{
  "data": {
    "a": {
      "slug": "granite-guardian",
      "name": "Granite Guardian",
      "vendor": "IBM",
      "vendorUrl": "https://www.ibm.com/granite",
      "kind": "model",
      "category": "guardrails",
      "summary": "Granite Guardian is IBM's family of open-weight judge models. The current 8-billion-parameter release answers yes or no on whether a prompt, response, retrieved context or function call meets a built-in or custom criterion, and the owner runs it.",
      "url": "https://www.anchorterminal.com/tools/granite-guardian",
      "markdownUrl": "https://www.anchorterminal.com/tools/granite-guardian.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/granite-guardian.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/granite-guardian.json",
      "repo": "https://github.com/ibm-granite/granite-guardian",
      "license": "Apache 2.0 for the weights and the repository",
      "transports": [
        "http"
      ],
      "packages": [],
      "auth": "none",
      "authNotes": "No account or key is needed to download or run the model. The Hugging Face repository is not gated. A vLLM or Ollama server has whatever authentication the owner adds.",
      "pricing": "free",
      "pricingNotes": "Free to download and run under the Apache 2.0 licence, with the owner's hardware as the cost. IBM's watsonx.ai lists only the earlier `ibm/granite-guardian-3-8b`, marked deprecated, at $0.0002 per 1,000 input or output tokens (checked 2026-10-08). Version 4.1 is not on that list.",
      "priceSummary": "Free",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402. Granite Guardian is a model the owner runs, with no payment route (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 182,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://www.ibm.com/granite/docs/models/guardian",
      "capabilities": [
        "guard.moderation",
        "guard.policy",
        "guard.injection",
        "guard.self-host"
      ],
      "tags": [
        "model",
        "open-weights",
        "self-hosted",
        "local",
        "free",
        "apache-2.0",
        "judge",
        "rag",
        "python",
        "ollama"
      ],
      "lastRelease": "2026-04-29",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60.1,
        "grade": "C",
        "agentReady": false,
        "rank": 478,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 69,
          "maintenance": 47,
          "payments": 60,
          "reliability": 56,
          "schema": 60,
          "security": 58,
          "transparency": 70
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "One ungated Apache 2.0 model judges harm, jailbreaks, RAG groundedness, function-call errors and custom criteria, with signed weights and published evaluation code. It is trained and tested on English only, each call checks one criterion, the 4.1 prompt format differs from 3.x, and IBM's watsonx.ai lists only the deprecated 3.0 model.",
        "bestFor": "A team with a GPU that wants one English-language judge for harm, jailbreaks, RAG groundedness, function-call checks and house rules, under a permissive licence with no gate.",
        "strengths": [
          "Weights are ungated on Hugging Face under the Apache 2.0 licence, with IBM's own GGUF builds and an Ollama library entry",
          "Built-in criteria cover harm, social bias, jailbreaking, violence, profanity, sexual content, unethical behaviour, three RAG checks and function-call hallucination",
          "A custom criterion is one natural-language sentence in the prompt, and the answer is `yes` or `no` inside `\u003cscore\u003e` tags",
          "The repository's `evaluation` folder reproduces the card's benchmark figures for versions 3.0 to 4.1",
          "Weights carry a sigstore signature in `model.sig`, and IBM documents how to verify it"
        ],
        "weaknesses": [
          "Trained and tested on English only, per the model card",
          "Each call judges one criterion, so checking several risks takes several calls or a separate LoRA adapter built on the 3.2 model",
          "Version 4.1 moved the criterion into a `\u003cguardian\u003e` block in the last user message, where 3.x cookbooks pass `guardian_config`",
          "The repository has no CI, no tests and no `SECURITY.md`, and an issue asking for one has been open since 9 February 2025",
          "The card's out-of-distribution safety F1 is 0.79 without thinking, below the 0.81 it reports for version 3.3",
          "IBM's watsonx.ai model list has only `ibm/granite-guardian-3-8b`, marked deprecated, so 4.1 has no hosted endpoint from IBM that we found"
        ],
        "agentNotes": [
          "Append the `\u003cguardian\u003e` block as the final user message, with the mode line, `### Criteria:` and `### Scoring Schema:`. Copy the strings from the model card, because no package builds them",
          "Use the no-think instruction for gating and parse `\u003cscore\u003e`. Think mode writes a reasoning trace first, and the card's examples allow up to 2,048 output tokens",
