On 3 October 2024 I spent the day at Snowflake World Tour Amsterdam. The event page gave the venue as Taets Art & Event Park in Zaandam, with shuttle buses from Zaandam station, and the theme as âJoin us in the Era of Enterprise AIâ. I went for the AI and governance content. As a consultant, I keep being asked how a data platform fits with the EU AI Act, and this agenda had a whole session on it.

Before the keynote, at the Snowstore with a copy of Frank Slootmanâs âAmp It Upâ.
The agenda boards in the expo area listed hands-on Snow Labs, such as âBuild and Manage Snowflake Cortex LLM Functions in Coalesceâ and an Eredivisie 2024/2025 football forecasting lab. They also showed a Data Foundation track with sessions like âAll Aboard the NS Data Expressâ and âSecurity and Compliance Risk Management with Snowflakeâs Trust Centerâ.
The keynote: the AI Data Cloud
Martin Frederik, Snowflakeâs Country Manager Benelux, opened the keynote. The side screens then introduced Benoit Dageville, co-founder and President of Products. The main slide summed up Snowflakeâs pitch: the AI Data Cloud as an âAI-powered data platformâ plus a âdata-powered AI platformâ.

The main hall as the keynote got going.
The slides I photographed covered:
- Efficiency: âEfficient. Better TCOâ, with a single platform for all workloads and built-in cost controls.
- Snowflake Marketplace: âover 2,400 listingsâ of data products.
- Dynamic Tables: a quote from Boston Childrenâs Hospital said they simplified its ETL tooling, and loads that took 4 hours in the early morning now ran in 45 minutes.
- Customer stories: a Swire Coca-Cola slide said it uses Snowpark to identify millions in savings and speed up route optimisation, and Sigma appeared as a partner.
The live demo was about cost. A notebook titled âBatch Text Processing using LLMs and Fine-tuningâ sorted support tickets with the Cortex COMPLETE function on a large Llama model. The presenter then switched to Mistral 7B, which on its own did worse. Next he fine-tuned the small model on the large modelâs answers until its output matched. The demo ended with a text-to-SQL analyst over the same tickets and a RAG chatbot over billing documents for call-centre agents. His point was that the data never left the account.
Cortex Analyst and Cortex Search: âTalk to your dataâ
The first Business Track breakout was âTalk to your data: fast, accurate answers to business questionsâ. The opening slide credited Grace Adamson (Senior Product Marketing Manager AI/ML, Snowflake EMEA) and Tom Christian (Platform Principal AI & ML, Snowflake EMEA).
Cortex Analyst was presented as self-service, conversational analytics over structured data: business users ask questions and get SQL-backed answers. Snowflakeâs slide claimed it was about 2x more accurate than single-shot SQL generation from state-of-the-art LLMs, and 11% more accurate than other text-to-SQL solutions. Those are Snowflakeâs own numbers. A demo app answered movie questions such as âWhat was the highest-grossing seriesâŠâ. A Bayer case slide said the company uses Streamlit in Snowflake and Cortex Analyst for self-serve analytics, to reduce reliance on data teams.
For unstructured text, the talk moved to Cortex Search: âfully managed indexing and retrievalâ for chatbots that use RAG. The examples were customer service bots on FAQs, research lookup for wealth managers, risk reports and questions over SEC filings.

The Cortex Search use cases slide in the Business Track.
European regulation: the Data Act and the AI Act
The session I most wanted to see was âEuropean Regulation: Opportunities and Challengesâ, presented by Grace Adamson. The agenda had four questions: what the EU Data Act is, what the EU AI Act is, and what customers should consider for each.
The EU Data Act was framed as a âmandate to share dataâ. It sets who can create value from data, and on what terms, for users, holders and recipients of connected products and data processing services. The principles were fair, reasonable and non-discriminatory sharing, openness balanced with non-competition, and reasonable compensation for sharing with third parties. A âdata sharing and portability are keyâ slide used an automotive example and listed manufacturing (enabling data collection in IoT), energy (usage data for optimisation and pricing) and financial services (more customised insurance offerings). Snowflakeâs angle was âturn compliance into a competitive edgeâ: sharing and Marketplace listings can make compliance work into data products.
The EU AI Act half was the more useful one for me. One slide set out the roles in the AI value chain: providers, deployers, importers and distributors. Organisations can sit in several roles at once, and each role carries obligations that range from monitoring and documentation to governance and reporting.


