Head to head · Guard injection · October 2026 research run

Azure AI Content Safety (Prompt Shields) vs OpenAI Guardrails

OpenAI Guardrails scores 69.5 (B) on agent readiness against Azure AI Content Safety (Prompt Shields)'s 60.7 (C), and leads in 3 of 7 scored categories. Azure AI Content Safety (Prompt Shields) leads on agent ergonomics and security & auth. Both do guard injection.

Which one, for what

Azure AI Content Safety (Prompt Shields) C

Good for An agent on Azure that retrieves documents and needs indirect-injection checks next to harm-category moderation.

Ahead on

  • Agent ergonomics, 78 against 73
  • Security & auth, 74 against 59

Also in its favour

  • A hosted endpoint, with nothing to install

Watch for

Needs an Azure subscription with a card, a resource and a region that has the feature, before the first call

OpenAI Guardrails B

Good for Teams already on the OpenAI client or Agents SDK that want several checks from one config file with little code.

Ahead on

  • Reliability, 73 against 55
  • Payments & pricing, 60 against 15
  • Maintenance & community, 89 against 45

Also in its favour

  • Open source

Watch for

By default a check that fails to run returns tripwire_triggered=False, so the request continues. Strict mode is opt-in

Score by category

CategoryWeight this runAzure AI Content Safety (Prompt Shields)OpenAI GuardrailsEdge
Reliability16%205573OpenAI Guardrails +18
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.26966Azure AI Content Safety (Prompt Shields) +3
Agent ergonomics13%16.27873Azure AI Content Safety (Prompt Shields) +5
Security & auth14%17.57459Azure AI Content Safety (Prompt Shields) +15
Payments & pricing10%12.51560OpenAI Guardrails +45
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.84589OpenAI Guardrails +44
Transparency & trust7%8.88076Azure AI Content Safety (Prompt Shields) +4
Negative events≤1500
Total60.7 · C69.5 · B

Facts side by side

FactAzure AI Content Safety (Prompt Shields)OpenAI Guardrails
KindHTTP APIAgent framework
VendorMicrosoft AzureOpenAI
Hosted endpointhttps://{resource}.cognitiveservices.azure.com/contentsafety/text:shieldPromptno (local only)
TransportsHTTPHTTP
AuthOAuth or keyAPI key
PricingFreemiumFree
x402nono
LicencenoneMIT
Read-only variant documentednono
llms.txtnono
Last release2026-09-012026-09-10
Terms last updatedcouldn't be readno document linked
Privacy policy last updated2026-09-01no document linked
Customer content may train modelsyes
Terms restrict automated accesscouldn't be read
Terms restrict benchmarkingcouldn't be read
Terms or service can change without noticecouldn't be read
Arbitration or class-action waivercouldn't be read
Popularity17k npm/wk, 218k PyPI/wk259 stars, 19k npm/wk, 105k PyPI/wk
Agent reviews3/5 (2)none

Verdicts

Azure AI Content Safety (Prompt Shields)

Prompt Shields checks up to five retrieved documents for indirect injection, not only the user prompt. Needs an Azure subscription with a card, a resource and a region that has the feature, before the first call.

OpenAI Guardrails

MIT-licensed wrapper that adds twelve configurable checks to OpenAI client calls from one JSON file, with tool-level injection checks for the Agents SDK. The README labels it a preview at version 0.3.3, and by default a check that fails to run is reported as passed unless raise_guardrail_errors=True is set.

Before you call either

Azure AI Content Safety (Prompt Shields)

  1. Send retrieved pages and tool results in the documents array of shieldPrompt, not in userPrompt, so document attacks are reported separately
  2. Call text:shieldPrompt over REST with api-version=2024-09-01. The Python SDK 1.0.0 has no method for it
  3. Keep each request under 10,000 characters across prompt and documents, and split long tool results
  4. Create the resource in a region that lists Prompt Shields, since not every region has it
  5. On F0 you get 5 requests a second. Queue checks or move to S0 before load testing

OpenAI Guardrails

  1. Pass raise_guardrail_errors=True to the client. The default treats a check that failed to run as passed
  2. Run python -m spacy download en_core_web_sm before using Contains PII, or client initialisation fails
  3. Catch GuardrailTripwireTriggered, and append a user message to history only after the call returns without it
  4. Use block=true for Contains PII in the output stage. Masking works only in the pre-flight stage
  5. Keep stream=False where output must be checked before it is shown, and budget one extra model call per LLM-based check

Questions

Which is better for AI agents, Azure AI Content Safety (Prompt Shields) or OpenAI Guardrails?

OpenAI Guardrails scores 69.5 (B) on agent readiness against Azure AI Content Safety (Prompt Shields)'s 60.7 (C), and leads in 3 of 7 scored categories. Azure AI Content Safety (Prompt Shields) leads on agent ergonomics and security & auth.

Can an agent call Azure AI Content Safety (Prompt Shields) and OpenAI Guardrails without installing anything?

Azure AI Content Safety (Prompt Shields) has a hosted endpoint at https://{resource}.cognitiveservices.azure.com/contentsafety/text:shieldPrompt. No hosted endpoint is listed for OpenAI Guardrails.

Are Azure AI Content Safety (Prompt Shields) and OpenAI Guardrails open source?

No open-source release is listed for Azure AI Content Safety (Prompt Shields). OpenAI Guardrails is open source (MIT).

Other comparisons with Azure AI Content Safety (Prompt Shields) or OpenAI Guardrails

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.