          "Treat `yes` as the criterion being met, which for built-in criteria means the risk is present. Treat a missing `\u003cscore\u003e` tag as a failed check",
          "Pass retrieved text through `documents=` and tool schemas through `available_tools=` in `apply_chat_template`, not inside the message text",
          "Under Ollama, set `num_ctx` in the request options. IBM's docs say the default context is short and long requests are truncated"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60.1
          }
        ],
        "editorialScores": {
          "ergonomics": 69,
          "maintenance": 47,
          "payments": 60,
          "reliability": 56,
          "schema": 60,
          "security": 58,
          "transparency": 67
        },
        "provenanceScore": 73
      },
      "connect": {
        "install": "pip install transformers torch vllm",
        "http": "curl http://localhost:11434/api/chat \\\n  -d '{\"model\": \"granite4.1-guardian:8b\", \"messages\": [{\"role\": \"user\", \"content\": \"Hello!\"}]}'"
      },
      "letme": {
        "capability": "https://letme.dev/guard.moderation",
        "tool": "https://letme.dev/granite-guardian"
      },
      "area": "models",
      "provenance": {
        "legalEntity": "International Business Machines Corporation",
        "domain": "ibm.com",
        "domainRegistered": "1986-03-19",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "IBM's naming guidance for Granite names International Business Machines Corporation as the developer and trademark owner.",
          "The Apache 2.0 licence in the repository is the document that governs use of the weights, so it is recorded as the terms. The Hugging Face repository declares the same licence in its metadata and has no licence file of its own.",
          "No privacy policy governs the model, because the owner runs it and no input reaches IBM. The privacy field is left out.",
          "www.ibm.com/.well-known/security.txt is present with PSIRT, HackerOne and email contacts and expires on 8 November 2026.",
          "RDAP gives 19 March 1986 as the registration date of ibm.com.",
          "IBM hosts no endpoint for version 4.1 that we found, so there is no status page. The repository has no changelog file. Dated notes sit in the README under What's New.",
          "Weights are on huggingface.co under the ibm-granite organisation and the code is at github.com/ibm-granite/granite-guardian, both off ibm.com."
        ],
        "score": 73
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/granite-guardian.json"
    },
    "answer": "Granite Guardian scores 60.1 (C) on agent readiness against Guardrails AI's 49.6 (D), and leads in 5 of 7 scored categories.",
    "b": {
      "slug": "guardrails-ai",
      "name": "Guardrails AI",
      "vendor": "Guardrails AI (Harvey)",
      "vendorUrl": "https://www.guardrailsai.com",
      "kind": "framework",
      "category": "guardrails",
      "summary": "Open-source Python framework for validating LLM inputs and outputs, with configurable actions for failed checks and an API server.",
      "url": "https://www.anchorterminal.com/tools/guardrails-ai",
      "markdownUrl": "https://www.anchorterminal.com/tools/guardrails-ai.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/guardrails-ai.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/guardrails-ai.json",
      "repo": "https://github.com/guardrails-ai/guardrails",
      "license": "Apache-2.0",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "pypi",
          "name": "guardrails-ai"
        },
        {
          "registry": "npm",
          "name": "@guardrails-ai/core"
        }
      ],
      "auth": "none",
      "authNotes": "None of its own since the Hub closed. Validators install from public PyPI as `guardrails-ai-\u003cname\u003e` with no `guardrails configure` step, and the models behind them run locally or on an endpoint you host. The server has no built-in auth.",
      "pricing": "free",
      "pricingNotes": "Apache-2.0 library and server. The hosted remote inference that some validators used (detect_pii, toxic_language, competitor_check, nsfw_text) was free and was switched off on 2026-08-25, so those validators now cost whatever it takes to run their models yourself with use_local=True or on your own endpoint (https://github.com/guardrails-ai/guardrails/blob/main/HUB_UPDATE.md).",
      "priceSummary": "Free · OSS",
      "where": "library",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 7300,
        "npmWeekly": 81,
        "pypiWeekly": 32438,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://www.guardrailsai.com/docs",
      "capabilities": [
        "guard.injection",
        "guard.pii",
        "guard.moderation",
        "guard.policy",
        "guard.self-host"
      ],
      "tags": [
        "framework",
        "open-source",
        "self-hosted",
        "local",
        "python",