Left: the four risk tiers. Right: the AI Act timeline as presented in October 2024.
The risk slide had four tiers:
- Unacceptable risk: prohibited (manipulation, social scoring).
- High risk: permitted with strict rules (biometrics, critical infrastructure, employment, essential services, education, law enforcement, migration, justice and democratic processes).
- Limited risk: permitted with some rules (some image or text generation).
- Minimal risk: permitted without restriction (likely spam filters, video games).
The timeline slide was titled âThe two year journey has just startedâ. It ran from publication in the Official Journal in July 2024, through the Article 5 prohibitions in February 2025 and the GPAI rules in August 2025, to general application in August 2026, Article 6(1) high-risk rules in August 2027, and full force by December 2030. The speakerâs main points were that AI compliance is now a board-level topic, that âAI is not just a point in timeâ, and that the gap analysis has to cover the whole organisation, from the board down to day-to-day processes.
The last part mapped the obligations onto the platform. AI quality management and compliance went with data and model governance. Human oversight and responsible AI went with impact assessments. Monitoring went with post-deployment monitoring plans. On the Snowflake side, the slides showed Snowflake Horizon (governance, data quality and lineage), ML explainability and observability in Snowsight, and âa single source of truth for data and modelsâ.
What has changed since. Some of those dates have moved. The Data Act has applied since 12 September 2025. For the AI Act, the Council gave its final approval on 29 June 2026 to an amendment that moves the high-risk rules to 2 December 2027 for stand-alone systems and 2 August 2028 for systems embedded in products. The February 2025 prohibitions and the August 2025 GPAI obligations kept their dates. I covered the details in EU AI Act high-risk deadlines postponed.
Snowflake Native Apps: the security model
After lunch I went to Fredrik Göransson (Field CTO, Snowflake) on the Snowflake Native App Framework. He compared it with traditional software, where the consumer installs and patches it, and with SaaS, which the provider hosts outside the customerâs infrastructure. A Native App is installed and runs inside the consumerâs Snowflake account, and is distributed through the Marketplace.

âApplication runs as itself. Not as the role of the user who installed it.â
The security points, from the slides:
- The app runs as itself, not as the installing userâs role. It only has access to what it creates during installation. Anything else it has to request, and an administrator manages that access.
- Components:
manifest.yml(properties and permissions),setup.sql(creates or upgrades objects in the consumer account), code for procedures, functions and Streamlit, and containers on Snowpark Container Services (marked ânewâ). - Code is scanned before publishing to the Marketplace. Consumers can run the code without seeing it, and providers push upgrades.
- References let the app ask the consumer to bind specific objects. They are resolved as the role of the user who binds them.
- Telemetry levels are set by the provider in
manifest.yml(log_level,telemetry_event_definitions), but the consumer has to consent to sharing and sees switches for each level. The speaker noted that logs can expose the names of internal procedures, so providers should choose the level carefully.
From 5K lines of Python to 10 lines of SQL
The last breakout I photographed was the most concrete. The speaker described classifying customer product suggestions for a supermarket. According to the slides, they received about 50K suggestions a month in 2023, 70% of them from âour most loyal or new customersâ. An example suggestion, âLipton ice tea green strawberryâ, was split into brand, product and variant, and then mapped to Dutch-language shop categories such as âKoffie & theeâ.
The first version called gpt-4o-mini through the OpenAI Python client. With more than 3M suggestions, they used batches of 50K and waited up to 24 hours for each batch. Then came the slide âWhat if⊠you can just write SQL? From 5K lines Python code to 10 lines SQL.â

The replacement: one SNOWFLAKE.CORTEX.COMPLETE call over the suggestions table, with llama3.1-70b âor any other modelâ.
The SQL version was a single CTE that called SNOWFLAKE.CORTEX.COMPLETE('llama3.1-70b', âŠ) with the system prompt and the suggestion as messages and a temperature of 0.3. It extracted the answer and the token usage as columns. The next slide, âEven easier!â, replaced the prompt with SNOWFLAKE.CORTEX.CLASSIFY_TEXT(s.suggestion, c.categories) joined to a categories table. The speaker also listed the caveats: about 30 ms per row, so 1M rows take about 8 hours, and model availability.
Today Snowflakeâs docs list COMPLETE and CLASSIFY_TEXT as legacy functions. New work should start from AI_COMPLETE and AI_CLASSIFY, and the COMPLETE page says it will be deprecated by the end of 2026. The Cortex Analyst docs now recommend moving to Cortex Agents. Cortex Search, the Native App Framework and Horizon Catalog are still current product names.
My take
From a data-platform and AI-governance angle, the useful part of the day was that the regulation session and the product sessions described the same thing from two sides. The AI Act asks who you are in the value chain, what risk tier each system is in, and how you show oversight and monitoring. In practice, most of that evidence is about data: lineage, access, quality and logs. Running LLM calls as SQL inside the governed platform, as in the supermarket case, leaves the prompts, model choice and token counts in tables you can audit. A Python job sending batches to an external API leaves a much thinner trail.
Two cautions, though. First, âinside the platformâ doesnât decide your role under the Act: if you build and deploy the classifier, you are still the deployer, and possibly the provider. Second, the 30 ms per row caveat matters. Row-by-row LLM calls are fine for millions of rows a month, but cost and latency have to be measured before you scale, as in the keynoteâs switch to a small fine-tuned model. For more on the governance side, see Building an AI Governance Framework That Actually Works and Edge AI and EU AI Act Compliance.

End of the day: the main hall was empty, and a group photo was being taken on stage.