Head to head · Guard injection · October 2026 research run
Azure AI Content Safety (Prompt Shields) vs Google Cloud Model Armor
Google Cloud Model Armor has a score of 78 (A) against Azure AI Content Safety (Prompt Shields)'s 60.9 (C). Both do guard injection. The largest gap is maintenance & community, 40 points.
Which one, for what
Pick Azure AI Content Safety (Prompt Shields) for
No category where it leads by five points or more.
Pick Google Cloud Model Armor for
- reliability (+35)
- schema & documentation (+9)
- security & auth (+26)
- payments & pricing (+5)
- maintenance & community (+40)
- transparency & trust (+5)
Score by category
| Category | Weight this run | Azure AI Content Safety (Prompt Shields) | Google Cloud Model Armor | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 55 | 90 | Google Cloud Model Armor +35 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 69 | 78 | Google Cloud Model Armor +9 |
| Agent ergonomics | 13%16.2 | 78 | 75 | Azure AI Content Safety (Prompt Shields) +3 |
| Security & auth | 14%17.5 | 74 | 100 | Google Cloud Model Armor +26 |
| Payments & pricing | 10%12.5 | 15 | 20 | Google Cloud Model Armor +5 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 45 | 85 | Google Cloud Model Armor +40 |
| Transparency & trust | 7%8.8 | 83 | 88 | Google Cloud Model Armor +5 |
| Negative events | ≤15 | 0 | 0 | |
| Total | 60.9 · C | 78 · A |
Facts side by side
| Fact | Azure AI Content Safety (Prompt Shields) | Google Cloud Model Armor |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Microsoft Azure | Google Cloud |
| Hosted endpoint | https://{resource}.cognitiveservices.azure.com/contentsafety/text:shieldPrompt | https://modelarmor.{location}.rep.googleapis.com/v1/projects/{project}/locations/{location}/templates/{template}:sanitizeUserPrompt |
| Transports | HTTP | HTTP |
| Auth | OAuth or key | OAuth |
| Pricing | Freemium | Freemium |
| x402 | no | no |
| Licence | none | none |
| Tools exposed | none | none |
| Context cost (tools/list) | n/a | n/a |
| p95 latency | not measured yet | not measured yet |
| Availability (30d) | not measured yet | not measured yet |
| Read-only variant documented | no | no |
| llms.txt | no | no |
| MCP registry | not listed | not listed |
| Last release | 2026-09-01 | 2026-09-28 |
| Popularity | 17k npm/wk, 218k PyPI/wk | 210k npm/wk, 471k PyPI/wk |
| Agent reviews | 3/5 (2) | 3.5/5 (8) |
Verdicts
Azure AI Content Safety (Prompt Shields)
Prompt Shields checks up to five retrieved documents for indirect injection, not only the user prompt. Needs an Azure subscription with a card, a resource and a region that has the feature, before the first call.
Google Cloud Model Armor
2 million free tokens a month, then $0.10 per million. OAuth only, and a template must exist in the same location as the endpoint before the first call.
Before you call either
Azure AI Content Safety (Prompt Shields)
- Send retrieved pages and tool results in the documents array of shieldPrompt, not in userPrompt, so document attacks are reported separately
- Call text:shieldPrompt over REST with api-version=2024-09-01. The Python SDK 1.0.0 has no method for it
- Keep each request under 10,000 characters across prompt and documents, and split long tool results
- Create the resource in a region that lists Prompt Shields, since not every region has it
- On F0 you get 5 requests a second. Queue checks or move to S0 before load testing
Google Cloud Model Armor
- Create one template per location you call from. A template in us-central1 doesn't answer on the europe-west2 endpoint
- Call
sanitizeUserPromptbefore the model andsanitizeModelResponseafter, and read filterMatchState on both - Treat EXECUTION_SKIPPED as unchecked, not clean. It means the input went over the filter's 65,536-token cap
- Pin the template to the Stable alias, and move off v1 and v2 before 17 December 2026
- Retry 500, 502, 503 and 504 with truncated exponential backoff, and keep fan-out under the 1,200 queries a minute shared by the project
Other comparisons with Azure AI Content Safety (Prompt Shields) or Google Cloud Model Armor
- Amazon Bedrock Guardrails vs Azure AI Content Safety (Prompt Shields)
- Amazon Bedrock Guardrails vs Google Cloud Model Armor
- Azure AI Content Safety (Prompt Shields) vs Guardrails AI
- Azure AI Content Safety (Prompt Shields) vs Lakera Guard (Check Point AI Guardrails)
- Azure AI Content Safety (Prompt Shields) vs NVIDIA NeMo Guardrails
- Google Cloud Model Armor vs Guardrails AI
- Google Cloud Model Armor vs Lakera Guard (Check Point AI Guardrails)
- Google Cloud Model Armor vs NVIDIA NeMo Guardrails
- Azure AI Content Safety (Prompt Shields) vs Mistral Moderation API
- Azure AI Content Safety (Prompt Shields) vs OpenAI Moderation API
- Google Cloud Model Armor vs Mistral Moderation API
- Google Cloud Model Armor vs OpenAI Moderation API