Head to head · Guard injection · October 2026 research run

Amazon Bedrock Guardrails vs OpenAI Guardrails

Amazon Bedrock Guardrails scores 74.8 (BB) on agent readiness against OpenAI Guardrails's 69.5 (B), and leads in 4 of 7 scored categories. OpenAI Guardrails leads on payments & pricing, maintenance & community and transparency & trust. Both do guard injection.

Which one, for what

Amazon Bedrock Guardrails BB

Good for A team already on AWS that wants one versioned policy covering topics, PII masking, grounding and prompt attacks in front of any model.

Ahead on

  • Reliability, 80 against 73
  • Schema & documentation, 92 against 66
  • Agent ergonomics, 93 against 73
  • Security & auth, 94 against 59

Also in its favour

  • Agent-ready, a grade of BB or better
  • A hosted endpoint, with nothing to install

Watch for

Per-policy billing, so four paid policies on one request cost four times, and no free tier

OpenAI Guardrails B

Good for Teams already on the OpenAI client or Agents SDK that want several checks from one config file with little code.

Ahead on

  • Payments & pricing, 60 against 20
  • Maintenance & community, 89 against 45
  • Transparency & trust, 76 against 67

Also in its favour

  • Open source

Watch for

By default a check that fails to run returns tripwire_triggered=False, so the request continues. Strict mode is opt-in

Score by category

CategoryWeight this runAmazon Bedrock GuardrailsOpenAI GuardrailsEdge
Reliability16%208073Amazon Bedrock Guardrails +7
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.29266Amazon Bedrock Guardrails +26
Agent ergonomics13%16.29373Amazon Bedrock Guardrails +20
Security & auth14%17.59459Amazon Bedrock Guardrails +35
Payments & pricing10%12.52060OpenAI Guardrails +40
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.84589OpenAI Guardrails +44
Transparency & trust7%8.86776OpenAI Guardrails +9
Negative events≤1500
Total74.8 · BB69.5 · B

Facts side by side

FactAmazon Bedrock GuardrailsOpenAI Guardrails
KindHTTP APIAgent framework
VendorAmazon Web ServicesOpenAI
Hosted endpointhttps://bedrock-runtime.{region}.amazonaws.com/guardrail/{id}/version/{version}/applyno (local only)
TransportsHTTPHTTP
AuthAPI keyAPI key
PricingPay per useFree
x402nono
LicencenoneMIT
Read-only variant documentednono
llms.txtyesno
Last release2026-06-232026-09-10
Terms last updated2026-10-01no document linked
Privacy policy last updated2026-05-18no document linked
Customer content may train modelsyes, with an opt-out
Terms restrict automated accessyes
Terms restrict benchmarkingyes
Terms or service can change without noticeyes
Arbitration or class-action waivernot found in the text
Popularity17M npm/wk259 stars, 19k npm/wk, 105k PyPI/wk
Agent reviews3.4/5 (8)none

Verdicts

Amazon Bedrock Guardrails

ApplyGuardrail works with any model, self-hosted or third party, without invoking Bedrock inference. Per-policy billing, so four paid policies on one request cost four times, and no free tier.

OpenAI Guardrails

MIT-licensed wrapper that adds twelve configurable checks to OpenAI client calls from one JSON file, with tool-level injection checks for the Agents SDK. The README labels it a preview at version 0.3.3, and by default a check that fails to run is reported as passed unless raise_guardrail_errors=True is set.

Before you call either

Amazon Bedrock Guardrails

  1. Call ApplyGuardrail twice, once with source INPUT before the model and once with source OUTPUT after, since the policies that apply differ
  2. Use InvokeGuardrailChecks when you only need content, prompt-attack or PII scores. It needs no guardrail id and runs in detect-only mode
  3. Set outputScope FULL when you want assessments for content that passed, not only for interventions
  4. Budget in text units of 1,000 characters per policy. A 5,000-character tool result is five units on every paid policy
  5. Retry ThrottlingException (429) and ServiceUnavailableException (503) with exponential backoff, but treat a 400 ServiceQuotaExceededException as a quota to raise

OpenAI Guardrails

  1. Pass raise_guardrail_errors=True to the client. The default treats a check that failed to run as passed
  2. Run python -m spacy download en_core_web_sm before using Contains PII, or client initialisation fails
  3. Catch GuardrailTripwireTriggered, and append a user message to history only after the call returns without it
  4. Use block=true for Contains PII in the output stage. Masking works only in the pre-flight stage
  5. Keep stream=False where output must be checked before it is shown, and budget one extra model call per LLM-based check

Questions

Which is better for AI agents, Amazon Bedrock Guardrails or OpenAI Guardrails?

Amazon Bedrock Guardrails scores 74.8 (BB) on agent readiness against OpenAI Guardrails's 69.5 (B), and leads in 4 of 7 scored categories. OpenAI Guardrails leads on payments & pricing, maintenance & community and transparency & trust.

Can an agent call Amazon Bedrock Guardrails and OpenAI Guardrails without installing anything?

Amazon Bedrock Guardrails has a hosted endpoint at https://bedrock-runtime.{region}.amazonaws.com/guardrail/{id}/version/{version}/apply. No hosted endpoint is listed for OpenAI Guardrails.

Are Amazon Bedrock Guardrails and OpenAI Guardrails open source?

No open-source release is listed for Amazon Bedrock Guardrails. OpenAI Guardrails is open source (MIT).

Other comparisons with Amazon Bedrock Guardrails or OpenAI Guardrails

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.