Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

Kong AI Gateway vs ServiceNow AI Control Tower

Kong AI Gateway

Gateway that governs LLM, MCP, and agent-to-agent traffic

ServiceNow AI Control Tower

What ServiceNow calls a central hub to discover, secure, govern, observe, and measure AI

Short answer

Kong AI Gateway is a gateway that governs LLM, MCP, and A2A traffic; ServiceNow describes AI Control Tower as a central hub to discover, secure, govern, observe, and measure AI across an enterprise.⁠Source 1, Source 2, Source 3 Kong checks traffic on 2.x data plane nodes you run; ServiceNow says AI Control Tower auto-discovers AI assets into one inventory.⁠Source 2, Source 3

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both can proxy agents’ calls to MCP servers, with authentication and logging; ServiceNow’s community documentation says AI Control Tower does this through its AI Gateway.⁠Source 2, Source 4, Source 5, Source 6, Source 7
Where they differ
Kong proxies LLM, MCP, and A2A traffic through one data plane.⁠Source 2 ServiceNow says AI Control Tower discovers agents, models, and datasets, and can revoke a managed agent’s credentials.⁠Source 3, Source 8
Running both
ServiceNow’s CMDB connector imports API details from Kong Gateway.⁠Source 9 Neither vendor publicly documents using the two together.
Public sources · checked 2 October 2026
  • Offered
  • Preview
  • Not publicly documented

Kong AI Gateway

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedPer-agent allow or deny lists⁠Source 10
  • Registry and governance: PreviewKonnect Catalog agents⁠Source 11
  • Traffic between agents, tools, and models: OfferedGateway for LLM, MCP, A2A⁠Source 1
  • Agents across organizations: Not publicly documented

ServiceNow AI Control Tower

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedScoped OAuth tokens (community docs)⁠Source 6
  • Registry and governance: OfferedAI inventory tied to CMDB⁠Source 3
  • Traffic between agents, tools, and models: OfferedAI Gateway (community docs)⁠Source 5
  • Agents across organizations: Not publicly documented

At a glance

TopicKong AI GatewayServiceNow AI Control Tower
What it coversLLM, MCP, and A2A traffic, through one data plane with shared authentication, observability, and policy features.⁠Source 1, Source 2ServiceNow says it inventories AI agents, models, and MCP servers from ServiceNow and third parties.⁠Source 3 ServiceNow’s community documentation says its AI Gateway proxies MCP traffic.⁠Source 5
Where it runsIn 2.x, a Konnect-managed control plane in a region you choose, with data plane nodes you run.⁠Source 2, Source 12 Fully self-hosted AI gateways are part of a separate Gateway Enterprise offering.⁠Source 13ServiceNow says it runs on the ServiceNow AI Platform.⁠Source 3 Whether self-hosted ServiceNow customers can use it is not publicly documented.
Stopping an agentAn agent can have an allow or deny list of identities, enforced before traffic reaches it.⁠Source 10The kill switch can contain a managed agent and revoke all of its active credentials across connected systems.⁠Source 8, Source 14, Source 15 It covers agents on ServiceNow and four connected platforms.⁠Source 16
Pricing modelAI Management Plus from $25 a month plus usage; control planes are $200 a month hybrid, $500 Dedicated Cloud, or $25 serverless.⁠Source 13 Enterprise is custom, billed annually.⁠Source 13Included in its Foundation, Advanced, and Prime product tiers.⁠Source 17 ServiceNow says to contact it for pricing; its community documentation says usage-based costs may apply.⁠Source 3, Source 7, Source 18
Generally availableVersion 2.0 announced generally available on 1 September 2026; 2.2.0 released 30 September 2026.⁠Source 19, Source 20ServiceNow announced general availability on 6 May 2025.⁠Source 21 ServiceNow’s community documentation says AI Gateway became generally available on 10 September 2026.⁠Source 7, Source 22

