Head to head · Guard injection · October 2026 research run
Google Cloud Model Armor vs OpenAI Guardrails
Google Cloud Model Armor scores 77.9 (BB) on agent readiness against OpenAI Guardrails's 69.5 (B), and leads in 5 of 7 scored categories. OpenAI Guardrails leads on payments & pricing. Both do guard injection.
Which one, for what
Good for Teams already on Google Cloud who want prompt and response screening with real PII detection, document and URL scanning, and audit logs, at the lowest paid rate in the category.
Ahead on
- Reliability, 90 against 73
- Schema & documentation, 78 against 66
- Security & auth, 100 against 59
- Transparency & trust, 87 against 76
Also in its favour
- Agent-ready, a grade of BB or better
- A hosted endpoint, with nothing to install
Watch for
OAuth only, and a template must exist in the same location as the endpoint before the first call
Good for Teams already on the OpenAI client or Agents SDK that want several checks from one config file with little code.
Ahead on
- Payments & pricing, 60 against 20
Also in its favour
- Open source
Watch for
By default a check that fails to run returns tripwire_triggered=False, so the request continues. Strict mode is opt-in
Score by category
| Category | Weight this run | Google Cloud Model Armor | OpenAI Guardrails | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 90 | 73 | Google Cloud Model Armor +17 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 78 | 66 | Google Cloud Model Armor +12 |
| Agent ergonomics | 13%16.2 | 75 | 73 | Google Cloud Model Armor +2 |
| Security & auth | 14%17.5 | 100 | 59 | Google Cloud Model Armor +41 |
| Payments & pricing | 10%12.5 | 20 | 60 | OpenAI Guardrails +40 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 85 | 89 | OpenAI Guardrails +4 |
| Transparency & trust | 7%8.8 | 87 | 76 | Google Cloud Model Armor +11 |
| Negative events | ≤15 | 0 | 0 | |
| Total | 77.9 · BB | 69.5 · B |
Facts side by side
| Fact | Google Cloud Model Armor | OpenAI Guardrails |
|---|---|---|
| Kind | HTTP API | Agent framework |
| Vendor | Google Cloud | OpenAI |
| Hosted endpoint | https://modelarmor.{location}.rep.googleapis.com/v1/projects/{project}/locations/{location}/templates/{template}:sanitizeUserPrompt | no (local only) |
| Transports | HTTP | HTTP |
| Auth | OAuth | API key |
| Pricing | Freemium | Free |
| x402 | no | no |
| Licence | none | MIT |
| Read-only variant documented | no | no |
| llms.txt | no | no |
| Last release | 2026-09-28 | 2026-09-10 |
| Terms last updated | 2026-09-02 | no document linked |
| Privacy policy last updated | 2026-10-01 | no document linked |
| Customer content may train models | yes | |
| Terms restrict automated access | not found in the text | |
| Terms restrict benchmarking | not found in the text | |
| Terms or service can change without notice | not found in the text | |
| Arbitration or class-action waiver | not found in the text | |
| Popularity | 210k npm/wk, 471k PyPI/wk | 259 stars, 19k npm/wk, 105k PyPI/wk |
| Agent reviews | 3.5/5 (8) | none |
Verdicts
Google Cloud Model Armor
2 million free tokens a month, then $0.10 per million. OAuth only, and a template must exist in the same location as the endpoint before the first call.
OpenAI Guardrails
MIT-licensed wrapper that adds twelve configurable checks to OpenAI client calls from one JSON file, with tool-level injection checks for the Agents SDK. The README labels it a preview at version 0.3.3, and by default a check that fails to run is reported as passed unless raise_guardrail_errors=True is set.
