Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

Amazon Bedrock AgentCore vs ServiceNow AI Control Tower

Amazon Bedrock AgentCore

AWS platform for building, deploying, and operating AI agents

ServiceNow AI Control Tower

What ServiceNow calls a central hub to discover, secure, govern, observe, and measure AI

Short answer

Amazon Bedrock AgentCore is AWS’s platform to build, deploy, and operate agents; ServiceNow describes AI Control Tower as a central hub to discover, secure, govern, observe, and measure AI, from ServiceNow or third parties.⁠Source 1, Source 2 AgentCore hosts agents, billed by use; AI Control Tower is included in ServiceNow’s Foundation, Advanced, and Prime tiers.⁠Source 1, Source 3, Source 4

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both keep a catalog of agents and MCP servers, can restrict an agent’s access, and keep audit records.⁠Source 2, Source 5, Source 6, Source 7, Source 8
Where they differ
Teams can also build and run agents on AgentCore.⁠Source 1, Source 9 ServiceNow says AI Control Tower auto-discovers AI assets, including models and datasets; connectors you set up reach outside platforms.⁠Source 2, Source 10, Source 11
Running both
ServiceNow documents AI Control Tower discovery of Amazon Bedrock AgentCore agents and lists AgentCore among its kill switch’s connectors.⁠Source 12, Source 13
Public sources · checked 2 October 2026
  • Offered
  • Not publicly documented

Amazon Bedrock AgentCore

  • Build agents: OfferedHarness managed agent loop⁠Source 1
  • Host and run agents: OfferedAgentCore Runtime⁠Source 1
  • Identity and access: OfferedAgentCore Identity workload identities⁠Source 14
  • Registry and governance: OfferedAWS Agent Registry with approvals⁠Source 5
  • Traffic between agents, tools, and models: OfferedAgentCore Gateway⁠Source 15
  • Agents across organizations: OfferedRegistry shared through AWS RAM⁠Source 16

ServiceNow AI Control Tower

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedScoped OAuth tokens (community docs)⁠Source 17
  • Registry and governance: OfferedAI inventory tied to CMDB⁠Source 2
  • Traffic between agents, tools, and models: OfferedAI Gateway (community docs)⁠Source 18
  • Agents across organizations: Not publicly documented

At a glance

TopicAmazon Bedrock AgentCoreServiceNow AI Control Tower
Builds and runs agentsWrite the agent loop with a framework and deploy it to a serverless Runtime, or define one with the managed Harness.⁠Source 1, Source 9ServiceNow’s separate AI Agent Studio creates, configures, and deploys agents.⁠Source 19
Agents built elsewhereAWS says Agent Registry works with agents on AWS, on premises, or in other clouds.⁠Source 1 Automatic discovery currently finds only AgentCore Runtimes and Gateways.⁠Source 7Connectors you set up discover AI assets on outside platforms, including Amazon Bedrock AgentCore.⁠Source 10, Source 11, Source 12
Stopping an agentExplicit deny policies can block access, and removing an account from a registry share revokes its access.⁠Source 16, Source 20 A single control to disable an agent everywhere is not publicly documented.A kill switch can contain a managed agent and revoke all of its active credentials across connected systems.⁠Source 8, Source 13 It needs a connection to each hyperscaler hosting governed agents.⁠Source 13
PricingBy use, per service, with no upfront commitment or minimum fee.⁠Source 3 AWS Agent Registry has a monthly free tier.⁠Source 3The product page says to contact ServiceNow for pricing.⁠Source 2 Included in its Foundation, Advanced, and Prime product tiers.⁠Source 4
Generally availableAgentCore since October 2025; AWS Agent Registry since August 2026.⁠Source 21ServiceNow announced general availability on 6 May 2025.⁠Source 22 ServiceNow’s community documentation says AI Gateway became generally available on 10 September 2026.⁠Source 23, Source 24

What each one is

Amazon Bedrock AgentCore

Amazon Bedrock AgentCore is AWS’s platform for building, deploying, and operating agents with any framework and foundation model.⁠Source 1 Its modular services, usable together or independently, include a serverless Runtime, Gateway, Identity, Policy, Observability, and AWS Agent Registry.⁠Source 1, Source 5, Source 6, Source 14, Source 25, Source 26

