# Best guardrails and safety filters for AI agents (slim) > Google Cloud Model Armor (BB), Amazon Bedrock Guardrails (BB) and OpenAI Moderation API (BB) lead the 16 ranked guardrails and safety filters. Picks by need, strengths, weaknesses and prices from the Anchor benchmark. - Full: https://www.anchorterminal.com/best/guardrails/index.md (~6,150 tokens) · this version ~1,530 tokens · JSON https://www.anchorterminal.com/best/guardrails/index.json · canonical https://www.anchorterminal.com/best/guardrails/ - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 The 10 highest-scoring of 16 guardrails and safety filters on the Anchor benchmark, with a pick for each need and where each one falls short. Scores come from public evidence, re-checked as vendors change. - Ranked: 16 · agent-ready (BB or better): 3 · accept x402: 0 · hosted endpoints: 9 - Full ranked table: https://www.anchorterminal.com/categories/guardrails.md - Head-to-head comparisons: https://www.anchorterminal.com/compare/guardrails/index.md (118) - Methodology: https://www.anchorterminal.com/benchmark/index.md ## The shortlist | # | Tool | Grade | Score | Best for | Price | Where | | --- | --- | --- | --- | --- | --- | --- | | 1 | [Google Cloud Model Armor](https://www.anchorterminal.com/tools/google-model-armor.md) | BB | 77.9 | Teams already on Google Cloud who want prompt and response screening with real PII detection, document and URL scanning, and audit logs, at the lowest paid rate in the category. | Freemium | hosted | | 2 | [Amazon Bedrock Guardrails](https://www.anchorterminal.com/tools/amazon-bedrock-guardrails.md) | BB | 74.8 | A team already on AWS that wants one versioned policy covering topics, PII masking, grounding and prompt attacks in front of any model. | Pay per use | hosted | | 3 | [OpenAI Moderation API](https://www.anchorterminal.com/tools/openai-moderation.md) | BB | 71.3 | A free harm-category filter for an agent already on OpenAI. | Free | hosted | | 4 | [OpenAI Guardrails](https://www.anchorterminal.com/tools/openai-guardrails.md) | B | 69.5 | Teams already on the OpenAI client or Agents SDK that want several checks from one config file with little code. | Free · OSS | library | | 5 | [NVIDIA NeMo Guardrails](https://www.anchorterminal.com/tools/nemo-guardrails.md) | B | 68.4 | Teams that want to compose several checks (their own, NVIDIA's and third-party APIs) behind one OpenAI-compatible endpoint. | Free · OSS | library | | 6 | [Presidio](https://www.anchorterminal.com/tools/microsoft-presidio.md) | B | 66 | Detecting and masking personal data in prompts, outputs, logs and images on the owner's own machines, with detection tuned by entity, threshold and custom recognisers. | Free · OSS | local | | 7 | [Prisma AIRS AI Runtime Security API](https://www.anchorterminal.com/tools/prisma-airs.md) | B | 62.8 | A company already buying Palo Alto Networks through Strata Cloud Manager that wants prompt, response and MCP tool scanning with DLP and URL filtering from the same vendor. | Paid | hosted | | 8 | [Cisco AI Defense Inspection API](https://www.anchorterminal.com/tools/cisco-ai-defense-inspection.md) | C | 61.3 | A company already buying Cisco security through Security Cloud Control that wants its own application to decide what to do with each verdict. | Paid | hosted | | 9 | [Azure AI Content Safety (Prompt Shields)](https://www.anchorterminal.com/tools/azure-ai-content-safety.md) | C | 60.7 | An agent on Azure that retrieves documents and needs indirect-injection checks next to harm-category moderation. | $338 / mo | hosted | | 10 | [Granite Guardian](https://www.anchorterminal.com/tools/granite-guardian.md) | C | 60.1 | A team with a GPU that wants one English-language judge for harm, jailbreaks, RAG groundedness, function-call checks and house rules, under a permissive licence with no gate. | Free | local | ## Picks by need - Highest score overall: [Google Cloud Model Armor](https://www.anchorterminal.com/tools/google-model-armor.md), BB, 77.9/100 on the benchmark. Also [Amazon Bedrock Guardrails](https://www.anchorterminal.com/tools/amazon-bedrock-guardrails.md), BB, 74.8/100. - Schema & documentation: [Amazon Bedrock Guardrails](https://www.anchorterminal.com/tools/amazon-bedrock-guardrails.md), 92/100 on schema & documentation, against 78 for the overall leader. - Agent ergonomics: [Amazon Bedrock Guardrails](https://www.anchorterminal.com/tools/amazon-bedrock-guardrails.md), 93/100 on agent ergonomics, against 75 for the overall leader. - Maintenance & community: [OpenAI Guardrails](https://www.anchorterminal.com/tools/openai-guardrails.md), 89/100 on maintenance & community, against 85 for the overall leader. - A hosted MCP endpoint: [Galileo API + MCP](https://www.anchorterminal.com/tools/galileo.md), remote MCP server, nothing to install. - Self-hosting under an open licence: [OpenAI Guardrails](https://www.anchorterminal.com/tools/openai-guardrails.md), self-hosted, MIT licence. Also [NVIDIA NeMo Guardrails](https://www.anchorterminal.com/tools/nemo-guardrails.md), self-hosted, Apache-2 licence. ## How to choose - Injection and jailbreak coverage: Check which attack types are detected, including indirect injection in tool results, because agents read untrusted pages and documents that can carry instructions. - Wrongful blocks on clean input: Check the false positive rate on clean inputs, because a filter that blocks legitimate tool calls stops the agent's task without any attack taking place. - Latency added to each call: Check the latency each check adds at your payload size, since guardrails run on every model call and the delay compounds across a multi-step agent run. - Self-hosting option: Check whether the filter can run in your own infrastructure, because a hosted check sends every prompt, including personal data, to another party. - How the benchmark tests this category: A set of prompts with injections, jailbreaks, personal data and clean inputs run through each filter. We count what is caught and what is wrongly blocked, and measure the latency each adds. Each listing's verdict, strengths and weaknesses: https://www.anchorterminal.com/best/guardrails/index.md