Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.
Kong AI Gateway vs ServiceNow AI Control Tower
Kong AI Gateway
Gateway that governs LLM, MCP, and agent-to-agent traffic
ServiceNow AI Control Tower
What ServiceNow calls a central hub to discover, secure, govern, observe, and measure AI
Short answer
Kong AI Gateway is a gateway that governs LLM, MCP, and A2A traffic; ServiceNow describes AI Control Tower as a central hub to discover, secure, govern, observe, and measure AI across an enterprise.Source 1, Source 2, Source 3 Kong checks traffic on 2.x data plane nodes you run; ServiceNow says AI Control Tower auto-discovers AI assets into one inventory.Source 2, Source 3
Where each one sits
Six layers of running AI agents at a company, and what each product’s own public sources say it covers.
These aren’t the same kind of product
- Where they overlap
- Both can proxy agents’ calls to MCP servers, with authentication and logging; ServiceNow’s community documentation says AI Control Tower does this through its AI Gateway.Source 2, Source 4, Source 5, Source 6, Source 7
- Where they differ
- Kong proxies LLM, MCP, and A2A traffic through one data plane.Source 2 ServiceNow says AI Control Tower discovers agents, models, and datasets, and can revoke a managed agent’s credentials.Source 3, Source 8
- Running both
- ServiceNow’s CMDB connector imports API details from Kong Gateway.Source 9 Neither vendor publicly documents using the two together.
Kong AI Gateway
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Agents across organizations: Not publicly documented
ServiceNow AI Control Tower
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Agents across organizations: Not publicly documented
At a glance
What each one is
Kong AI Gateway
Kong AI Gateway governs LLM, MCP, and agent-to-agent traffic through one data plane, with shared authentication, observability, and policy features for all three.Source 1, Source 2 In 2.x, an agent is added as an AI Agent entity, which exposes it at a gateway endpoint and can carry policies.Source 10, Source 23
ServiceNow AI Control Tower
ServiceNow describes AI Control Tower as a central hub to discover, secure, govern, observe, and measure AI across an enterprise.Source 3 ServiceNow says it keeps AI agents, models, and MCP servers from ServiceNow and third parties in one inventory tied to the CMDB.Source 3
The differences that matter
Agent inventory
Kong AI GatewayIn 2.x, each AI Agent entity is scoped to one gateway instance; Kong’s organization-wide agent inventory, in Konnect Catalog, is in beta.Source 2, Source 10, Source 11
ServiceNow AI Control TowerServiceNow says it auto-discovers agents, models, MCP servers, and datasets into one inventory tied to the CMDB; connectors you set up reach external platforms.Source 3, Source 24, Source 25
Kong says the beta Catalog agent inventory should not be used in production.Source 11 ServiceNow’s community documentation says only assets marked Managed get governance workflows and monitoring.Source 15
Policy on traffic
Kong AI GatewayAI Policies on agents can apply input validation, request logging, and per-agent or per-consumer rate limits.Source 10
ServiceNow AI Control TowerServiceNow’s community documentation says AI Gateway lets agents use only approved, active MCP servers, with tool policies by role, department, or data classification.Source 6, Source 7
Kong’s AI Policies can also apply to models, MCP servers, and consumers, or globally.Source 2
Where data goes
Kong AI GatewayKong’s control plane is never in the path of user data traffic; by default, telemetry to Konnect carries only usage, cost, and latency metadata.Source 2
ServiceNow AI Control TowerAI Control Tower requires sending data from your instance to a central ServiceNow environment, possibly in another region, and possibly to a third-party cloud.Source 26
Kong lets you choose the Konnect region.Source 12 Separately, AI Control Tower has a regional data routing option for LLM and SLM requests.Source 27
For security teams
What a security review asks, answered from each vendor’s public documentation.