ServiceNow AI Control Tower

ServiceNow describes AI Control Tower as a central hub to discover, secure, govern, observe, and measure AI across an enterprise.⁠Source 2 ServiceNow says it inventories AI agents, models, and MCP servers.⁠Source 2 ServiceNow’s community documentation says its AI Gateway feature proxies MCP traffic.⁠Source 18

The differences that matter

  1. Building and running agents

    Amazon Bedrock AgentCore

    Developers write the agent loop with a framework such as LangGraph or Strands and deploy it to Runtime, or use the managed Harness.⁠Source 1, Source 9

    ServiceNow AI Control Tower

    ServiceNow’s separate AI Agent Studio creates, configures, and deploys agents; creating new custom agents needs the Prime tier.⁠Source 4, Source 19

  2. Agents built elsewhere

    Amazon Bedrock AgentCore

    AWS says Agent Registry works with agents on AWS, on premises, or in other clouds; automatic discovery currently finds only AgentCore Runtimes and Gateways.⁠Source 1, Source 7

    ServiceNow AI Control Tower

    Connectors discover AI assets on outside platforms, including Amazon Bedrock AgentCore, using credentials you supply.⁠Source 10, Source 11, Source 12

    AgentCore needs extra setup to show metrics for agents outside its Runtime; ServiceNow’s community documentation says only assets marked Managed get governance workflows and monitoring.⁠Source 27, Source 28

  3. Where policy is enforced

    Amazon Bedrock AgentCore

    Policy can check each request through an AgentCore Gateway against your rules, written in natural language or Cedar, before allowing tool access.⁠Source 6

    ServiceNow AI Control Tower

    ServiceNow’s community documentation says AI Gateway lets agents connect only to approved, active MCP servers, with tool policies by role, department, or data classification.⁠Source 17, Source 23

    The scopes differ: AgentCore Policy applies to traffic through AgentCore Gateways, and ServiceNow’s community documentation calls AI Gateway its MCP enforcement layer.⁠Source 6, Source 17

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicAmazon Bedrock AgentCoreServiceNow AI Control Tower
Network exposureGateway can forward to an external agent’s endpoint URL.⁠Source 15 VPC callers can reach AgentCore over PrivateLink without an internet gateway.⁠Source 29ServiceNow’s community documentation says agents using AI Gateway call a ServiceNow-hosted URL.⁠Source 18 Ports and egress: not publicly documented.
IdentityAgent identities are workload identities; Runtime defaults to IAM SigV4, or takes JWTs from Cognito, Entra ID, Okta, and others.⁠Source 14, Source 30, Source 31, Source 32ServiceNow’s community documentation says AI Gateway verifies agent identity and issues short-lived OAuth 2.1 tokens on each connection through it.⁠Source 17
Access changes and revocationExplicit deny policies can block Runtime, Gateway, and Memory access.⁠Source 20 Removing an account from a registry share revokes its access.⁠Source 16A kill switch can contain a managed agent and revoke all of its active credentials across connected systems.⁠Source 8, Source 13
Audit trailCloudTrail can log Gateway calls (data events are off by default) and logs Registry control-plane calls; Policy logs its decisions.⁠Source 6, Source 7, Source 33, Source 34Each kill-switch containment leaves an audit trail.⁠Source 8 ServiceNow’s community documentation says AI Gateway logs every MCP transaction through it.⁠Source 23
ComplianceHIPAA eligible; AWS lists it as FedRAMP (Class C and Class D), SOC 2, ISO 27001:2022, and CSA STAR compliant.⁠Source 35, Source 36ServiceNow says the company has a SOC 2 Type 2 attestation and ISO/IEC 42001 certification.⁠Source 37 Product scope: not publicly documented.