        "free",
        "openai-compatible",
        "incidents"
      ],
      "lastRelease": "2026-08-14",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 49.6,
        "grade": "D",
        "agentReady": false,
        "rank": 701,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 14,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 63,
          "maintenance": 44,
          "payments": 60,
          "reliability": 58,
          "schema": 59,
          "security": 44,
          "transparency": 59
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -6,
        "negativeNotes": [
          "2026-05-11 supply-chain compromise. An attacker used an employee's GitHub token to run Actions across 30 repositories, took deploy secrets and published a malicious guardrails-ai 0.10.1 to PyPI. Quarantined in about two hours, tokens rotated, Hub and Snowglobe keys force-rotated on 13 May, and a full advisory published telling anyone who installed 0.10.1 to treat the host as compromised. Fixed and documented, so partly decayed (-6). https://github.com/guardrails-ai/guardrails/blob/main/SECURITY_ADVISORY.md"
        ],
        "verdict": "Validators have configurable actions for failed checks. Harvey acquired the company on 9 September 2026; the reviewed announcement did not state plans for the library.",
        "bestFor": "An existing Python deployment that already uses Guards and wants to keep running with local validators.",
        "strengths": [
          "Guard and validator API that reads well, with an on_fail action per validator",
          "Validators are plain PyPI packages, from PII and toxicity to schema and competitor checks",
          "Guardrails Server turns a guard into an OpenAI-compatible endpoint any client can point at",
          "Full public advisory after the May 2026 incident, with the attack chain and rotation steps",
          "Apache-2.0 with nothing to buy"
        ],
        "weaknesses": [
          "Acquired by Harvey on 9 September 2026 with no statement on the library",
          "Hub, private registry and hosted inference closed on 25 August 2026, so model-backed validators need your own compute",
          "Malicious 0.10.1 release on PyPI in May 2026 from a compromised token",
          "0.11.0 has no release notes on GitHub, and open 1.0.0 issues plan to remove reask, on_fail and RAIL",
          "Metrics on by default in the client config"
        ],
        "agentNotes": [
          "Pin guardrails-ai==0.11.0 and each guardrails-ai-\u003cvalidator\u003e package, install only from PyPI, and never install 0.10.1",
          "Import validators from guardrails_ai.\u003cname\u003e, not guardrails.hub, and don't run guardrails hub install",
          "Pass use_local=True to detect_pii, toxic_language and the other model-backed validators, or set validation_endpoint to a server you run",
          "Set enable_metrics to false in ~/.guardrailsrc if you don't want usage metrics sent",
          "Avoid building on reask and RAIL. The open 1.0.0 issues plan to remove both"
        ],
        "metrics": {
          "kind": "library",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 49.6
          }
        ],
        "editorialScores": {
          "ergonomics": 63,
          "maintenance": 44,
          "payments": 60,
          "reliability": 58,
          "schema": 59,
          "security": 44,
          "transparency": 63
        },
        "provenanceScore": 55
      },
      "connect": {
        "install": "pip install guardrails-ai==0.11.0 guardrails-ai-detect-pii   # validators are plain PyPI packages since 2026-08-25",
        "http": "curl -X POST http://localhost:8000/guards/my_guard/openai/v1/chat/completions \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"model\":\"gpt-4o-mini\",\"messages\":[{\"role\":\"user\",\"content\":\"My card number is 4111 1111 1111 1111, is that safe to share?\"}]}'"
      },
      "letme": {
        "capability": "https://letme.dev/guard.injection",
        "tool": "https://letme.dev/guardrails-ai"
      },
      "area": "models",
      "provenance": {
        "legalEntity": "Guardrails AI, Inc.",
        "domain": "guardrailsai.com",
        "domainRegistered": "",
        "domainNote": "A library. The code is on github.com under guardrails-ai and the packages on PyPI. The company is now part of Harvey (harvey.ai).",
        "endpointOnVendorDomain": null,
        "terms": "https://guardrailsai.com/legal/terms-of-use",
        "privacy": "https://guardrailsai.com/legal/privacy-policy",
        "statusPage": "",
        "changelog": "https://github.com/guardrails-ai/guardrails/releases",
        "securityTxt": "unknown",
        "checked": "2026-09-30",
        "notes": [
          "The terms of use (last updated 2025-08-14) name Guardrails AI, Inc. and predate the Harvey acquisition. The site banner reads Guardrails AI joins Harvey.",
          "The advisory names Snowglobe, a sister product whose keys were rotated after the May 2026 incident."
