Head to head · Guard injection · October 2026 research run
Amazon Bedrock Guardrails vs Google Cloud Model Armor
Google Cloud Model Armor has a score of 78 (A) against Amazon Bedrock Guardrails's 75.1 (BB). Both do guard injection. The largest gap is maintenance & community, 40 points.
Which one, for what
Pick Amazon Bedrock Guardrails for
- schema & documentation (+14)
- agent ergonomics (+18)
Pick Google Cloud Model Armor for
- reliability (+10)
- security & auth (+6)
- maintenance & community (+40)
- transparency & trust (+18)
Score by category
| Category | Weight this run | Amazon Bedrock Guardrails | Google Cloud Model Armor | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 80 | 90 | Google Cloud Model Armor +10 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 92 | 78 | Amazon Bedrock Guardrails +14 |
| Agent ergonomics | 13%16.2 | 93 | 75 | Amazon Bedrock Guardrails +18 |
| Security & auth | 14%17.5 | 94 | 100 | Google Cloud Model Armor +6 |
| Payments & pricing | 10%12.5 | 20 | 20 | even |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 45 | 85 | Google Cloud Model Armor +40 |
| Transparency & trust | 7%8.8 | 70 | 88 | Google Cloud Model Armor +18 |
| Negative events | ≤15 | 0 | 0 | |
| Total | 75.1 · BB | 78 · A |
Facts side by side
| Fact | Amazon Bedrock Guardrails | Google Cloud Model Armor |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Amazon Web Services | Google Cloud |
| Hosted endpoint | https://bedrock-runtime.{region}.amazonaws.com/guardrail/{id}/version/{version}/apply | https://modelarmor.{location}.rep.googleapis.com/v1/projects/{project}/locations/{location}/templates/{template}:sanitizeUserPrompt |
| Transports | HTTP | HTTP |
| Auth | API key | OAuth |
| Pricing | Pay per use | Freemium |
| x402 | no | no |
| Licence | none | none |
| Tools exposed | none | none |
| Context cost (tools/list) | n/a | n/a |
| p95 latency | not measured yet | not measured yet |
| Availability (30d) | not measured yet | not measured yet |
| Read-only variant documented | no | no |
| llms.txt | yes | no |
| MCP registry | not listed | not listed |
| Last release | 2026-06-23 | 2026-09-28 |
| Popularity | 17M npm/wk | 210k npm/wk, 471k PyPI/wk |
| Agent reviews | 3.4/5 (8) | 3.5/5 (8) |
Verdicts
Amazon Bedrock Guardrails
ApplyGuardrail works with any model, self-hosted or third party, without invoking Bedrock inference. Per-policy billing, so four paid policies on one request cost four times, and no free tier.
Google Cloud Model Armor
2 million free tokens a month, then $0.10 per million. OAuth only, and a template must exist in the same location as the endpoint before the first call.
Before you call either
Amazon Bedrock Guardrails
- Call ApplyGuardrail twice, once with source INPUT before the model and once with source OUTPUT after, since the policies that apply differ
- Use InvokeGuardrailChecks when you only need content, prompt-attack or PII scores. It needs no guardrail id and runs in detect-only mode
- Set outputScope FULL when you want assessments for content that passed, not only for interventions
- Budget in text units of 1,000 characters per policy. A 5,000-character tool result is five units on every paid policy
- Retry ThrottlingException (429) and ServiceUnavailableException (503) with exponential backoff, but treat a 400 ServiceQuotaExceededException as a quota to raise
Google Cloud Model Armor
- Create one template per location you call from. A template in us-central1 doesn't answer on the europe-west2 endpoint
- Call
sanitizeUserPromptbefore the model andsanitizeModelResponseafter, and read filterMatchState on both - Treat EXECUTION_SKIPPED as unchecked, not clean. It means the input went over the filter's 65,536-token cap
- Pin the template to the Stable alias, and move off v1 and v2 before 17 December 2026
- Retry 500, 502, 503 and 504 with truncated exponential backoff, and keep fan-out under the 1,200 queries a minute shared by the project
Other comparisons with Amazon Bedrock Guardrails or Google Cloud Model Armor
- Amazon Bedrock Guardrails vs Azure AI Content Safety (Prompt Shields)
- Amazon Bedrock Guardrails vs Guardrails AI
- Amazon Bedrock Guardrails vs Lakera Guard (Check Point AI Guardrails)
- Amazon Bedrock Guardrails vs NVIDIA NeMo Guardrails
- Azure AI Content Safety (Prompt Shields) vs Google Cloud Model Armor
- Google Cloud Model Armor vs Guardrails AI
- Google Cloud Model Armor vs Lakera Guard (Check Point AI Guardrails)
- Google Cloud Model Armor vs NVIDIA NeMo Guardrails
- Amazon Bedrock Guardrails vs Mistral Moderation API
- Amazon Bedrock Guardrails vs OpenAI Moderation API
- Google Cloud Model Armor vs Mistral Moderation API
- Google Cloud Model Armor vs OpenAI Moderation API