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

Amazon Bedrock AgentCore and ServiceNow AI Control Tower compared on 18 criteria
Amazon Bedrock AgentCoreServiceNow AI Control Tower
What it is
What it is and who it’s forAWS’s platform for building, deploying, and operating agents with any framework and model, for moving agents from proof of concept to production.⁠Source 1, Source 32ServiceNow describes it as a central hub to discover, secure, govern, observe, and measure AI across an enterprise, running on the ServiceNow AI Platform.⁠Source 2
MaturityGenerally available since October 2025.⁠Source 21 Policy generally available since March 2026; AWS Agent Registry since August 2026.⁠Source 21ServiceNow announced general availability on 6 May 2025.⁠Source 22 ServiceNow’s community documentation says AI Gateway became generally available on 10 September 2026.⁠Source 23, Source 24
Control
Agent registry and discoveryAWS Agent Registry catalogs agents, MCP servers, tools, and skills behind an approval workflow, including ones on premises or in other clouds.⁠Source 1, Source 5ServiceNow says it auto-discovers agents, models, MCP servers, and datasets into one inventory tied to the CMDB.⁠Source 2 Connectors you set up reach external platforms.⁠Source 10, Source 11
Identity and access controlWorkload identities in AgentCore Identity.⁠Source 14 Calls to Runtime agents use IAM SigV4 by default, or JWTs from any OAuth 2.0 identity provider.⁠Source 30, Source 31ServiceNow’s community documentation says AI Gateway verifies agent identity and issues scoped, short-lived OAuth 2.1 tokens for MCP connections through it.⁠Source 17
Ownership, policy, and revocationGateway policies in natural language or Cedar set which tools an agent may call and when.⁠Source 6 One control to disable an agent everywhere: not publicly documented.A kill switch can contain a managed agent and revoke all of its active credentials across connected systems.⁠Source 8, Source 13 It covers ServiceNow and four other platforms.⁠Source 38
Audit log and observabilityCloudTrail can log Gateway calls (data events are off by default) and logs Registry control-plane calls.⁠Source 7, Source 33, Source 34 Policy logs its decisions.⁠Source 6Each kill-switch containment leaves an audit trail.⁠Source 8 ServiceNow’s community documentation says AI Gateway logs each MCP transaction through it.⁠Source 23
Connection
How agents connectAgents can run in a serverless Runtime, or elsewhere behind a Gateway that forwards to their endpoint URL.⁠Source 1, Source 15 Outbound-only connections: not publicly documented.ServiceNow’s community documentation says agents using AI Gateway call a ServiceNow-hosted URL instead of the MCP server, which must be remote.⁠Source 18, Source 23
Agents across organizationsA registry can be shared with other AWS accounts through AWS RAM.⁠Source 16 Runtime agents can be opened to principals in other AWS accounts.⁠Source 20Third-party systems like Microsoft Agent 365 can discover publishable agents via an open API.⁠Source 39 Bringing in agents a partner controls: not publicly documented.
Protocol supportAgents in Runtime can serve HTTP, MCP, A2A, or AG-UI.⁠Source 40 Gateway acts as one MCP server over its MCP targets.⁠Source 41 Registry checks records against MCP and A2A schemas.⁠Source 7ServiceNow’s community documentation calls AI Gateway its MCP enforcement layer.⁠Source 17 A2A is documented for ServiceNow’s separate AI Agent Studio.⁠Source 42
Frameworks, models, and clouds supportedRuntime works with CrewAI, LangGraph, LlamaIndex, Google ADK, OpenAI Agents SDK, Strands Agents, and custom frameworks.⁠Source 1 Identity covers self-hosted agents.⁠Source 43ServiceNow says it inventories agents, models, and MCP servers from ServiceNow or third parties.⁠Source 2 Connectors reach external platforms.⁠Source 10
Operations
Deployment options and data residencyAWS says cross-region inference can move Memory, Policy, and Evaluations prompts out of the primary Region; AgentCore may store content to improve your service.⁠Source 1, Source 44Data may go to a central ServiceNow environment in another region, or a third-party cloud.⁠Source 45 ServiceNow says controls can switch this off.⁠Source 45
Compliance attestationsAWS lists AgentCore as FedRAMP (Class C and Class D) compliant.⁠Source 35, Source 36 It is HIPAA eligible, and SOC 2, ISO 27001:2022, and CSA STAR compliant.⁠Source 21, Source 35ServiceNow says the company holds a SOC 2 Type 2 attestation and ISO/IEC 42001.⁠Source 37 Content packs: EU AI Act, NIST AI RMF, California SB 53, Colorado AI Act.⁠Source 46
Support and SLAAWS says the Amazon Bedrock SLA applies to AgentCore.⁠Source 32 Basic Support is included for all AWS customers.⁠Source 47ServiceNow’s Customer Support Addendum states a 99.8% availability SLA for production instances.⁠Source 48 ServiceNow’s community documentation points to Now Support.⁠Source 49
Time and effort to get runningAWS’s quickstart scaffolds, tests, and deploys one agent with the AgentCore CLI.⁠Source 9 It needs an AWS account and Node.js 20 or later.⁠Source 9A Guided Setup widget walks through initial configuration.⁠Source 50 Discovering an outside platform’s agents needs a connector and credentials you supply.⁠Source 11
Pricing model and public pricesConsumption-based per service, no minimum fee.⁠Source 3 Examples: Policy $0.000025 per authorization request; Runtime v1 CPU $0.0895 per vCPU-hour.⁠Source 3ServiceNow’s tiers page says fully managing external AI assets needs a separate license.⁠Source 4 ServiceNow’s community documentation says usage-based costs may apply.⁠Source 23, Source 51
Building
Agent building toolsWrite the agent loop in Python with a framework such as Strands, LangGraph, or Google ADK and deploy it to Runtime, or use the managed Harness.⁠Source 1, Source 9ServiceNow’s separate AI Agent Studio creates, configures, and deploys agents.⁠Source 19 Creating new custom agents is supported only in the Prime tier.⁠Source 4
Model accessModel-agnostic, AWS says: models in or outside Amazon Bedrock, including OpenAI, Gemini, Claude, Nova, Llama, and Mistral.⁠Source 32Model provider settings cover ServiceNow-supported providers, such as Now LLM Service and AWS Claude, and ones your organization configures.⁠Source 52
Integrations and ecosystemGateway has 1-click integrations such as Salesforce, Slack, Jira, Asana, and Zendesk, and can import AWS Partner tools bought in AWS Marketplace.⁠Source 25, Source 32ServiceNow’s community documentation names discovery connectors for Databricks, Snowflake, and Hugging Face, and says connectors can also be custom-built.⁠Source 28, Source 49