What each one is

Kong AI Gateway

Kong AI Gateway governs LLM, MCP, and agent-to-agent traffic through one data plane, with shared authentication, observability, and policy features for all three.⁠Source 1, Source 2 In 2.x, an agent is added as an AI Agent entity, which exposes it at a gateway endpoint and can carry policies.⁠Source 10, Source 23

ServiceNow AI Control Tower

ServiceNow describes AI Control Tower as a central hub to discover, secure, govern, observe, and measure AI across an enterprise.⁠Source 3 ServiceNow says it keeps AI agents, models, and MCP servers from ServiceNow and third parties in one inventory tied to the CMDB.⁠Source 3

The differences that matter

  1. Agent inventory

    Kong AI Gateway

    In 2.x, each AI Agent entity is scoped to one gateway instance; Kong’s organization-wide agent inventory, in Konnect Catalog, is in beta.⁠Source 2, Source 10, Source 11

    ServiceNow AI Control Tower

    ServiceNow says it auto-discovers agents, models, MCP servers, and datasets into one inventory tied to the CMDB; connectors you set up reach external platforms.⁠Source 3, Source 24, Source 25

    Kong says the beta Catalog agent inventory should not be used in production.⁠Source 11 ServiceNow’s community documentation says only assets marked Managed get governance workflows and monitoring.⁠Source 15

  2. Policy on traffic

    Kong AI Gateway

    AI Policies on agents can apply input validation, request logging, and per-agent or per-consumer rate limits.⁠Source 10

    ServiceNow AI Control Tower

    ServiceNow’s community documentation says AI Gateway lets agents use only approved, active MCP servers, with tool policies by role, department, or data classification.⁠Source 6, Source 7

    Kong’s AI Policies can also apply to models, MCP servers, and consumers, or globally.⁠Source 2

  3. Where data goes

    Kong AI Gateway

    Kong’s control plane is never in the path of user data traffic; by default, telemetry to Konnect carries only usage, cost, and latency metadata.⁠Source 2

    ServiceNow AI Control Tower

    AI Control Tower requires sending data from your instance to a central ServiceNow environment, possibly in another region, and possibly to a third-party cloud.⁠Source 26

    Kong lets you choose the Konnect region.⁠Source 12 Separately, AI Control Tower has a regional data routing option for LLM and SLM requests.⁠Source 27

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicKong AI GatewayServiceNow AI Control Tower
Network exposureIn 2.x, data plane nodes you run proxy to each agent’s URL and authenticate to the control plane over mTLS.⁠Source 2, Source 10Agents using AI Gateway call a ServiceNow-hosted URL, per ServiceNow’s community documentation.⁠Source 5 Ports and egress: not publicly documented.
IdentityAn AI Agent can require API key or OpenID Connect authentication, such as through Okta or Azure AD, before routing.⁠Source 10, Source 28ServiceNow’s community documentation says AI Gateway verifies agent identity and issues short-lived OAuth 2.1 tokens on each connection through it.⁠Source 6
Access changes and revocationEach agent has an enabled switch; Request Termination or deny lists block callers.⁠Source 10, Source 29, Source 30 Nodes keep their last config without Konnect.⁠Source 2ServiceNow says its kill switch can contain a managed agent and revoke all of its active credentials across connected systems.⁠Source 8, Source 14, Source 15
Audit trailA2A audit logs: task IDs, method calls, latencies, errors.⁠Source 31 Konnect audit logs (Enterprise): webhook delivery, kept 7 days in Konnect.⁠Source 13, Source 32Audit logs record configuration changes to Data, Approvals, and AI model providers settings; each kill-switch containment leaves an audit trail.⁠Source 8, Source 27
Compliance2.2+ FIPS mode: FIPS 140-3 algorithms only, not NIST-validated.⁠Source 33 Kong Inc. lists ISO 27001 and SOC 2 (report under NDA).⁠Source 34ServiceNow says the company has an annual SOC 2 Type 2 attestation and ISO/IEC 42001 certification.⁠Source 35