Full comparison
18 criteria in five groups. Every cell links to its source, or says no public source answers it.
| Kong AI Gateway | ServiceNow AI Control Tower | |
|---|---|---|
| What it is | ||
| What it is and who it’s for | A gateway that governs LLM, MCP, and A2A traffic.Source 1, Source 2 All three run through one data plane, with shared authentication, observability, and policy features.Source 2 | ServiceNow describes it as a central hub to discover, secure, govern, observe, and measure AI across an enterprise, on the ServiceNow AI Platform.Source 3 |
| Maturity | 2.0 announced generally available on 1 September 2026, and 2.2.0 released 30 September 2026.Source 19, Source 20 Konnect Catalog’s agent inventory is in beta, not for production.Source 11 | ServiceNow announced general availability on 6 May 2025.Source 21 ServiceNow’s community documentation says AI Gateway became generally available on 10 September 2026.Source 7, Source 22 |
| Control | ||
| Agent registry and discovery | Each AI Agent entity is scoped to one gateway instance.Source 2, Source 10 Konnect Catalog’s agent inventory is in beta.Source 11 | ServiceNow says it auto-discovers agents, models, MCP servers, and datasets into one inventory tied to the CMDB.Source 3 Connectors you set up reach external platforms.Source 24, Source 25 |
| Identity and access control | An agent can require API key or OpenID Connect authentication before routing, and an allow or deny list enforced before traffic reaches it.Source 10 | ServiceNow’s community documentation says AI Gateway verifies agent identity, issues short-lived OAuth 2.1 tokens, and allows only approved MCP servers.Source 6 |
| Ownership, policy, and revocation | Agent policies include input validation, logging, and rate limits.Source 10 Kong’s AI PII Sanitizer scrubs requests to AI models: a Plus add-on, included on Enterprise.Source 13, Source 36 | The kill switch can contain a managed agent, revoking all of its active credentials across connected systems.Source 8, Source 14, Source 15 It covers ServiceNow and four connected platforms.Source 16 |
| Audit log and observability | A2A audit logs record task IDs, method calls, latencies, and errors.Source 31 A2A telemetry can go to Konnect and OpenTelemetry.Source 10 Bodies go to Konnect only if you opt in.Source 2 | Audit logs show some workspace configuration changes.Source 27 Each kill-switch containment leaves an audit trail.Source 8 ServiceNow says metrics and traces monitor agents.Source 3 |
| Connection | ||
| How agents connect | Each agent is an upstream URL the gateway proxies to.Source 10 In 2.x, nodes you run keep a persistent connection to the control plane and authenticate over mTLS.Source 2 | ServiceNow’s community documentation says agents using AI Gateway call a ServiceNow-hosted URL instead of the MCP server, which must be remote.Source 5, Source 7 |
| Agents across organizations | Not publicly documented (checked 2 October 2026) | Third-party systems like Microsoft Agent 365 can discover publishable agents via an open API.Source 37 Bringing in agents a partner controls: not publicly documented. |
| Protocol support | A2A over JSON-RPC and REST bindings.Source 10 Four MCP revisions, 2025-03-26 to 2026-07-28 (the last from version 2.1).Source 38 | ServiceNow’s community documentation calls AI Gateway its MCP enforcement layer.Source 6 ServiceNow’s separate AI Agent Studio can connect external agents over A2A.Source 39 |
| Frameworks, models, and clouds supported | Kong says it governs A2A traffic without changing how agents are built.Source 40 Requests to agents that don’t use A2A can pass through as plain HTTP.Source 10 | ServiceNow says it inventories agents, models, and MCP servers from ServiceNow or third parties.Source 3 Its connector for Amazon covers Amazon Bedrock AgentCore.Source 41 |
| Operations | ||
| Deployment options and data residency | 2.x: a Konnect-managed control plane in a region you choose, data plane nodes you run.Source 2, Source 12 Kong also sells Kong-managed Dedicated Cloud and serverless gateways.Source 13, Source 42, Source 43 | ServiceNow says it runs on the ServiceNow AI Platform.Source 3 Data goes to a central ServiceNow environment, possibly in another region or a third-party cloud.Source 26 |
| Compliance attestations | From 2.2, FIPS mode uses only FIPS 140-3 approved algorithms; not submitted for NIST validation.Source 33 Kong lists ISO 27001, SOC 2, and PCI DSS for Kong Inc.Source 34 | ServiceNow says the company has an annual SOC 2 Type 2 attestation and ISO/IEC 42001 certification.Source 35 AI Control Tower’s coverage isn’t publicly documented. |
