeping us all awake at
night, right? We just saw earlier
somebody had
modeler a bad actor had hacked someone's
phone and contacted the PM of England
just this morning, right? So, there's
all sorts of crazy stuff happening right
now out there. But, staying on on
Snowflake and this relationship and this
partnership for the last question, talk
about what's ahead. I mean, I know this
is a relatively new acquisition. It's an
exciting one. Core capability brings a
lot of technical know-how and need I
think to the Snowflake model overall.
You guys are old friends though, right?
This is an This is an old partnership.
Talk about what the next kind of year
outlooks like cuz I don't think we can
think past that.
>> You want to go first?
>> Sure. Yeah, from a cybersecurity
standpoint we're investing we're
doubling down on the Snowflake
component. So
we're looking at different solutions
that they're going to start beta testing
us with. I can't speak too much into
that but the the goal is to really dive
in with the concept of data analytics at
the end of the day, right? So
a Simmons our product is essentially a
data mine for a cybersecurity team,
right? We can essentially do the same
thing with the Snowflake data lake as
well. So that's the gist of it. We're
we're going to we're going to go down
that road and explore those paths.
>> I'll keep it simple too for Snowflake.
Number one is efficient intelligence for
our customers.
Number two is
owning the enterprise context. We have
the data
either data parked at Snowflake or in
motion with with the Cortex AI gateway.
How do we make it much more valuable to
our customers? And as we are entering
this Agility era
we are beginning to hear a lot of DIY
where customers want to own and build
bespoke software for what they need to
do versus buying something off the
shelf. And enable partners like Jacob to
build that efficiently and at scale.
>> That's an interesting point to end on
because you need to meet partners where
they're at right across all industries
especially when it's critical as
children's health. So gents, thank you
so much for joining us at the NYSE
Wired.
>> Thank you so much Emma.
>> Appreciate the opportunity.
>> I'm
here at the Cube studio at the NYSE.
This is Cybersecurity Leaders. Thanks
for watching.