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

Kong AI Gateway and ServiceNow AI Control Tower compared on 18 criteria
Kong AI GatewayServiceNow AI Control Tower
What it is
What it is and who it’s forA gateway that governs LLM, MCP, and A2A traffic.⁠Source 1, Source 2 All three run through one data plane, with shared authentication, observability, and policy features.⁠Source 2ServiceNow describes it as a central hub to discover, secure, govern, observe, and measure AI across an enterprise, on the ServiceNow AI Platform.⁠Source 3
Maturity2.0 announced generally available on 1 September 2026, and 2.2.0 released 30 September 2026.⁠Source 19, Source 20 Konnect Catalog’s agent inventory is in beta, not for production.⁠Source 11ServiceNow announced general availability on 6 May 2025.⁠Source 21 ServiceNow’s community documentation says AI Gateway became generally available on 10 September 2026.⁠Source 7, Source 22
Control
Agent registry and discoveryEach AI Agent entity is scoped to one gateway instance.⁠Source 2, Source 10 Konnect Catalog’s agent inventory is in beta.⁠Source 11ServiceNow says it auto-discovers agents, models, MCP servers, and datasets into one inventory tied to the CMDB.⁠Source 3 Connectors you set up reach external platforms.⁠Source 24, Source 25
Identity and access controlAn agent can require API key or OpenID Connect authentication before routing, and an allow or deny list enforced before traffic reaches it.⁠Source 10ServiceNow’s community documentation says AI Gateway verifies agent identity, issues short-lived OAuth 2.1 tokens, and allows only approved MCP servers.⁠Source 6
Ownership, policy, and revocationAgent policies include input validation, logging, and rate limits.⁠Source 10 Kong’s AI PII Sanitizer scrubs requests to AI models: a Plus add-on, included on Enterprise.⁠Source 13, Source 36The kill switch can contain a managed agent, revoking all of its active credentials across connected systems.⁠Source 8, Source 14, Source 15 It covers ServiceNow and four connected platforms.⁠Source 16
Audit log and observabilityA2A audit logs record task IDs, method calls, latencies, and errors.⁠Source 31 A2A telemetry can go to Konnect and OpenTelemetry.⁠Source 10 Bodies go to Konnect only if you opt in.⁠Source 2Audit logs show some workspace configuration changes.⁠Source 27 Each kill-switch containment leaves an audit trail.⁠Source 8 ServiceNow says metrics and traces monitor agents.⁠Source 3
Connection
How agents connectEach agent is an upstream URL the gateway proxies to.⁠Source 10 In 2.x, nodes you run keep a persistent connection to the control plane and authenticate over mTLS.⁠Source 2ServiceNow’s community documentation says agents using AI Gateway call a ServiceNow-hosted URL instead of the MCP server, which must be remote.⁠Source 5, Source 7
Agents across organizationsNot publicly documented (checked 2 October 2026)Third-party systems like Microsoft Agent 365 can discover publishable agents via an open API.⁠Source 37 Bringing in agents a partner controls: not publicly documented.
Protocol supportA2A over JSON-RPC and REST bindings.⁠Source 10 Four MCP revisions, 2025-03-26 to 2026-07-28 (the last from version 2.1).⁠Source 38ServiceNow’s community documentation calls AI Gateway its MCP enforcement layer.⁠Source 6 ServiceNow’s separate AI Agent Studio can connect external agents over A2A.⁠Source 39
Frameworks, models, and clouds supportedKong says it governs A2A traffic without changing how agents are built.⁠Source 40 Requests to agents that don’t use A2A can pass through as plain HTTP.⁠Source 10ServiceNow says it inventories agents, models, and MCP servers from ServiceNow or third parties.⁠Source 3 Its connector for Amazon covers Amazon Bedrock AgentCore.⁠Source 41
Operations
Deployment options and data residency2.x: a Konnect-managed control plane in a region you choose, data plane nodes you run.⁠Source 2, Source 12 Kong also sells Kong-managed Dedicated Cloud and serverless gateways.⁠Source 13, Source 42, Source 43ServiceNow says it runs on the ServiceNow AI Platform.⁠Source 3 Data goes to a central ServiceNow environment, possibly in another region or a third-party cloud.⁠Source 26
Compliance attestationsFrom 2.2, FIPS mode uses only FIPS 140-3 approved algorithms; not submitted for NIST validation.⁠Source 33 Kong lists ISO 27001, SOC 2, and PCI DSS for Kong Inc.⁠Source 34ServiceNow says the company has an annual SOC 2 Type 2 attestation and ISO/IEC 42001 certification.⁠Source 35 AI Control Tower’s coverage isn’t publicly documented.
Support and SLAKonnect targets 99.9% availability; Dedicated Cloud Gateways list a 99.99% SLA, serverless gateways none.⁠Source 13 Enterprise support SLAs: 30 min to 2 hours.⁠Source 13ServiceNow’s community documentation points to Now Support.⁠Source 44 ServiceNow’s Customer Support Addendum states a 99.8% availability SLA for production instances.⁠Source 45
Time and effort to get runningA quickstart script creates a Konnect control plane and a local Docker data plane.⁠Source 46 To route A2A traffic, you then create an AI Agent entity and attach policies.⁠Source 23Which features you can use depends on your license.⁠Source 47 ServiceNow’s community documentation says many customers implement it with a ServiceNow partner.⁠Source 44
Pricing model and public pricesPlus: from $25 a month plus usage; per control plane, $200 hybrid, $500 Dedicated Cloud, $25 serverless.⁠Source 13 Enterprise: custom, billed annually.⁠Source 13Contact ServiceNow for pricing.⁠Source 3 ServiceNow’s community documentation says usage-based costs may apply.⁠Source 7, Source 18 Fully managing external AI needs a separate license.⁠Source 17
Building
Agent building toolsKong says it can generate MCP tools and servers from Kong-managed APIs.⁠Source 1 Tools for building agents in Kong AI Gateway are not publicly documented.ServiceNow’s separate AI Agent Studio creates, configures, and deploys agents.⁠Source 48 Creating new custom agents is supported only in the Prime tier.⁠Source 17
Model accessOne API to providers including OpenAI, Anthropic, Amazon Bedrock, Gemini, Azure AI, Mistral, and Ollama, with credentials you supply.⁠Source 2, Source 46, Source 49Model provider settings cover ServiceNow-supported providers, such as Now LLM Service and AWS Claude, and ones your organization configures.⁠Source 27
Integrations and ecosystemA Policies Hub of policies and integrations.⁠Source 29 AI Vault works with AWS, GCP, Azure, and HashiCorp Vault secrets backends.⁠Source 2ServiceNow’s community documentation names discovery connectors for Databricks, Snowflake, and Hugging Face, and says connectors can also be custom-built.⁠Source 15, Source 44