| Support and SLA | Konnect targets 99.9% availability; Dedicated Cloud Gateways list a 99.99% SLA, serverless gateways none.Source 13 Enterprise support SLAs: 30 min to 2 hours.Source 13 | ServiceNow’s community documentation points to Now Support.Source 44 ServiceNow’s Customer Support Addendum states a 99.8% availability SLA for production instances.Source 45 |
| Time and effort to get running | A quickstart script creates a Konnect control plane and a local Docker data plane.Source 46 To route A2A traffic, you then create an AI Agent entity and attach policies.Source 23 | Which features you can use depends on your license.Source 47 ServiceNow’s community documentation says many customers implement it with a ServiceNow partner.Source 44 |
| Pricing model and public prices | Plus: from $25 a month plus usage; per control plane, $200 hybrid, $500 Dedicated Cloud, $25 serverless.Source 13 Enterprise: custom, billed annually.Source 13 | Contact ServiceNow for pricing.Source 3 ServiceNow’s community documentation says usage-based costs may apply.Source 7, Source 18 Fully managing external AI needs a separate license.Source 17 |
| Building | ||
| Agent building tools | Kong says it can generate MCP tools and servers from Kong-managed APIs.Source 1 Tools for building agents in Kong AI Gateway are not publicly documented. | ServiceNow’s separate AI Agent Studio creates, configures, and deploys agents.Source 48 Creating new custom agents is supported only in the Prime tier.Source 17 |
| Model access | One API to providers including OpenAI, Anthropic, Amazon Bedrock, Gemini, Azure AI, Mistral, and Ollama, with credentials you supply.Source 2, Source 46, Source 49 | Model provider settings cover ServiceNow-supported providers, such as Now LLM Service and AWS Claude, and ones your organization configures.Source 27 |
| Integrations and ecosystem | A Policies Hub of policies and integrations.Source 29 AI Vault works with AWS, GCP, Azure, and HashiCorp Vault secrets backends.Source 2 | ServiceNow’s community documentation names discovery connectors for Databricks, Snowflake, and Hugging Face, and says connectors can also be custom-built.Source 15, Source 44 |
Which to choose
Choose Kong AI Gateway if
- You want one gateway for LLM, MCP, and A2A traffic, with one API to model providers such as OpenAI, Anthropic, and Mistral.Source 1, Source 2, Source 46, Source 49
- You want callers checked before requests reach an agent: API key or OpenID Connect authentication, then a per-agent allow or deny list.Source 10
- You want to run the data plane yourself: in 2.x, Konnect manages the control plane, which is never in your traffic’s path.Source 2
- You want published prices: AI Management Plus is from $25 a month plus usage, and $200 a month per hybrid control plane.Source 13
Choose ServiceNow AI Control Tower if
- You run ServiceNow on a Foundation, Advanced, or Prime tier: each includes AI Control Tower, which ties AI assets to your CMDB.Source 3, Source 17
- You want one inventory of agents, models, and MCP servers across platforms, with connectors that discover AI assets outside ServiceNow.Source 3, Source 24
- You want a kill switch that revokes all active credentials of a managed agent on connected platforms, with an audit trail.Source 8, Source 14
- You want AI compliance content: ServiceNow’s pack covers the EU AI Act, NIST AI RMF, and California and Colorado AI laws.Source 50
Questions buyers ask
Do they support MCP and A2A?
Kong AI Gateway proxies LLM, MCP, and A2A traffic; it detects A2A requests and accepts four MCP revisions.Source 2, Source 10, Source 38 ServiceNow’s community documentation says AI Control Tower’s AI Gateway proxies MCP traffic.Source 5, Source 6 ServiceNow’s separate AI Agent Studio can connect external agents over A2A.Source 39
How is each one priced?
Kong’s AI Management Plus: from $25 a month plus usage, and $200 a month per hybrid control plane.Source 13 ServiceNow says to contact it for pricing; its Foundation, Advanced, and Prime tiers include AI Control Tower.Source 3, Source 17 ServiceNow’s community documentation says usage-based costs may apply.Source 7, Source 18
Can either one be self-hosted?
Kong offers fully self-hosted AI gateways in its separate Gateway Enterprise offering; the 2.x AI entities run hybrid, with Konnect’s managed control plane.Source 2, Source 13 ServiceNow says AI Control Tower runs on the ServiceNow AI Platform; whether self-hosted ServiceNow customers can use it is not publicly documented.Source 3
Can either one connect agents across organizations?
Kong AI Gateway proxies to agents registered as upstream URLs.Source 10 ServiceNow’s External Registries API lets third-party systems such as Microsoft Agent 365 retrieve agents marked publishable.Source 37 For both, bringing in another organization’s agents with access it controls is not publicly documented.