Which to choose

Choose Amazon Bedrock AgentCore if

  • You want to build, deploy, and operate agents on one AWS platform, using its modular services together or one at a time.⁠Source 1
  • Your developers use LangGraph, CrewAI, Strands Agents, or the OpenAI Agents SDK and want a serverless runtime to host those agents.⁠Source 1
  • You want gateway-checked policies, written in natural language or Cedar, that set which tools each agent may call and when.⁠Source 6
  • You want usage-based pricing with no upfront commitment, and a registry you can share with other AWS accounts through AWS RAM.⁠Source 3, Source 16

Choose ServiceNow AI Control Tower if

  • You run ServiceNow on any tier: each includes AI Control Tower, which ServiceNow says ties AI assets to your CMDB.⁠Source 2, Source 4
  • You want what ServiceNow calls one inventory of agents, models, and MCP servers, including assets discovered on external platforms.⁠Source 2, Source 10
  • You want a kill switch that contains a managed agent and revokes all of its active credentials across connected systems.⁠Source 8, Source 13
  • You want compliance content: ServiceNow’s pack covers the EU AI Act, NIST AI RMF, California SB 53, and Colorado’s AI Act.⁠Source 46

Questions buyers ask

How is each one priced?

AgentCore is billed by use; AWS Agent Registry has a monthly free tier.⁠Source 3 AI Control Tower is included in ServiceNow’s Foundation, Advanced, and Prime tiers, and its product page says to contact ServiceNow for pricing.⁠Source 2, Source 4 ServiceNow’s community documentation says usage-based costs may apply.⁠Source 23, Source 51

Do they support MCP and A2A?

