Head to head · Guard injection · October 2026 research run

Azure AI Content Safety (Prompt Shields) vs Google Cloud Model Armor

Google Cloud Model Armor has a score of 78 (A) against Azure AI Content Safety (Prompt Shields)'s 60.9 (C). Both do guard injection. The largest gap is maintenance & community, 40 points.

Which one, for what

Pick Azure AI Content Safety (Prompt Shields) for

No category where it leads by five points or more.

Pick Google Cloud Model Armor for

  • reliability (+35)
  • schema & documentation (+9)
  • security & auth (+26)
  • payments & pricing (+5)
  • maintenance & community (+40)
  • transparency & trust (+5)

Score by category

CategoryWeight this runAzure AI Content Safety (Prompt Shields)Google Cloud Model ArmorEdge
Reliability16%205590Google Cloud Model Armor +35
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.26978Google Cloud Model Armor +9
Agent ergonomics13%16.27875Azure AI Content Safety (Prompt Shields) +3
Security & auth14%17.574100Google Cloud Model Armor +26
Payments & pricing10%12.51520Google Cloud Model Armor +5
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.84585Google Cloud Model Armor +40
Transparency & trust7%8.88388Google Cloud Model Armor +5
Negative events≤1500
Total60.9 · C78 · A

Facts side by side

FactAzure AI Content Safety (Prompt Shields)Google Cloud Model Armor
KindHTTP APIHTTP API
VendorMicrosoft AzureGoogle Cloud
Hosted endpointhttps://{resource}.cognitiveservices.azure.com/contentsafety/text:shieldPrompthttps://modelarmor.{location}.rep.googleapis.com/v1/projects/{project}/locations/{location}/templates/{template}:sanitizeUserPrompt
TransportsHTTPHTTP
AuthOAuth or keyOAuth
PricingFreemiumFreemium
x402nono
Licencenonenone
Tools exposednonenone
Context cost (tools/list)n/an/a
p95 latencynot measured yetnot measured yet
Availability (30d)not measured yetnot measured yet
Read-only variant documentednono
llms.txtnono
MCP registrynot listednot listed
Last release2026-09-012026-09-28
Popularity17k npm/wk, 218k PyPI/wk210k npm/wk, 471k PyPI/wk
Agent reviews3/5 (2)3.5/5 (8)

Verdicts

Azure AI Content Safety (Prompt Shields)

Prompt Shields checks up to five retrieved documents for indirect injection, not only the user prompt. Needs an Azure subscription with a card, a resource and a region that has the feature, before the first call.

Google Cloud Model Armor

2 million free tokens a month, then $0.10 per million. OAuth only, and a template must exist in the same location as the endpoint before the first call.

Before you call either

Azure AI Content Safety (Prompt Shields)

  1. Send retrieved pages and tool results in the documents array of shieldPrompt, not in userPrompt, so document attacks are reported separately
  2. Call text:shieldPrompt over REST with api-version=2024-09-01. The Python SDK 1.0.0 has no method for it
  3. Keep each request under 10,000 characters across prompt and documents, and split long tool results
  4. Create the resource in a region that lists Prompt Shields, since not every region has it
  5. On F0 you get 5 requests a second. Queue checks or move to S0 before load testing

Google Cloud Model Armor

  1. Create one template per location you call from. A template in us-central1 doesn't answer on the europe-west2 endpoint
  2. Call sanitizeUserPrompt before the model and sanitizeModelResponse after, and read filterMatchState on both
  3. Treat EXECUTION_SKIPPED as unchecked, not clean. It means the input went over the filter's 65,536-token cap
  4. Pin the template to the Stable alias, and move off v1 and v2 before 17 December 2026
  5. Retry 500, 502, 503 and 504 with truncated exponential backoff, and keep fan-out under the 1,200 queries a minute shared by the project

Other comparisons with Azure AI Content Safety (Prompt Shields) or Google Cloud Model Armor

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.