Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.
DIY vs ServiceNow AI Control Tower: an in-house build or what ServiceNow calls a central hub for AI
Build it yourself (DIY)
Building agent connections and controls in-house from open protocols, existing infrastructure, and open-source tools
ServiceNow AI Control Tower
What ServiceNow calls a central hub to discover, secure, govern, observe, and measure AI
Short answer
DIY is not a product: you connect and govern agents on openly licensed protocols such as MCP and A2A, which leave authorization logic to you.Source 1, Source 2, Source 3 ServiceNow describes AI Control Tower as a central hub to discover, secure, govern, observe, and measure AI across an enterprise; a kill switch can contain a managed agent.Source 4, Source 5
Where each one sits
Six layers of running AI agents at a company, and what each product’s own public sources say it covers.
These aren’t the same kind of product
- Where they overlap
- Both can list MCP servers and control access to them: Uber built an MCP registry and proxy gateway; ServiceNow’s community documentation describes AI Control Tower’s AI Gateway.Source 6, Source 7, Source 8, Source 9
- Where they differ
- ServiceNow’s agents are built in ServiceNow’s separate AI Agent Studio.Source 10 A DIY build can also include agent frameworks like LangGraph and service meshes like Istio.Source 11, Source 12
- Running both
- ServiceNow’s community documentation says agents on a custom-built platform can connect to MCP servers through AI Gateway, with its Gateway URL and OAuth 2.1.Source 7
DIY
ServiceNow AI Control Tower
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Agents across organizations: Not publicly documented
At a glance
What each one is
Build it yourself (DIY)
DIY means connecting and governing agents without buying a product for it: open protocols such as MCP and A2A wired together, existing infrastructure stretched, an in-house platform, self-hosted open source, or no central approach; Uber and Pinterest each describe building their own MCP registry.Source 6, Source 17
ServiceNow AI Control Tower
ServiceNow describes AI Control Tower as a central hub to discover, secure, govern, observe, and measure AI across an enterprise.Source 4 ServiceNow’s community documentation says AI Stewards approve AI systems and AI Gateway proxies MCP traffic and issues OAuth 2.1 tokens.Source 8, Source 9, Source 19
The differences that matter
Agent inventory
DIYYou run your own: A2A prescribes no standard API for curated registries, and Uber and Pinterest each built their own MCP registry.Source 6, Source 15, Source 17
ServiceNow AI Control TowerConnectors you set up discover AI assets on external platforms and sync them into the inventory.Source 20, Source 21
The official MCP Registry is in preview and does not support private servers; its docs recommend hosting your own private registry for those.Source 25
Access and revocation
DIYA2A leaves authorization logic to each server and MCP makes it optional; Uber’s gateway applies policies from its internal Access Control System.Source 1, Source 6, Source 26
ServiceNow AI Control TowerA kill switch can contain a managed agent and revoke all of its active credentials across connected systems.Source 5, Source 22
The kill switch covers agents on ServiceNow and four connected platforms.Source 22, Source 27 ServiceNow’s community documentation says AI Gateway issues scoped OAuth 2.1 tokens for MCP.Source 9
Where it runs
DIYWhere you put it: Pinterest optimized for MCP servers in its internal cloud, and Uber’s gateway sends requests through its service mesh sidecar.Source 6, Source 17
ServiceNow AI Control TowerServiceNow says it runs on its AI Platform; data goes to a central ServiceNow environment, maybe in another region or on Azure.Source 4, Source 28
Separately, a regional data routing option sends LLM and SLM requests to data centers in your region.Source 29 Network requirements, such as ports and egress, are not publicly documented.
For security teams
What a security review asks, answered from each vendor’s public documentation.