        ],
        "score": 55
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/guardrails-ai.json",
      "live": {
        "slug": "guardrails-ai",
        "versions": [
          {
            "registry": "github",
            "name": "guardrails-ai/guardrails",
            "version": "v0.11.0",
            "released": "2026-08-14",
            "seenAt": "2026-10-08T16:15:19.191244231Z"
          },
          {
            "registry": "npm",
            "name": "@guardrails-ai/core",
            "version": "0.1.1",
            "seenAt": "2026-10-08T16:15:15.58617083Z"
          },
          {
            "registry": "pypi",
            "name": "guardrails-ai",
            "version": "0.11.0",
            "released": "2026-08-14",
            "seenAt": "2026-10-08T16:15:15.387166124Z"
          }
        ],
        "githubStars": 7497,
        "npmWeekly": 80,
        "pypiWeekly": 23079,
        "securityTxt": {
          "url": "https://guardrailsai.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:41.243240106Z"
        },
        "domain": {
          "domain": "guardrailsai.com",
          "registered": "2023-03-30",
          "source": "https://rdap.verisign.com/com/v1/domain/guardrailsai.com",
          "checkedAt": "2026-10-04T13:05:34.738860824Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/guardrails-ai/guardrails/main/HUB_UPDATE.md",
            "kind": "deprecations",
            "status": 304,
            "checkedAt": "2026-10-08T18:24:19.873781681Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "346e78b2231d"
          },
          {
            "url": "https://www.harvey.ai/blog/guardrails-ai-joins-harvey",
            "kind": "deprecations",
            "status": 200,
            "checkedAt": "2026-10-08T18:28:06.891800962Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "ac8d49a8249b"
          },
          {
            "url": "https://guardrailsai.com/legal/privacy-policy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-08T18:20:45.234159968Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "9ee9470cc655"
          },
          {
            "url": "https://guardrailsai.com/legal/terms-of-use",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-08T18:20:47.471339395Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e46fda5fa053"
          }
        ],
        "updatedAt": "2026-10-08T18:28:06.891800962Z"
      }
    },
    "facts": [
      {
        "a": "Model API",
        "b": "Agent framework",
        "name": "Kind"
      },
      {
        "a": "IBM",
        "b": "Guardrails AI (Harvey)",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "None",
        "b": "None",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Apache 2.0 for the weights and the repository",
        "b": "Apache-2.0",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-04-29",
        "b": "2026-08-14",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "2025-08-14",
        "name": "Terms last updated"
      },
      {
        "a": "no document linked",
        "b": "2025-05-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "182 stars",
        "b": "7.3k stars, 81 npm/wk, 32k PyPI/wk",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "2/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Granite Guardian scores 60.1 (C) on agent readiness against Guardrails AI's 49.6 (D), and leads in 5 of 7 scored categories.",
        "question": "Which is better for AI agents, Granite Guardian or Guardrails AI?"
      },
      {
        "answer": "No hosted endpoint is listed for Granite Guardian. No hosted endpoint is listed for Guardrails AI.",
        "question": "Can an agent call Granite Guardian and Guardrails AI without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Granite Guardian. Guardrails AI is open source (Apache-2.0).",
        "question": "Are Granite Guardian and Guardrails AI open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Agent ergonomics, 69 against 63",
          "Security \u0026 auth, 58 against 44",
          "Transparency \u0026 trust, 70 against 59"
        ],
        "also": [
          "No incidents deducted, where Guardrails AI loses 6 points for them"
        ],
        "goodFor": "A team with a GPU that wants one English-language judge for harm, jailbreaks, RAG groundedness, function-call checks and house rules, under a permissive licence with no gate.",
        "slug": "granite-guardian",
        "watchFor": "Trained and tested on English only, per the model card"
      },
      {
        "aheadOn": null,
        "also": [
          "Open source"
        ],
        "goodFor": "An existing Python deployment that already uses Guards and wants to keep running with local validators.",
        "slug": "guardrails-ai",
        "watchFor": "Acquired by Harvey on 9 September 2026 with no statement on the library"
      }
    ],
    "job": {
