ServiceNow AI Control Tower & AI Gateway: A UK Playbook for Governing Agents and MCP
Australia turns AI Control Tower into an enterprise command centre for agents, prompts and MCP — with AI Gateway enforcement and kill switches. Here is how UK teams should roll it out without freezing delivery.

Australia turns AI Control Tower into an enterprise command centre for agents, prompts and MCP — with AI Gateway enforcement and kill switches. Here is how UK teams should roll it out without freezing delivery.
- Australia elevates AI Control Tower from dashboard to command centre across ServiceNow and the wider AI estate.
- AI Gateway enforces MCP registry, auth, PII and policy — unapproved servers can be hidden from builders.
- Kill switches and least-privilege access graphs are mandatory for agentic production in UK regulated firms.
- Roll out in 30 days: inventory → policy → non-prod prove → single-workflow prod pilot.
Why AI Control Tower is no longer a dashboard
If Zurich gave UK platform teams visibility into Now Assist and early agents, the Australia release turns AI Control Tower into a command centre: discover, observe, govern, secure and measure AI across ServiceNow and the wider estate.
That matters because agent sprawl is already real. Teams wire Claude, Copilot, Build Agent skills and home-grown MCP servers into tickets, CMDB and workflows faster than CAB and cyber can inventory them. Control Tower plus AI Gateway is ServiceNow's answer — a governed path for agentic work instead of another shadow integration.
AI governance and automation
This guide is for UK CIOs, AI Stewards and ServiceNow architects who need a practical enablement order — not a feature brochure.
What changed in Australia (and why UK boards care)
At Knowledge 2026, ServiceNow expanded Control Tower so it can:
- Discover agents, models, prompts, datasets and MCP servers across hyperscalers and major apps (AWS, Azure, Google Cloud, SAP, Oracle, Workday and more)
- Observe live metrics and agent behaviour (including deeper runtime observability from the Traceloop acquisition)
- Govern with risk frameworks aligned to NIST and EU AI Act patterns — useful for UK firms already mapping to ICO guidance and board AI policies
- Secure with least-privilege access graphs and a kill switch when an agent goes off script
- Measure ROI and usage instead of quarterly spreadsheet audits
AI Gateway sits on the execution path for MCP traffic: registry of servers, policy for auth and safety, runtime enforcement, and observability that feeds Control Tower. Unapproved MCP servers are no longer just flagged — they can be hidden from AI Agent Studio. PII controls move from recommendation toward gateway blocking.
Reference operating model for UK enterprises
Builders (AI Agent Studio / external agents / Build Agent)
│
▼
AI Gateway (MCP registry + policy + PII / auth)
│
▼
AI Control Tower (discover / observe / govern / secure / measure)
│
├── Kill switch / disable misbehaving agents
├── CAB + AI Steward approvals
└── Audit for cyber, risk and regulators
Design rules that survive UK cyber and architecture boards:
- No production MCP without Control Tower registration — treat the gateway as mandatory, not optional.
- Separate builder freedom from production authority — Innovation Lab / non-prod can experiment; prod needs Steward + CAB.
- Kill switch owners named — who can disable an agent at 2am, and how is that tested?
- Map to your AI policy — EU AI Act-aligned frameworks in Control Tower still need a UK GDPR / DPA 2018 data-minimisation story.
- Action Fabric and Otto ride the same bus — external agents that act through MCP inherit Control Tower audit; do not invent a second path.
30-day UK rollout checklist
| Week | Focus | Exit criteria |
|---|---|---|
| 1 | Inventory | All known MCP servers and production agents listed in Control Tower; shadow endpoints retired or ticketed |
| 2 | Policy | Auth, allow/deny and PII rules for AI Gateway agreed with cyber; kill-switch runbook signed |
| 3 | Non-prod prove | One high-value workflow (incident or case) through approved MCP under Steward review |
| 4 | Prod pilot | Single agent identity, CAB, monitoring dashboards live; rollback rehearsed |
How this fits Otto, Action Fabric and Build Agent
- Otto is the unified experience brand — Control Tower is still where governance lives.
- Action Fabric + MCP Server open ServiceNow actions to external agents; Control Tower must approve which agents and tools.
- Build Agent / IDE skills accelerate delivery; they do not replace Steward lifecycle for prompts, skills and MCP.
Common failure modes
- Enabling MCP in prod before gateway policies exist
- Letting citizen-built skills bypass the same approval playbook as MCP servers
- Measuring only "agents deployed" instead of successful governed outcomes and kill-switch readiness
- Ignoring hyperscaler-side agents that never touch ServiceNow UX but still move enterprise data
Bottom line
Australia makes agentic ServiceNow executable and controllable. For UK estates, AI Control Tower and AI Gateway should be on the critical path of every AI programme — before the next wave of Claude/Copilot connectors hits production.
AIATS helps UK organisations design that control plane alongside ITSM, CMDB and cloud agent runtimes.
Control Tower without AI Gateway is visibility theatre. Make the gateway the only path for production MCP, name kill-switch owners, and put Steward+CAB in front of every new agent identity.