Full comparison
18 criteria in five groups. Every cell links to its source, or says no public source answers it.
| DIY | ServiceNow AI Control Tower | |
|---|---|---|
| What it is | ||
| What it is and who it’s for | Built in-house from parts such as A2A, an open standard for communication between agent systems, and MCP, which A2A’s specification calls complementary.Source 1 | ServiceNow describes AI Control Tower as a central hub to discover, secure, govern, observe, and measure AI across an enterprise.Source 4 |
| Maturity | Varies by part: MCP’s latest revision is 2026-07-28, and the official MCP Registry is in preview.Source 25, Source 31 | ServiceNow announced general availability on 6 May 2025.Source 33 ServiceNow’s community documentation says AI Gateway became generally available on 10 September 2026.Source 34 |
| Control | ||
| Agent registry and discovery | Yours to run: A2A prescribes no standard API for curated registries; the official MCP Registry is in preview and does not support private servers.Source 15, Source 25 | ServiceNow says it auto-discovers agents, models, MCP servers, and datasets into one inventory tied to the CMDB.Source 4 Connectors you set up reach external platforms.Source 20, Source 21 |
| Identity and access control | In A2A, identity is set at the HTTP layer and each server authorizes requests under its own policies.Source 1, Source 16 MCP authorization is optional.Source 26 | ServiceNow’s community documentation says AI Gateway verifies agent identity and issues scoped, short-lived OAuth 2.1 tokens for MCP connections through it.Source 9 |
| Ownership, policy, and revocation | MCP leaves consent and authorization flows to implementers.Source 3 Pinterest requires an owning team, a registry entry, and review for non-experimental MCP servers.Source 17 | A kill switch can contain a managed agent and revoke all of its active credentials across connected systems.Source 5 It covers ServiceNow and four connected platforms.Source 22, Source 27 |
| Audit log and observability | A2A’s docs advise auditing significant events and distributed tracing, for example with OpenTelemetry.Source 16 Pinterest’s MCP servers log inputs and outputs.Source 17 | Each kill-switch containment leaves an audit trail.Source 5 ServiceNow’s community documentation says AI Gateway logs each MCP transaction through it.Source 7 |
| Connection | ||
| How agents connect | MCP servers on Streamable HTTP expose an HTTP endpoint; A2A HTTP interfaces need HTTPS in production.Source 1, Source 30 AWS PrivateLink privately connects a VPC to services.Source 35 | ServiceNow’s community documentation says agents using AI Gateway call a ServiceNow-hosted URL instead of the MCP server, which must be remote.Source 7, Source 8 |
| Agents across organizations | A2A is designed for agents built by different companies on separate servers.Source 18 Each server authorizes requests under its own policies.Source 1 | Systems like Microsoft Agent 365 can discover publishable agents via an open API.Source 36 Bringing in agents another organization controls: not publicly documented. |
| Protocol support | MCP defines stdio and Streamable HTTP transports; A2A maps to JSON-RPC, gRPC, and HTTP/REST.Source 1, Source 37 MCP’s latest revision is 2026-07-28.Source 3 | ServiceNow’s community documentation calls AI Gateway its MCP enforcement layer.Source 9 ServiceNow’s separate AI Agent Studio can connect external agents over A2A.Source 38 |
| Frameworks, models, and clouds supported | A2A gives a common language to agents built with different frameworks, languages, or vendors.Source 1 Google’s ADK says it is model- and deployment-agnostic.Source 13 | ServiceNow says it inventories agents, models, and MCP servers from ServiceNow or third parties.Source 4 Connectors reach external platforms.Source 20 |
| Operations | ||
| Deployment options and data residency | Where you choose: Pinterest optimized for MCP servers in its internal cloud, and A2A’s docs leave protecting stored data to your own policies.Source 16, Source 17 | ServiceNow says it runs on its AI Platform and sends data to a central environment, maybe in another region or on Azure, with controls to turn this off.Source 4, Source 28 |
| Compliance attestations | With the implementer: A2A’s docs name GDPR, CCPA, and HIPAA; MCP leaves access controls and data protections to implementers.Source 3, Source 16 | ServiceNow says the company has undertaken an annual SOC 2 Type 2 attestation since 2013.Source 32 It says the company holds ISO/IEC 42001 certification.Source 32 |