      "capability": "guard.moderation",
      "name": "Guard moderation"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/amazon-bedrock-guardrails-vs-granite-guardian.json",
        "title": "Amazon Bedrock Guardrails vs Granite Guardian",
        "url": "https://www.anchorterminal.com/compare/amazon-bedrock-guardrails-vs-granite-guardian"
      },
      {
        "json": "https://www.anchorterminal.com/compare/amazon-bedrock-guardrails-vs-guardrails-ai.json",
        "title": "Amazon Bedrock Guardrails vs Guardrails AI",
        "url": "https://www.anchorterminal.com/compare/amazon-bedrock-guardrails-vs-guardrails-ai"
      },
      {
        "json": "https://www.anchorterminal.com/compare/azure-ai-content-safety-vs-granite-guardian.json",
        "title": "Azure AI Content Safety (Prompt Shields) vs Granite Guardian",
        "url": "https://www.anchorterminal.com/compare/azure-ai-content-safety-vs-granite-guardian"
      },
      {
        "json": "https://www.anchorterminal.com/compare/azure-ai-content-safety-vs-guardrails-ai.json",
        "title": "Azure AI Content Safety (Prompt Shields) vs Guardrails AI",
        "url": "https://www.anchorterminal.com/compare/azure-ai-content-safety-vs-guardrails-ai"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-granite-guardian.json",
        "title": "Cisco AI Defense Inspection API vs Granite Guardian",
        "url": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-granite-guardian"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-guardrails-ai.json",
        "title": "Cisco AI Defense Inspection API vs Guardrails AI",
        "url": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-guardrails-ai"
      },
      {
        "json": "https://www.anchorterminal.com/compare/google-model-armor-vs-granite-guardian.json",
        "title": "Google Cloud Model Armor vs Granite Guardian",
        "url": "https://www.anchorterminal.com/compare/google-model-armor-vs-granite-guardian"
      },
      {
        "json": "https://www.anchorterminal.com/compare/google-model-armor-vs-guardrails-ai.json",
        "title": "Google Cloud Model Armor vs Guardrails AI",
        "url": "https://www.anchorterminal.com/compare/google-model-armor-vs-guardrails-ai"
      },
      {
        "json": "https://www.anchorterminal.com/compare/granite-guardian-vs-llamafirewall.json",
        "title": "Granite Guardian vs LlamaFirewall",
        "url": "https://www.anchorterminal.com/compare/granite-guardian-vs-llamafirewall"
      },
      {
        "json": "https://www.anchorterminal.com/compare/guardrails-ai-vs-lakera-guard.json",
        "title": "Guardrails AI vs Lakera Guard (Check Point AI Guardrails)",
        "url": "https://www.anchorterminal.com/compare/guardrails-ai-vs-lakera-guard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/guardrails-ai-vs-llamafirewall.json",
        "title": "Guardrails AI vs LlamaFirewall",
        "url": "https://www.anchorterminal.com/compare/guardrails-ai-vs-llamafirewall"
      },
      {
        "json": "https://www.anchorterminal.com/compare/guardrails-ai-vs-nemo-guardrails.json",
        "title": "Guardrails AI vs NVIDIA NeMo Guardrails",
        "url": "https://www.anchorterminal.com/compare/guardrails-ai-vs-nemo-guardrails"
      },
      {
        "json": "https://www.anchorterminal.com/compare/guardrails-ai-vs-openai-guardrails.json",
        "title": "Guardrails AI vs OpenAI Guardrails",
        "url": "https://www.anchorterminal.com/compare/guardrails-ai-vs-openai-guardrails"
      },
      {
        "json": "https://www.anchorterminal.com/compare/guardrails-ai-vs-prisma-airs.json",
        "title": "Guardrails AI vs Prisma AIRS AI Runtime Security API",
        "url": "https://www.anchorterminal.com/compare/guardrails-ai-vs-prisma-airs"
      },
      {
        "json": "https://www.anchorterminal.com/compare/granite-guardian-vs-lakera-guard.json",
        "title": "Granite Guardian vs Lakera Guard (Check Point AI Guardrails)",
        "url": "https://www.anchorterminal.com/compare/granite-guardian-vs-lakera-guard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/granite-guardian-vs-llama-guard.json",
        "title": "Granite Guardian vs Llama Guard 4",
        "url": "https://www.anchorterminal.com/compare/granite-guardian-vs-llama-guard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/granite-guardian-vs-mistral-moderation.json",
        "title": "Granite Guardian vs Mistral Moderation API",
        "url": "https://www.anchorterminal.com/compare/granite-guardian-vs-mistral-moderation"
      },
      {
        "json": "https://www.anchorterminal.com/compare/granite-guardian-vs-nemo-guardrails.json",
        "title": "Granite Guardian vs NVIDIA NeMo Guardrails",
        "url": "https://www.anchorterminal.com/compare/granite-guardian-vs-nemo-guardrails"
      },
      {
        "json": "https://www.anchorterminal.com/compare/granite-guardian-vs-openai-guardrails.json",
