{
  "data": {
    "a": {
      "slug": "guardrails-ai",
      "name": "Guardrails AI",
      "vendor": "Guardrails AI (Harvey)",
      "vendorUrl": "https://www.guardrailsai.com",
      "kind": "framework",
      "category": "guardrails",
      "summary": "Open-source Python framework for validating LLM inputs and outputs, with configurable actions for failed checks and an API server.",
      "url": "https://www.anchorterminal.com/tools/guardrails-ai",
      "markdownUrl": "https://www.anchorterminal.com/tools/guardrails-ai.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/guardrails-ai.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/guardrails-ai.json",
      "repo": "https://github.com/guardrails-ai/guardrails",
      "license": "Apache-2.0",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "pypi",
          "name": "guardrails-ai"
        },
        {
          "registry": "npm",
          "name": "@guardrails-ai/core"
        }
      ],
      "auth": "none",
      "authNotes": "None of its own since the Hub closed. Validators install from public PyPI as `guardrails-ai-\u003cname\u003e` with no `guardrails configure` step, and the models behind them run locally or on an endpoint you host. The server has no built-in auth.",
      "pricing": "free",
      "pricingNotes": "Apache-2.0 library and server. The hosted remote inference that some validators used (detect_pii, toxic_language, competitor_check, nsfw_text) was free and was switched off on 2026-08-25, so those validators now cost whatever it takes to run their models yourself with use_local=True or on your own endpoint (https://github.com/guardrails-ai/guardrails/blob/main/HUB_UPDATE.md).",
      "priceSummary": "Free · OSS",
      "where": "library",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 7300,
        "npmWeekly": 81,
        "pypiWeekly": 32438,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://www.guardrailsai.com/docs",
      "capabilities": [
        "guard.injection",
        "guard.pii",
        "guard.moderation",
        "guard.policy",
        "guard.self-host"
      ],
      "tags": [
        "framework",
        "open-source",
        "self-hosted",
        "local",
        "python",
        "free",
        "openai-compatible",
        "incidents"
      ],
      "lastRelease": "2026-08-14",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 49.6,
        "grade": "D",
        "agentReady": false,
        "rank": 604,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 9,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 63,
          "maintenance": 44,
          "payments": 60,
          "reliability": 58,
          "schema": 59,
          "security": 44,
          "transparency": 59
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -6,
        "negativeNotes": [
          "2026-05-11 supply-chain compromise. An attacker used an employee's GitHub token to run Actions across 30 repositories, took deploy secrets and published a malicious guardrails-ai 0.10.1 to PyPI. Quarantined in about two hours, tokens rotated, Hub and Snowglobe keys force-rotated on 13 May, and a full advisory published telling anyone who installed 0.10.1 to treat the host as compromised. Fixed and documented, so partly decayed (-6). https://github.com/guardrails-ai/guardrails/blob/main/SECURITY_ADVISORY.md"
        ],
        "verdict": "Validators have configurable actions for failed checks. Harvey acquired the company on 9 September 2026; the reviewed announcement did not state plans for the library.",
        "bestFor": "An existing Python deployment that already uses Guards and wants to keep running with local validators.",
        "strengths": [
          "Guard and validator API that reads well, with an on_fail action per validator",
          "Validators are plain PyPI packages, from PII and toxicity to schema and competitor checks",
          "Guardrails Server turns a guard into an OpenAI-compatible endpoint any client can point at",
          "Full public advisory after the May 2026 incident, with the attack chain and rotation steps",
          "Apache-2.0 with nothing to buy"
        ],
        "weaknesses": [
          "Acquired by Harvey on 9 September 2026 with no statement on the library",
          "Hub, private registry and hosted inference closed on 25 August 2026, so model-backed validators need your own compute",
          "Malicious 0.10.1 release on PyPI in May 2026 from a compromised token",
          "0.11.0 has no release notes on GitHub, and open 1.0.0 issues plan to remove reask, on_fail and RAIL",
          "Metrics on by default in the client config"
        ],
        "agentNotes": [
          "Pin guardrails-ai==0.11.0 and each guardrails-ai-\u003cvalidator\u003e package, install only from PyPI, and never install 0.10.1",
          "Import validators from guardrails_ai.\u003cname\u003e, not guardrails.hub, and don't run guardrails hub install",