| Support and SLA | Depends on the component: MCP SDKs are tiered partly by maintenance commitments; the official MCP Registry, in preview, gives no uptime guarantees.Source 39, Source 40 | ServiceNow’s Customer Support Addendum states a 99.8% availability SLA for production instances.Source 41 Its community documentation points to Now Support.Source 19 |
| Time and effort to get running | A curated A2A registry is a service you deploy and maintain.Source 15 Pinterest built a unified deployment pipeline after new MCP servers took too much setup.Source 17 | Which features you can use depends on your license.Source 42 ServiceNow’s community documentation says many customers implement it with a ServiceNow partner.Source 19 |
| Pricing model and public prices | The A2A and MCP specifications are openly licensed, A2A under Apache 2.0.Source 1, Source 2 Build and running costs are not publicly documented. | ServiceNow says to contact it for pricing.Source 4 It is in all three product tiers.Source 23 ServiceNow’s community documentation says usage-based costs may apply.Source 7, Source 24 |
| Building | ||
| Agent building tools | Open-source frameworks such as LangGraph and Google’s ADK build and deploy agents.Source 11, Source 13 A2A has SDKs in six languages.Source 43 | ServiceNow agents are built in ServiceNow’s separate AI Agent Studio.Source 10 Creating net-new custom agents is supported only in the Prime tier.Source 23 |
| Model access | Chosen by whoever builds the agents: Google’s ADK says it is optimized for Gemini and model-agnostic.Source 13 | Model provider settings cover ServiceNow-supported providers, such as Now LLM Service and AWS Claude, and ones your organization configures.Source 29 |
| Integrations and ecosystem | The official MCP Registry, in preview, has a REST API for discovering servers.Source 25 Uber says its own gateway hosts over 800 MCP servers.Source 6 | ServiceNow’s community documentation names discovery connectors for Databricks, Snowflake, and Hugging Face, and says connectors can also be custom-built.Source 19, Source 44 |
Which to choose
Choose DIY if
- You want MCP servers in your own cloud, under your own routing and security logic, as Pinterest chose.Source 17
- You want agents at different companies to authorize each other’s calls themselves: under A2A, each server applies its own policies.Source 1, Source 18
- You already run a service mesh or access-control system and want it to check MCP calls, as Uber and Pinterest do.Source 6, Source 17
- You want no agent platform contract: the A2A and MCP specifications are openly licensed, A2A under Apache 2.0.Source 1, Source 2
Choose ServiceNow AI Control Tower if
- You run ServiceNow on a Foundation, Advanced, or Prime tier, each of which includes AI Control Tower.Source 23
- You want connectors you set up to discover AI on external platforms and sync it into one inventory.Source 20, Source 21
- You want a kill switch that can contain a managed agent and revoke all of its active credentials, with each containment audited.Source 5
- You want MCP traffic governed in one place, as ServiceNow’s community documentation describes AI Gateway: approved servers only, scoped tokens, and logs.Source 7, Source 9
Questions buyers ask
Is ServiceNow AI Control Tower an alternative to building it yourself?
Can ServiceNow AI Control Tower govern agents built outside ServiceNow?
Yes, with limits: ServiceNow’s community documentation says AI Gateway governs MCP connections from any agent platform, and discovery covers AWS Bedrock, Azure AI Foundry, GCP Vertex AI, and more.Source 7, Source 19 ServiceNow’s docs say its connector for Amazon also discovers Amazon Bedrock AgentCore agents.Source 46
Does ServiceNow AI Control Tower support MCP and A2A?
How do the costs compare?
ServiceNow says to contact it for AI Control Tower pricing.Source 4 It is included in the Foundation, Advanced, and Prime tiers.Source 23 ServiceNow’s community documentation says usage-based costs may apply.Source 7, Source 24 DIY’s A2A and MCP specifications are openly licensed; build and running costs are not publicly documented.Source 1, Source 2
How we compare
Read the full methodEvery claim on this page links to a public source. Where none answers a question, the page says so.
We re-check every fact at least every 90 days. This page was last checked .