Which to choose

Choose Kong AI Gateway if

  • You want one gateway for LLM, MCP, and A2A traffic, with one API to model providers such as OpenAI, Anthropic, and Mistral.⁠Source 1, Source 2, Source 46, Source 49
  • You want callers checked before requests reach an agent: API key or OpenID Connect authentication, then a per-agent allow or deny list.⁠Source 10
  • You want to run the data plane yourself: in 2.x, Konnect manages the control plane, which is never in your traffic’s path.⁠Source 2
  • You want published prices: AI Management Plus is from $25 a month plus usage, and $200 a month per hybrid control plane.⁠Source 13

Choose ServiceNow AI Control Tower if

  • You run ServiceNow on a Foundation, Advanced, or Prime tier: each includes AI Control Tower, which ties AI assets to your CMDB.⁠Source 3, Source 17
  • You want one inventory of agents, models, and MCP servers across platforms, with connectors that discover AI assets outside ServiceNow.⁠Source 3, Source 24
  • You want a kill switch that revokes all active credentials of a managed agent on connected platforms, with an audit trail.⁠Source 8, Source 14
  • You want AI compliance content: ServiceNow’s pack covers the EU AI Act, NIST AI RMF, and California and Colorado AI laws.⁠Source 50

Questions buyers ask

Do they support MCP and A2A?