How we compare
Read the full methodEvery claim on this page links to a public source. Where none answers a question, the page says so.
We re-check every fact at least every 90 days. This page was last checked .
Something wrong or out of date? Tell us and we’ll correct it.
Sources
55 public sources, each with the date we checked it. Every one opens in a new tab.
Source 2: AI Gateway architecture - Kong Docs Back:abcdefghijklmnopqrstuvwx
Source 3: AI Control Tower - ServiceNow (product page) Back:abcdefghijklmnopqrst
Source 4: AI Gateway audit log reference - Kong Docs Back to text
Source 5: AI Gateway Implementation Guide (ServiceNow Community, AI Control Tower articles) Back:abcdef
Source 6: What's new in AI Gateway v3.4 - September 2026 release (ServiceNow Community, AI Control Tower articles) Back:abcdefg
Source 7: AI Gateway FAQ (ServiceNow Community, AI Control Tower articles) Back:abcdefgh
Source 8: AI agent containment using kill switch protocol manually (ServiceNow product documentation, Australia release) Back:abcdefg
Source 9: API Service Graph Connector for Kong Gateway (ServiceNow product documentation, Australia release) Back to text
Source 10: AI Agents - Kong AI Gateway docs Back:abcdefghijklmnopqr
Source 14: Configure AI agent containment using kill switch protocol manually (ServiceNow product documentation, Australia release) Back:abcd
Source 15: AI Control Tower: What's new in the June 2026 release (ServiceNow Community, AI Control Tower articles) Back:abcde
Source 16: Control enforcement points (ServiceNow product documentation, Australia release) Back:ab
Source 17: ServiceNow product tiers (ServiceNow product documentation, Australia release) Back:abcde
Source 18: AI Control Tower Observability & Monitoring FAQ (ServiceNow Community, AI Control Tower articles) Back:abc
Source 19: Kong AI Gateway 2.0 Is Now GA - And It's Already Moving Faster Back:ab
Source 21: ServiceNow Launches AI Control Tower, a Centralized Command Center to Govern, Manage, Secure, and Realize Value From Any AI Agent, Model, and Workflow (ServiceNow news release, investor relations PDF) Back:ab
Source 22: What's new in AI Control Tower for August & September 2026 (ServiceNow Community, AI Control Tower articles) Back:ab
Source 23: Route A2A agent traffic through AI Gateway - Kong Docs Back:ab
Source 24: Discovering AI assets through connectors (ServiceNow product documentation, Australia release) Back:abc
Source 25: Configuring connectors (ServiceNow product documentation, Australia release) Back:ab
Source 26: AI Control Tower (ServiceNow product documentation, Australia release) Back:ab
Source 27: AI model providers (ServiceNow product documentation, Australia release) Back:abcd
Source 28: AI Auth Strategies - Kong AI Gateway docs Back to text
Source 30: Request Termination - Configuration Reference - Policy | Kong Docs Back to text
Source 31: Route A2A traffic through AI Gateway - Kong Docs Back:ab
Source 32: Konnect and Dev Portal audit logs - Kong Docs Back to text
Source 33: FIPS 140-3 compliance in AI Gateway - Kong Docs Back:ab
Source 36: AI PII Sanitizer - Policy | Kong Docs Back to text
Source 37: External Registries (ServiceNow product documentation, Australia release) Back:ab
Source 38: MCP version support - Kong AI Gateway docs Back:ab
Source 39: Integrating external AI agents (ServiceNow product documentation, Australia release) Back:ab
Source 40: The Agent Gateway for Secure, Observable Agent-to-Agent Communication (Kong) Back to text
Source 41: AI Service Graph Connector for Amazon release notes (ServiceNow Store version history) Back to text
Source 42: Dedicated Cloud Gateways - Kong Docs Back to text
Source 44: AI Control Tower Welcome Guide (ServiceNow Community, AI Control Tower articles) Back:abc
Source 45: Customer Support Addendum (ServiceNow legal schedules, Version 12MAR2025) Back to text
Source 47: Activating AI Control Tower (ServiceNow product documentation, Australia release) Back to text
Source 48: AI Agent Studio (ServiceNow product documentation, Australia release) Back to text
Source 50: AI Risk and Compliance Content Pack (ServiceNow product documentation, Australia release, Governance, Risk, and Compliance) Back to text