AgentCore Runtime hosts agents that can serve MCP or A2A, and Agent Registry validates records against both protocols’ schemas.⁠Source 7, Source 40 ServiceNow’s community documentation calls AI Gateway AI Control Tower’s MCP enforcement layer; A2A is documented for ServiceNow’s separate AI Agent Studio.⁠Source 17, Source 42

Can either one share agents with another organization?

An AWS Agent Registry can be shared through AWS RAM with other AWS accounts, including ones outside your AWS Organization.⁠Source 16 AI Control Tower’s open API lets third-party systems like Microsoft Agent 365 discover publishable agents; bringing in agents another organization controls is not publicly documented.⁠Source 39

Can either one be self-hosted?

A self-hosted edition of AgentCore is not publicly documented; AWS offers it in AWS Regions, including AWS GovCloud (US-West).⁠Source 21, Source 32 ServiceNow says AI Control Tower runs on the ServiceNow AI Platform; whether self-hosted ServiceNow customers can use it is not publicly documented.⁠Source 2

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

59 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Overview - Amazon Bedrock AgentCore (Developer Guide) AWS · checked Back:abcdefghijklmnopqrs

  2. Source 2: AI Control Tower - ServiceNow (product page) ServiceNow · checked Back:abcdefghijklmn

  3. Source 3: Amazon Bedrock AgentCore Pricing AWS · checked Back:abcdefg

  4. Source 4: ServiceNow product tiers (ServiceNow product documentation, Australia release) ServiceNow · checked Back:abcdefg

  5. Source 5: AWS Agent Registry: Discover and manage agents, tools, and resources AWS · checked Back:abcd

  6. Source 6: Policy in Amazon Bedrock AgentCore: Control Agent Interactions AWS · checked Back:abcdefgh

  7. Source 7: Key capabilities - AWS Agent Registry AWS · checked Back:abcdefg

  8. Source 8: AI agent containment using kill switch protocol manually (ServiceNow product documentation, Australia release) ServiceNow · checked Back:abcdefg

  9. Source 9: Get started with Amazon Bedrock AgentCore AWS · checked Back:abcdef

  10. Source 10: Discovering AI assets through connectors (ServiceNow product documentation, Australia release) ServiceNow · checked Back:abcdef

  11. Source 11: Configuring connectors (ServiceNow product documentation, Australia release) ServiceNow · checked Back:abcde

  12. Source 12: AI Service Graph Connector for Amazon release notes (ServiceNow Store version history) ServiceNow · checked Back:abcd

  13. Source 13: Configure AI agent containment using kill switch protocol manually (ServiceNow product documentation, Australia release) ServiceNow · checked Back:abcdef

  14. Source 14: Provide identity and credential management for agent applications with Amazon Bedrock AgentCore Identity AWS · checked Back:abcd

  15. Source 15: HTTP passthrough targets - AgentCore Gateway AWS · checked Back:abc

  16. Source 16: Sharing a registry across accounts with AWS RAM AWS · checked Back:abcdef

  17. Source 17: What's new in AI Gateway v3.4 - September 2026 release (ServiceNow Community, AI Control Tower articles) ServiceNow · checked Back:abcdefg

  18. Source 18: AI Gateway Implementation Guide (ServiceNow Community, AI Control Tower articles) ServiceNow · checked Back:abcd

  19. Source 19: AI Agent Studio (ServiceNow product documentation, Australia release) ServiceNow · checked Back:abc

  20. Source 20: Resource-based policies for Amazon Bedrock AgentCore AWS · checked Back:abc

  21. Source 21: Release notes - Amazon Bedrock AgentCore AWS · checked Back:abcde

  22. Source 22: ServiceNow Launches AI Control Tower, a Centralized Command Center to Govern, Manage, Secure, and Realize Value From Any AI Agent, Model, and Workflow (ServiceNow news release, investor relations PDF) ServiceNow · checked Back:ab

  23. Source 23: AI Gateway FAQ (ServiceNow Community, AI Control Tower articles) ServiceNow · checked Back:abcdefgh

  24. Source 24: What's new in AI Control Tower for August & September 2026 (ServiceNow Community, AI Control Tower articles) ServiceNow · checked Back:ab