Kong AI Gateway proxies LLM, MCP, and A2A traffic; it detects A2A requests and accepts four MCP revisions.⁠Source 2, Source 10, Source 38 ServiceNow’s community documentation says AI Control Tower’s AI Gateway proxies MCP traffic.⁠Source 5, Source 6 ServiceNow’s separate AI Agent Studio can connect external agents over A2A.⁠Source 39

How is each one priced?

Kong’s AI Management Plus: from $25 a month plus usage, and $200 a month per hybrid control plane.⁠Source 13 ServiceNow says to contact it for pricing; its Foundation, Advanced, and Prime tiers include AI Control Tower.⁠Source 3, Source 17 ServiceNow’s community documentation says usage-based costs may apply.⁠Source 7, Source 18

Can either one be self-hosted?

Kong offers fully self-hosted AI gateways in its separate Gateway Enterprise offering; the 2.x AI entities run hybrid, with Konnect’s managed control plane.⁠Source 2, Source 13 ServiceNow says AI Control Tower runs on the ServiceNow AI Platform; whether self-hosted ServiceNow customers can use it is not publicly documented.⁠Source 3

Can either one connect agents across organizations?

Kong AI Gateway proxies to agents registered as upstream URLs.⁠Source 10 ServiceNow’s External Registries API lets third-party systems such as Microsoft Agent 365 retrieve agents marked publishable.⁠Source 37 For both, bringing in another organization’s agents with access it controls is not publicly documented.

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

55 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Kong AI Gateway product page Kong · checked Back:abcdefg

  2. Source 2: AI Gateway architecture - Kong Docs Kong · checked Back:abcdefghijklmnopqrstuvwx

  3. Source 3: AI Control Tower - ServiceNow (product page) ServiceNow · checked Back:abcdefghijklmnopqrst

  4. Source 4: AI Gateway audit log reference - Kong Docs Kong · checked Back to text

  5. Source 5: AI Gateway Implementation Guide (ServiceNow Community, AI Control Tower articles) ServiceNow · checked Back:abcdef

  6. Source 6: What's new in AI Gateway v3.4 - September 2026 release (ServiceNow Community, AI Control Tower articles) ServiceNow · checked Back:abcdefg

  7. Source 7: AI Gateway FAQ (ServiceNow Community, AI Control Tower articles) ServiceNow · checked Back:abcdefgh

  8. Source 8: AI agent containment using kill switch protocol manually (ServiceNow product documentation, Australia release) ServiceNow · checked Back:abcdefg

  9. Source 9: API Service Graph Connector for Kong Gateway (ServiceNow product documentation, Australia release) ServiceNow · checked Back to text

  10. Source 10: AI Agents - Kong AI Gateway docs Kong · checked Back:abcdefghijklmnopqr

  11. Source 11: Agents in Catalog - Kong Docs Kong · checked Back:abcde

  12. Source 12: Geographic regions - Kong Docs Kong · checked Back:abc

  13. Source 13: Kong Pricing & Plans Kong · checked Back:abcdefghijklm

  14. Source 14: Configure AI agent containment using kill switch protocol manually (ServiceNow product documentation, Australia release) ServiceNow · checked Back:abcd

  15. Source 15: AI Control Tower: What's new in the June 2026 release (ServiceNow Community, AI Control Tower articles) ServiceNow · checked Back:abcde

  16. Source 16: Control enforcement points (ServiceNow product documentation, Australia release) ServiceNow · checked Back:ab

  17. Source 17: ServiceNow product tiers (ServiceNow product documentation, Australia release) ServiceNow · checked Back:abcde

  18. Source 18: AI Control Tower Observability & Monitoring FAQ (ServiceNow Community, AI Control Tower articles) ServiceNow · checked Back:abc