Something wrong or out of date? Tell us and we’ll correct it.
Sources
51 public sources, each with the date we checked it. Every one opens in a new tab.
Source 1: Agent2Agent (A2A) Protocol Specification Back:abcdefghijklmnopqr
Source 2: modelcontextprotocol/modelcontextprotocol LICENSE (GitHub) Back:abcdef
Source 3: Specification - Model Context Protocol 2026-07-28 Back:abcde
Source 4: AI Control Tower - ServiceNow (product page) Back:abcdefghijklmno
Source 5: AI agent containment using kill switch protocol manually (ServiceNow product documentation, Australia release) Back:abcdefghi
Source 6: Designing MCP Gateway Uber's MCP Management Platform - Uber Blog Back:abcdefghi
Source 7: AI Gateway FAQ (ServiceNow Community, AI Control Tower articles) Back:abcdefghij
Source 8: AI Gateway Implementation Guide (ServiceNow Community, AI Control Tower articles) Back:abcde
Source 9: What's new in AI Gateway v3.4 - September 2026 release (ServiceNow Community, AI Control Tower articles) Back:abcdefghi
Source 10: AI Agent Studio (ServiceNow product documentation, Australia release) Back:abc
Source 14: Integrating with Model Context Protocol (MCP) - Keycloak Back to text
Source 17: Building an MCP Ecosystem at Pinterest - Pinterest Engineering Blog Back:abcdefghij
Source 19: AI Control Tower Welcome Guide (ServiceNow Community, AI Control Tower articles) Back:abcdefg
Source 20: Discovering AI assets through connectors (ServiceNow product documentation, Australia release) Back:abcde
Source 21: Configuring connectors (ServiceNow product documentation, Australia release) Back:abcd
Source 22: Configure AI agent containment using kill switch protocol manually (ServiceNow product documentation, Australia release) Back:abcde
Source 23: ServiceNow product tiers (ServiceNow product documentation, Australia release) Back:abcde
Source 24: AI Control Tower Observability & Monitoring FAQ (ServiceNow Community, AI Control Tower articles) Back:abc
Source 25: The MCP Registry - Model Context Protocol Back:abcd
Source 26: Authorization - Model Context Protocol specification 2026-07-28 Back:abc
Source 27: Control enforcement points (ServiceNow product documentation, Australia release) Back:ab
Source 28: AI Control Tower (ServiceNow product documentation, Australia release) Back:ab
Source 29: AI model providers (ServiceNow product documentation, Australia release) Back:ab
Source 30: Streamable HTTP - Model Context Protocol specification 2026-07-28 Back:ab
Source 31: Key Changes - Model Context Protocol specification 2026-07-28 Back:ab
Source 33: ServiceNow Launches AI Control Tower, a Centralized Command Center to Govern, Manage, Secure, and Realize Value From Any AI Agent, Model, and Workflow (ServiceNow news release, investor relations PDF) Back to text
Source 34: What's new in AI Control Tower for August & September 2026 (ServiceNow Community, AI Control Tower articles) Back to text
Source 35: What is AWS PrivateLink? - Amazon Virtual Private Cloud Back to text
Source 36: External Registries (ServiceNow product documentation, Australia release) Back:ab
Source 37: Transports - Model Context Protocol specification 2026-07-28 Back to text
Source 38: Integrating external AI agents (ServiceNow product documentation, Australia release) Back:ab
Source 40: MCP Registry Aggregators - Model Context Protocol Back to text
Source 41: Customer Support Addendum (ServiceNow legal schedules, Version 12MAR2025) Back to text
Source 42: Activating AI Control Tower (ServiceNow product documentation, Australia release) Back to text
Source 44: AI Control Tower: What's new in the June 2026 release (ServiceNow Community, AI Control Tower articles) Back to text
Source 45: Activate evaluation scoring for external AI systems (ServiceNow product documentation, Australia release) Back to text
Source 46: AI Service Graph Connector for Amazon release notes (ServiceNow Store version history) Back to text