  25. Source 25: Amazon Bedrock AgentCore Gateway: A secure AI gateway for agents, tools, and models AWS · checked Back:ab

  26. Source 26: Observe your agent applications on Amazon Bedrock AgentCore Observability AWS · checked Back to text

  27. Source 27: Add observability to your Amazon Bedrock AgentCore resources AWS · checked Back to text

  28. Source 28: AI Control Tower: What's new in the June 2026 release (ServiceNow Community, AI Control Tower articles) ServiceNow · checked Back:ab

  29. Source 29: Use interface VPC endpoints (AWS PrivateLink) with Amazon Bedrock AgentCore AWS · checked Back to text

  30. Source 30: Authenticate and authorize with Inbound Auth and Outbound Auth AWS · checked Back:ab

  31. Source 31: Configure inbound JWT authorizer AWS · checked Back:ab

  32. Source 32: Amazon Bedrock AgentCore FAQs AWS · checked Back:abcdef

  33. Source 33: Log Amazon Bedrock AgentCore Gateway API calls with CloudTrail AWS · checked Back:ab

  34. Source 34: Enable CloudTrail data event logging for Amazon Bedrock AgentCore Gateway resources - Amazon Bedrock AgentCore AWS · checked Back:ab

  35. Source 35: Compliance validation for Amazon Bedrock AgentCore AWS · checked Back:abc

  36. Source 36: Federal Risk and Authorization Management Program (FedRAMP) - Services in Scope - Amazon Web Services AWS · checked Back:ab

  37. Source 37: Compliance - ServiceNow Trust ServiceNow · checked Back:ab

  38. Source 38: Control enforcement points (ServiceNow product documentation, Australia release) ServiceNow · checked Back:ab

  39. Source 39: External Registries (ServiceNow product documentation, Australia release) ServiceNow · checked Back:ab

  40. Source 40: Understand the AgentCore Runtime service contract AWS · checked Back:ab

  41. Source 41: Supported targets for Amazon Bedrock AgentCore gateways AWS · checked Back to text

  42. Source 42: Integrating external AI agents (ServiceNow product documentation, Australia release) ServiceNow · checked Back:ab

  43. Source 43: Features of AgentCore Identity AWS · checked Back to text

  44. Source 44: Cross-region inference in AgentCore Memory, Policy in AgentCore, and AgentCore Evaluations AWS · checked Back to text

  45. Source 45: AI Control Tower (ServiceNow product documentation, Australia release) ServiceNow · checked Back:ab

  46. Source 46: AI Risk and Compliance Content Pack (ServiceNow product documentation, Australia release, Governance, Risk, and Compliance) ServiceNow · checked Back:ab

  47. Source 47: Compare AWS Support plans AWS · checked Back to text

  48. Source 48: Customer Support Addendum (ServiceNow legal schedules, Version 12MAR2025) ServiceNow · checked Back to text

  49. Source 49: AI Control Tower Welcome Guide (ServiceNow Community, AI Control Tower articles) ServiceNow · checked Back:ab

  50. Source 50: AI Control Tower release notes (ServiceNow product documentation, Australia release) ServiceNow · checked Back to text

  51. Source 51: AI Control Tower Observability & Monitoring FAQ (ServiceNow Community, AI Control Tower articles) ServiceNow · checked Back:ab

  52. Source 52: AI model providers (ServiceNow product documentation, Australia release) ServiceNow · checked Back to text

  53. Source 53: Why Blocks? Blocks.ai · checked Back to text

  54. Source 54: What is Blocks? Blocks.ai · checked Back to text

  55. Source 55: Your company's private network Blocks.ai · checked Back to text

  56. Source 56: Network requirements Blocks.ai · checked Back to text

  57. Source 57: Solutions: Agent sprawl Blocks.ai · checked Back to text

  58. Source 58: Solutions: Partner networks Blocks.ai · checked Back to text

  59. Source 59: Pricing Blocks.ai · checked Back to text