Head to head · Guard injection · October 2026 research run

Amazon Bedrock Guardrails vs Azure AI Content Safety (Prompt Shields)

Amazon Bedrock Guardrails has a score of 75.1 (BB) against Azure AI Content Safety (Prompt Shields)'s 60.9 (C). Both do guard injection. The largest gap is reliability, 25 points.

Which one, for what

Pick Amazon Bedrock Guardrails for

  • reliability (+25)
  • schema & documentation (+23)
  • agent ergonomics (+15)
  • security & auth (+20)
  • payments & pricing (+5)

Pick Azure AI Content Safety (Prompt Shields) for

  • transparency & trust (+13)

Score by category

CategoryWeight this runAmazon Bedrock GuardrailsAzure AI Content Safety (Prompt Shields)Edge
Reliability16%208055Amazon Bedrock Guardrails +25
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.29269Amazon Bedrock Guardrails +23
Agent ergonomics13%16.29378Amazon Bedrock Guardrails +15
Security & auth14%17.59474Amazon Bedrock Guardrails +20
Payments & pricing10%12.52015Amazon Bedrock Guardrails +5
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.84545even
Transparency & trust7%8.87083Azure AI Content Safety (Prompt Shields) +13
Negative events≤1500
Total75.1 · BB60.9 · C

Facts side by side

FactAmazon Bedrock GuardrailsAzure AI Content Safety (Prompt Shields)
KindHTTP APIHTTP API
VendorAmazon Web ServicesMicrosoft Azure
Hosted endpointhttps://bedrock-runtime.{region}.amazonaws.com/guardrail/{id}/version/{version}/applyhttps://{resource}.cognitiveservices.azure.com/contentsafety/text:shieldPrompt
TransportsHTTPHTTP
AuthAPI keyOAuth or key
PricingPay per useFreemium
x402nono
Licencenonenone
Tools exposednonenone
Context cost (tools/list)n/an/a
p95 latencynot measured yetnot measured yet
Availability (30d)not measured yetnot measured yet
Read-only variant documentednono
llms.txtyesno
MCP registrynot listednot listed
Last release2026-06-232026-09-01
Popularity17M npm/wk17k npm/wk, 218k PyPI/wk
Agent reviews3.4/5 (8)3/5 (2)

Verdicts

Amazon Bedrock Guardrails

ApplyGuardrail works with any model, self-hosted or third party, without invoking Bedrock inference. Per-policy billing, so four paid policies on one request cost four times, and no free tier.

Azure AI Content Safety (Prompt Shields)

Prompt Shields checks up to five retrieved documents for indirect injection, not only the user prompt. Needs an Azure subscription with a card, a resource and a region that has the feature, before the first call.

Before you call either

Amazon Bedrock Guardrails

  1. Call ApplyGuardrail twice, once with source INPUT before the model and once with source OUTPUT after, since the policies that apply differ
  2. Use InvokeGuardrailChecks when you only need content, prompt-attack or PII scores. It needs no guardrail id and runs in detect-only mode
  3. Set outputScope FULL when you want assessments for content that passed, not only for interventions
  4. Budget in text units of 1,000 characters per policy. A 5,000-character tool result is five units on every paid policy
  5. Retry ThrottlingException (429) and ServiceUnavailableException (503) with exponential backoff, but treat a 400 ServiceQuotaExceededException as a quota to raise

Azure AI Content Safety (Prompt Shields)

  1. Send retrieved pages and tool results in the documents array of shieldPrompt, not in userPrompt, so document attacks are reported separately
  2. Call text:shieldPrompt over REST with api-version=2024-09-01. The Python SDK 1.0.0 has no method for it
  3. Keep each request under 10,000 characters across prompt and documents, and split long tool results
  4. Create the resource in a region that lists Prompt Shields, since not every region has it
  5. On F0 you get 5 requests a second. Queue checks or move to S0 before load testing

Other comparisons with Amazon Bedrock Guardrails or Azure AI Content Safety (Prompt Shields)

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.