        "title": "Granite Guardian vs OpenAI Guardrails",
        "url": "https://www.anchorterminal.com/compare/granite-guardian-vs-openai-guardrails"
      },
      {
        "json": "https://www.anchorterminal.com/compare/granite-guardian-vs-openai-moderation.json",
        "title": "Granite Guardian vs OpenAI Moderation API",
        "url": "https://www.anchorterminal.com/compare/granite-guardian-vs-openai-moderation"
      },
      {
        "json": "https://www.anchorterminal.com/compare/granite-guardian-vs-prisma-airs.json",
        "title": "Granite Guardian vs Prisma AIRS AI Runtime Security API",
        "url": "https://www.anchorterminal.com/compare/granite-guardian-vs-prisma-airs"
      },
      {
        "json": "https://www.anchorterminal.com/compare/guardrails-ai-vs-llama-guard.json",
        "title": "Guardrails AI vs Llama Guard 4",
        "url": "https://www.anchorterminal.com/compare/guardrails-ai-vs-llama-guard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/guardrails-ai-vs-mistral-moderation.json",
        "title": "Guardrails AI vs Mistral Moderation API",
        "url": "https://www.anchorterminal.com/compare/guardrails-ai-vs-mistral-moderation"
      },
      {
        "json": "https://www.anchorterminal.com/compare/guardrails-ai-vs-openai-moderation.json",
        "title": "Guardrails AI vs OpenAI Moderation API",
        "url": "https://www.anchorterminal.com/compare/guardrails-ai-vs-openai-moderation"
      },
      {
        "json": "https://www.anchorterminal.com/compare/guardrails-ai-vs-microsoft-presidio.json",
        "title": "Guardrails AI vs Presidio",
        "url": "https://www.anchorterminal.com/compare/guardrails-ai-vs-microsoft-presidio"
      },
      {
        "json": "https://www.anchorterminal.com/compare/granite-guardian-vs-microsoft-presidio.json",
        "title": "Granite Guardian vs Presidio",
        "url": "https://www.anchorterminal.com/compare/granite-guardian-vs-microsoft-presidio"
      }
    ],
    "scores": [
      {
        "by": 2,
        "edge": "guardrails-ai",
        "granite-guardian": 56,
        "guardrails-ai": 58,
        "key": "reliability",
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 1,
        "edge": "granite-guardian",
        "granite-guardian": 60,
        "guardrails-ai": 59,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 6,
        "edge": "granite-guardian",
        "granite-guardian": 69,
        "guardrails-ai": 63,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 14,
        "edge": "granite-guardian",
        "granite-guardian": 58,
        "guardrails-ai": 44,
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 0,
        "edge": "",
        "granite-guardian": 60,
        "guardrails-ai": 60,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 3,
        "edge": "granite-guardian",
        "granite-guardian": 47,
        "guardrails-ai": 44,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 11,
        "edge": "granite-guardian",
        "granite-guardian": 70,
        "guardrails-ai": 59,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Granite Guardian scores 60.1 (C) on agent readiness against Guardrails AI's 49.6 (D), and leads in 5 of 7 scored categories. Both do guard moderation.",
    "verdicts": {
      "granite-guardian": "One ungated Apache 2.0 model judges harm, jailbreaks, RAG groundedness, function-call errors and custom criteria, with signed weights and published evaluation code. It is trained and tested on English only, each call checks one criterion, the 4.1 prompt format differs from 3.x, and IBM's watsonx.ai lists only the deprecated 3.0 model.",
      "guardrails-ai": "Validators have configurable actions for failed checks. Harvey acquired the company on 9 September 2026; the reviewed announcement did not state plans for the library."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/granite-guardian-vs-guardrails-ai",
    "json": "https://www.anchorterminal.com/compare/granite-guardian-vs-guardrails-ai.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/granite-guardian-vs-guardrails-ai.md",
    "slim": "https://www.anchorterminal.com/compare/granite-guardian-vs-guardrails-ai.min.md"
  },