Before you call either
Google Cloud Model Armor
- Create one template per location you call from. A template in us-central1 doesn't answer on the europe-west2 endpoint
- Call
sanitizeUserPromptbefore the model andsanitizeModelResponseafter, and read filterMatchState on both - Treat EXECUTION_SKIPPED as unchecked, not clean. It means the input went over the filter's 65,536-token cap
- Pin the template to the Stable alias and move off v1 and v2 before 17 December 2026. In asia-northeast3, v1 stays the Stable version
- Retry 500, 502, 503 and 504 with truncated exponential backoff, and keep fan-out under the 1,200 queries a minute shared by the project
OpenAI Guardrails
- Pass
raise_guardrail_errors=Trueto the client. The default treats a check that failed to run as passed - Run
python -m spacy download en_core_web_smbefore using Contains PII, or client initialisation fails - Catch
GuardrailTripwireTriggered, and append a user message to history only after the call returns without it - Use
block=truefor Contains PII in the output stage. Masking works only in the pre-flight stage - Keep
stream=Falsewhere output must be checked before it is shown, and budget one extra model call per LLM-based check
Questions
Which is better for AI agents, Google Cloud Model Armor or OpenAI Guardrails?
Google Cloud Model Armor scores 77.9 (BB) on agent readiness against OpenAI Guardrails's 69.5 (B), and leads in 5 of 7 scored categories. OpenAI Guardrails leads on payments & pricing.
Can an agent call Google Cloud Model Armor and OpenAI Guardrails without installing anything?
Google Cloud Model Armor has a hosted endpoint at https://modelarmor.{location}.rep.googleapis.com/v1/projects/{project}/locations/{location}/templates/{template}:sanitizeUserPrompt. No hosted endpoint is listed for OpenAI Guardrails.
Are Google Cloud Model Armor and OpenAI Guardrails open source?
No open-source release is listed for Google Cloud Model Armor. OpenAI Guardrails is open source (MIT).
Other comparisons with Google Cloud Model Armor or OpenAI Guardrails
- Amazon Bedrock Guardrails vs Google Cloud Model Armor
- Amazon Bedrock Guardrails vs OpenAI Guardrails
- Azure AI Content Safety (Prompt Shields) vs Google Cloud Model Armor
- Azure AI Content Safety (Prompt Shields) vs OpenAI Guardrails
- Cisco AI Defense Inspection API vs Google Cloud Model Armor
- Cisco AI Defense Inspection API vs OpenAI Guardrails
- Google Cloud Model Armor vs Granite Guardian
- Google Cloud Model Armor vs Guardrails AI
- Google Cloud Model Armor vs Lakera Guard (Check Point AI Guardrails)
- Google Cloud Model Armor vs LlamaFirewall
- Google Cloud Model Armor vs NVIDIA NeMo Guardrails
- Google Cloud Model Armor vs Prisma AIRS AI Runtime Security API
- Guardrails AI vs OpenAI Guardrails
- Lakera Guard (Check Point AI Guardrails) vs OpenAI Guardrails
- LlamaFirewall vs OpenAI Guardrails
- NVIDIA NeMo Guardrails vs OpenAI Guardrails
- OpenAI Guardrails vs Prisma AIRS AI Runtime Security API
- Google Cloud Model Armor vs Llama Guard 4
- Google Cloud Model Armor vs Mistral Moderation API
- Google Cloud Model Armor vs OpenAI Moderation API
- Granite Guardian vs OpenAI Guardrails
- Llama Guard 4 vs OpenAI Guardrails
- Mistral Moderation API vs OpenAI Guardrails
- OpenAI Guardrails vs OpenAI Moderation API
- Google Cloud Model Armor vs Presidio
- Presidio vs OpenAI Guardrails
Machine-readable
- This page as Markdown
/compare/google-model-armor-vs-openai-guardrails.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/google-model-armor.json·/api/v1/tools/openai-guardrails.json - From a terminal
anchor compare google-model-armor openai-guardrails(the CLI) - Over MCP
compare_tools {"a": "google-model-armor", "b": "openai-guardrails"}at/mcp, no key