  19. Source 19: Kong AI Gateway 2.0 Is Now GA - And It's Already Moving Faster Kong · checked Back:ab

  20. Source 20: Kong AI Gateway changelog - Kong Docs Kong · checked Back:ab

  21. Source 21: ServiceNow Launches AI Control Tower, a Centralized Command Center to Govern, Manage, Secure, and Realize Value From Any AI Agent, Model, and Workflow (ServiceNow news release, investor relations PDF) ServiceNow · checked Back:ab

  22. Source 22: What's new in AI Control Tower for August & September 2026 (ServiceNow Community, AI Control Tower articles) ServiceNow · checked Back:ab

  23. Source 23: Route A2A agent traffic through AI Gateway - Kong Docs Kong · checked Back:ab

  24. Source 24: Discovering AI assets through connectors (ServiceNow product documentation, Australia release) ServiceNow · checked Back:abc

  25. Source 25: Configuring connectors (ServiceNow product documentation, Australia release) ServiceNow · checked Back:ab

  26. Source 26: AI Control Tower (ServiceNow product documentation, Australia release) ServiceNow · checked Back:ab

  27. Source 27: AI model providers (ServiceNow product documentation, Australia release) ServiceNow · checked Back:abcd

  28. Source 28: AI Auth Strategies - Kong AI Gateway docs Kong · checked Back to text

  29. Source 29: Kong AI Gateway Policies - Kong Docs Kong · checked Back:ab

  30. Source 30: Request Termination - Configuration Reference - Policy | Kong Docs Kong · checked Back to text

  31. Source 31: Route A2A traffic through AI Gateway - Kong Docs Kong · checked Back:ab

  32. Source 32: Konnect and Dev Portal audit logs - Kong Docs Kong · checked Back to text

  33. Source 33: FIPS 140-3 compliance in AI Gateway - Kong Docs Kong · checked Back:ab

  34. Source 34: Trust Center - Kong Inc. Kong · checked Back:ab

  35. Source 35: Compliance - ServiceNow Trust ServiceNow · checked Back:ab

  36. Source 36: AI PII Sanitizer - Policy | Kong Docs Kong · checked Back to text

  37. Source 37: External Registries (ServiceNow product documentation, Australia release) ServiceNow · checked Back:ab

  38. Source 38: MCP version support - Kong AI Gateway docs Kong · checked Back:ab

  39. Source 39: Integrating external AI agents (ServiceNow product documentation, Australia release) ServiceNow · checked Back:ab

  40. Source 40: The Agent Gateway for Secure, Observable Agent-to-Agent Communication (Kong) Kong · checked Back to text

  41. Source 41: AI Service Graph Connector for Amazon release notes (ServiceNow Store version history) ServiceNow · checked Back to text

  42. Source 42: Dedicated Cloud Gateways - Kong Docs Kong · checked Back to text

  43. Source 43: Serverless Gateways - Kong Docs Kong · checked Back to text

  44. Source 44: AI Control Tower Welcome Guide (ServiceNow Community, AI Control Tower articles) ServiceNow · checked Back:abc

  45. Source 45: Customer Support Addendum (ServiceNow legal schedules, Version 12MAR2025) ServiceNow · checked Back to text

  46. Source 46: Kong AI Gateway | Kong Docs Kong · checked Back:abc

  47. Source 47: Activating AI Control Tower (ServiceNow product documentation, Australia release) ServiceNow · checked Back to text

  48. Source 48: AI Agent Studio (ServiceNow product documentation, Australia release) ServiceNow · checked Back to text

  49. Source 49: AI Gateway providers - Kong Docs Kong · checked Back:ab

  50. Source 50: AI Risk and Compliance Content Pack (ServiceNow product documentation, Australia release, Governance, Risk, and Compliance) ServiceNow · checked Back to text

  51. Source 51: Your company's private network Blocks.ai · checked Back to text

  52. Source 52: Network requirements Blocks.ai · checked Back to text

  53. Source 53: Solutions: Agent sprawl Blocks.ai · checked Back to text

  54. Source 54: Solutions: Partner networks Blocks.ai · checked Back to text

  55. Source 55: Pricing Blocks.ai · checked Back to text