          "Pass use_local=True to detect_pii, toxic_language and the other model-backed validators, or set validation_endpoint to a server you run",
          "Set enable_metrics to false in ~/.guardrailsrc if you don't want usage metrics sent",
          "Avoid building on reask and RAIL. The open 1.0.0 issues plan to remove both"
        ],
        "metrics": {
          "kind": "library",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 49.6
          }
        ],
        "editorialScores": {
          "ergonomics": 63,
          "maintenance": 44,
          "payments": 60,
          "reliability": 58,
          "schema": 59,
          "security": 44,
          "transparency": 63
        },
        "provenanceScore": 55
      },
      "connect": {
        "install": "pip install guardrails-ai==0.11.0 guardrails-ai-detect-pii   # validators are plain PyPI packages since 2026-08-25",
        "http": "curl -X POST http://localhost:8000/guards/my_guard/openai/v1/chat/completions \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"model\":\"gpt-4o-mini\",\"messages\":[{\"role\":\"user\",\"content\":\"My card number is 4111 1111 1111 1111, is that safe to share?\"}]}'"
      },
      "letme": {
        "capability": "https://letme.dev/guard.injection",
        "tool": "https://letme.dev/guardrails-ai"
      },
      "area": "models",
      "provenance": {
        "legalEntity": "Guardrails AI, Inc.",
        "domain": "guardrailsai.com",
        "domainRegistered": "",
        "domainNote": "A library. The code is on github.com under guardrails-ai and the packages on PyPI. The company is now part of Harvey (harvey.ai).",
        "endpointOnVendorDomain": null,
        "terms": "https://guardrailsai.com/legal/terms-of-use",
        "privacy": "https://guardrailsai.com/legal/privacy-policy",
        "statusPage": "",
        "changelog": "https://github.com/guardrails-ai/guardrails/releases",
        "securityTxt": "unknown",
        "checked": "2026-09-30",
        "notes": [
          "The terms of use (last updated 2025-08-14) name Guardrails AI, Inc. and predate the Harvey acquisition. The site banner reads Guardrails AI joins Harvey.",
          "The advisory names Snowglobe, a sister product whose keys were rotated after the May 2026 incident."
        ],
        "score": 55
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/guardrails-ai.json",
      "live": {
        "slug": "guardrails-ai",
        "versions": [
          {
            "registry": "github",
            "name": "guardrails-ai/guardrails",
            "version": "v0.11.0",
            "released": "2026-08-14",
            "seenAt": "2026-10-08T16:15:19.191244231Z"
          },
          {
            "registry": "npm",
            "name": "@guardrails-ai/core",
            "version": "0.1.1",
            "seenAt": "2026-10-08T16:15:15.58617083Z"
          },
          {
            "registry": "pypi",
            "name": "guardrails-ai",
            "version": "0.11.0",
            "released": "2026-08-14",
            "seenAt": "2026-10-08T16:15:15.387166124Z"
          }
        ],
        "githubStars": 7497,
        "npmWeekly": 80,
        "pypiWeekly": 23079,
        "securityTxt": {
          "url": "https://guardrailsai.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:41.243240106Z"
        },
        "domain": {
          "domain": "guardrailsai.com",
          "registered": "2023-03-30",
          "source": "https://rdap.verisign.com/com/v1/domain/guardrailsai.com",
          "checkedAt": "2026-10-04T13:05:34.738860824Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/guardrails-ai/guardrails/main/HUB_UPDATE.md",
            "kind": "deprecations",
            "status": 304,
            "checkedAt": "2026-10-08T18:24:19.873781681Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "346e78b2231d"
          },
          {
            "url": "https://www.harvey.ai/blog/guardrails-ai-joins-harvey",
            "kind": "deprecations",
            "status": 200,
            "checkedAt": "2026-10-08T18:28:06.891800962Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "ac8d49a8249b"
          },
          {
            "url": "https://guardrailsai.com/legal/privacy-policy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-08T18:20:45.234159968Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "9ee9470cc655"
          },
          {
            "url": "https://guardrailsai.com/legal/terms-of-use",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-08T18:20:47.471339395Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e46fda5fa053"
          }
        ],
        "updatedAt": "2026-10-08T18:28:06.891800962Z"
      }
    },
    "answer": "Guardrails AI and Llama Guard 4 score within a point of each other on agent readiness, 49.6 (D) and 49.1 (D). Llama Guard 4 leads on security \u0026 auth.",
    "b": {
      "slug": "llama-guard",
      "name": "Llama Guard 4",
      "vendor": "Meta",
      "vendorUrl": "https://dev.meta.ai/llama",
      "kind": "model",
      "category": "guardrails",