  "markdown": "Granite Guardian scores 60.1 (C) on agent readiness against Guardrails AI's 49.6 (D), and leads in 5 of 7 scored categories. Both do guard moderation.\n\n- Granite Guardian: grade C, 60.1/100, rank #478 of 842. Markdown https://www.anchorterminal.com/tools/granite-guardian.md · JSON https://www.anchorterminal.com/api/v1/tools/granite-guardian.json\n- Guardrails AI: grade D, 49.6/100, rank #701 of 842. Markdown https://www.anchorterminal.com/tools/guardrails-ai.md · JSON https://www.anchorterminal.com/api/v1/tools/guardrails-ai.json\n\n## Which one, for what\n\n### Granite Guardian (C)\n\nGood for: A team with a GPU that wants one English-language judge for harm, jailbreaks, RAG groundedness, function-call checks and house rules, under a permissive licence with no gate.\n\nAhead on:\n- Agent ergonomics, 69 against 63\n- Security \u0026 auth, 58 against 44\n- Transparency \u0026 trust, 70 against 59\n\nAlso in its favour:\n- No incidents deducted, where Guardrails AI loses 6 points for them\n\nWatch for: Trained and tested on English only, per the model card\n\n### Guardrails AI (D)\n\nGood for: An existing Python deployment that already uses Guards and wants to keep running with local validators.\n\nAlso in its favour:\n- Open source\n\nWatch for: Acquired by Harvey on 9 September 2026 with no statement on the library\n\n\n## Score by category\n\n| Category | Weight | Granite Guardian | Guardrails AI | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 56 | 58 | Guardrails AI +2 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 60 | 59 | Granite Guardian +1 |\n| Agent ergonomics | 13% (16.2 this run) | 69 | 63 | Granite Guardian +6 |\n| Security \u0026 auth | 14% (17.5 this run) | 58 | 44 | Granite Guardian +14 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 60 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 47 | 44 | Granite Guardian +3 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 70 | 59 | Granite Guardian +11 |\n| Negative events | ≤15 | 0 | -6 | |\n| **Total** | | **60.1 · C** | **49.6 · D** | |\n\n## Facts side by side\n\n| Fact | Granite Guardian | Guardrails AI |\n| --- | --- | --- |\n| Kind | Model API | Agent framework |\n| Vendor | IBM | Guardrails AI (Harvey) |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | HTTP | HTTP |\n| Auth | None | None |\n| Pricing | Free | Free |\n| x402 | no | no |\n| Licence | Apache 2.0 for the weights and the repository | Apache-2.0 |\n| Read-only variant documented | no | no |\n| llms.txt | no | no |\n| Last release | 2026-04-29 | 2026-08-14 |\n| Terms last updated | no document linked | 2025-08-14 |\n| Privacy policy last updated | no document linked | 2025-05-01 |\n| Customer content may train models |  | not found in the text |\n| Terms restrict automated access |  | not found in the text |\n| Terms restrict benchmarking |  | not found in the text |\n| Terms or service can change without notice |  | not found in the text |\n| Arbitration or class-action waiver |  | yes |\n| Popularity | 182 stars | 7.3k stars, 81 npm/wk, 32k PyPI/wk |\n| Agent reviews | none | 2/5 (2) |\n\n## Verdicts\n\n**Granite Guardian.** One ungated Apache 2.0 model judges harm, jailbreaks, RAG groundedness, function-call errors and custom criteria, with signed weights and published evaluation code. It is trained and tested on English only, each call checks one criterion, the 4.1 prompt format differs from 3.x, and IBM's watsonx.ai lists only the deprecated 3.0 model.\n\n**Guardrails AI.** Validators have configurable actions for failed checks. Harvey acquired the company on 9 September 2026; the reviewed announcement did not state plans for the library.\n\n## Before you call either\n\n### Granite Guardian\n\n1. Append the `\u003cguardian\u003e` block as the final user message, with the mode line, `### Criteria:` and `### Scoring Schema:`. Copy the strings from the model card, because no package builds them\n2. Use the no-think instruction for gating and parse `\u003cscore\u003e`. Think mode writes a reasoning trace first, and the card's examples allow up to 2,048 output tokens\n3. Treat `yes` as the criterion being met, which for built-in criteria means the risk is present. Treat a missing `\u003cscore\u003e` tag as a failed check\n4. Pass retrieved text through `documents=` and tool schemas through `available_tools=` in `apply_chat_template`, not inside the message text\n5. Under Ollama, set `num_ctx` in the request options. IBM's docs say the default context is short and long requests are truncated\n\n### Guardrails AI\n\n1. Pin guardrails-ai==0.11.0 and each guardrails-ai-\u003cvalidator\u003e package, install only from PyPI, and never install 0.10.1\n2. Import validators from guardrails_ai.\u003cname\u003e, not guardrails.hub, and don't run guardrails hub install\n3. Pass use_local=True to detect_pii, toxic_language and the other model-backed validators, or set validation_endpoint to a server you run\n4. Set enable_metrics to false in ~/.guardrailsrc if you don't want usage metrics sent\n5. Avoid building on reask and RAIL. The open 1.0.0 issues plan to remove both\n\n## Questions\n\n### Which is better for AI agents, Granite Guardian or Guardrails AI?\n\nGranite Guardian scores 60.1 (C) on agent readiness against Guardrails AI's 49.6 (D), and leads in 5 of 7 scored categories.\n\n### Can an agent call Granite Guardian and Guardrails AI without installing anything?\n\nNo hosted endpoint is listed for Granite Guardian. No hosted endpoint is listed for Guardrails AI.\n\n### Are Granite Guardian and Guardrails AI open source?\n\nNo open-source release is listed for Granite Guardian. Guardrails AI is open source (Apache-2.0).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/granite-guardian-vs-guardrails-ai.json, and with the fewest tokens: https://www.anchorterminal.com/compare/granite-guardian-vs-guardrails-ai.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"granite-guardian\", \"b\": \"guardrails-ai\"}`. From a terminal: `anchor compare granite-guardian guardrails-ai`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/granite-guardian.json and https://www.anchorterminal.com/api/v1/tools/guardrails-ai.json\n\n## Other comparisons with Granite Guardian or Guardrails AI\n\n- [Amazon Bedrock Guardrails vs Granite Guardian](https://www.anchorterminal.com/compare/amazon-bedrock-guardrails-vs-granite-guardian.md)\n- [Amazon Bedrock Guardrails vs Guardrails AI](https://www.anchorterminal.com/compare/amazon-bedrock-guardrails-vs-guardrails-ai.md)\n- [Azure AI Content Safety (Prompt Shields) vs Granite Guardian](https://www.anchorterminal.com/compare/azure-ai-content-safety-vs-granite-guardian.md)\n- [Azure AI Content Safety (Prompt Shields) vs Guardrails AI](https://www.anchorterminal.com/compare/azure-ai-content-safety-vs-guardrails-ai.md)\n- [Cisco AI Defense Inspection API vs Granite Guardian](https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-granite-guardian.md)\n- [Cisco AI Defense Inspection API vs Guardrails AI](https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-guardrails-ai.md)\n- [Google Cloud Model Armor vs Granite Guardian](https://www.anchorterminal.com/compare/google-model-armor-vs-granite-guardian.md)\n- [Google Cloud Model Armor vs Guardrails AI](https://www.anchorterminal.com/compare/google-model-armor-vs-guardrails-ai.md)\n- [Granite Guardian vs LlamaFirewall](https://www.anchorterminal.com/compare/granite-guardian-vs-llamafirewall.md)\n- [Guardrails AI vs Lakera Guard (Check Point AI Guardrails)](https://www.anchorterminal.com/compare/guardrails-ai-vs-lakera-guard.md)\n- [Guardrails AI vs LlamaFirewall](https://www.anchorterminal.com/compare/guardrails-ai-vs-llamafirewall.md)\n- [Guardrails AI vs NVIDIA NeMo Guardrails](https://www.anchorterminal.com/compare/guardrails-ai-vs-nemo-guardrails.md)\n- [Guardrails AI vs OpenAI Guardrails](https://www.anchorterminal.com/compare/guardrails-ai-vs-openai-guardrails.md)\n- [Guardrails AI vs Prisma AIRS AI Runtime Security API](https://www.anchorterminal.com/compare/guardrails-ai-vs-prisma-airs.md)\n- [Granite Guardian vs Lakera Guard (Check Point AI Guardrails)](https://www.anchorterminal.com/compare/granite-guardian-vs-lakera-guard.md)\n- [Granite Guardian vs Llama Guard 4](https://www.anchorterminal.com/compare/granite-guardian-vs-llama-guard.md)\n- [Granite Guardian vs Mistral Moderation API](https://www.anchorterminal.com/compare/granite-guardian-vs-mistral-moderation.md)\n- [Granite Guardian vs NVIDIA NeMo Guardrails](https://www.anchorterminal.com/compare/granite-guardian-vs-nemo-guardrails.md)\n- [Granite Guardian vs OpenAI Guardrails](https://www.anchorterminal.com/compare/granite-guardian-vs-openai-guardrails.md)\n- [Granite Guardian vs OpenAI Moderation API](https://www.anchorterminal.com/compare/granite-guardian-vs-openai-moderation.md)\n- [Granite Guardian vs Prisma AIRS AI Runtime Security API](https://www.anchorterminal.com/compare/granite-guardian-vs-prisma-airs.md)\n- [Guardrails AI vs Llama Guard 4](https://www.anchorterminal.com/compare/guardrails-ai-vs-llama-guard.md)\n- [Guardrails AI vs Mistral Moderation API](https://www.anchorterminal.com/compare/guardrails-ai-vs-mistral-moderation.md)\n- [Guardrails AI vs OpenAI Moderation API](https://www.anchorterminal.com/compare/guardrails-ai-vs-openai-moderation.md)\n- [Guardrails AI vs Presidio](https://www.anchorterminal.com/compare/guardrails-ai-vs-microsoft-presidio.md)\n- [Granite Guardian vs Presidio](https://www.anchorterminal.com/compare/granite-guardian-vs-microsoft-presidio.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Granite Guardian vs Guardrails AI",
        "url": ""
      }
    ],
    "description": "Granite Guardian scores 60.1 (C) on agent readiness against Guardrails AI's 49.6 (D), and leads in 5 of 7 scored categories. Both do guard moderation. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Granite Guardian C 60.1",
      "Guardrails AI D 49.6",
      "scores"
    ],
    "h1": "Granite Guardian vs Guardrails AI",
    "image": "https://www.anchorterminal.com/assets/og/compare-granite-guardian-vs-guardrails-ai.png",
    "path": "/compare/granite-guardian-vs-guardrails-ai",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Granite Guardian vs Guardrails AI for AI agents, C 60.1 vs D 49.6",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/granite-guardian-vs-guardrails-ai"
  },
  "tokens": {
    "markdown": 2600,
    "slim": 630
  },
  "version": 1
}