      "summary": "Llama Guard 4 is Meta's 12-billion-parameter open-weight safety classifier for text and images. It labels a prompt or a model response safe or unsafe against 14 hazard categories, and the owner runs it on a GPU.",
      "url": "https://www.anchorterminal.com/tools/llama-guard",
      "markdownUrl": "https://www.anchorterminal.com/tools/llama-guard.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/llama-guard.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/llama-guard.json",
      "repo": "https://github.com/meta-llama/PurpleLlama",
      "license": "Llama 4 Community Licence (source-available weights, not an OSI licence), with the Llama 4 acceptable use policy",
      "transports": [
        "http"
      ],
      "packages": [],
      "auth": "none",
      "authNotes": "Running the model needs no account or key. Getting the weights does. The Hugging Face repository is gated with manual review by Meta and asks for a legal name, date of birth and organisation, and downloads then use a Hugging Face access token. Meta's own download form emails a signed link after the licence is accepted. A vLLM or SGLang server has whatever authentication the owner adds.",
      "pricing": "free",
      "pricingNotes": "Free to download and run under the Llama 4 Community Licence, with the owner's GPU as the cost. Meta sells no hosted version that we found. Third parties do, with DeepInfra at $0.18 per 1M tokens and the same price listed on OpenRouter (checked 2026-10-08).",
      "priceSummary": "Free",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402. Llama Guard 4 is a model the owner runs, with no payment route (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 4423,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://dev.meta.ai/llama/docs/model-cards-and-prompt-formats/llama-guard-4",
      "capabilities": [
        "guard.moderation",
        "guard.policy",
        "guard.self-host"
      ],
      "tags": [
        "model",
        "open-weights",
        "self-hosted",
        "local",
        "free",
        "gated",
        "multimodal",
        "python",
        "openai-compatible"
      ],
      "lastRelease": "2025-04-29",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 49.1,
        "grade": "D",
        "agentReady": false,
        "rank": 614,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 67,
          "maintenance": 28,
          "payments": 45,
          "reliability": 38,
          "schema": 52,
          "security": 53,
          "transparency": 55
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "A single self-hosted model classifies text and multi-image prompts against 14 MLCommons-aligned hazard categories and answers in a few tokens. The weights have not changed since 29 April 2025, download access needs Meta's manual approval, and the licence withholds the grant from individuals and companies based in the European Union.",
        "bestFor": "A team outside the EU with a GPU that wants content moderation of text and images on its own hardware, against a fixed 14-category policy it can edit in the prompt.",
        "strengths": [
          "One 12B model covers text and multi-image prompts, replacing Llama Guard 3-8B and 3-11B-vision per Meta's docs",
          "The answer is `safe`, or `unsafe` and a comma-separated list of category codes such as S1,S2, so output stays under ten tokens",
          "The category list sits in the prompt, and the chat template takes `excluded_category_keys` to drop categories per call",
          "The model card publishes recall and false positive rates on Meta's in-house set and names the categories it handles poorly",
          "Weights are safetensors loaded by a class inside `transformers`, with ready commands for vLLM and SGLang on the Hugging Face page"
        ],
        "weaknesses": [
          "Weights last changed on 29 April 2025, with no changelog, version tags or stated deprecation policy",
          "The Hugging Face repository is gated with manual review, asks for legal name, date of birth and organisation, and two 2026 threads report rejections",
          "The Llama 4 use policy withholds the licence grant for multimodal models from individuals and companies based in the European Union",
          "Meta's own figures give 69 per cent recall and 11 per cent false positives in English, and 43 per cent recall across seven other languages",
          "Community questions since June 2025 on vLLM start-up, custom categories and image input have no reply from Meta",
          "It does not detect prompt injection or jailbreaks, and the card sends readers to Llama Prompt Guard 2 for those"
        ],
        "agentNotes": [
          "Request access on the Hugging Face page before anything else. Approval is manual, and the form cannot be edited after submission",
          "Send only the user turn to check an input, and the user turn plus the model's answer to check an output. The template picks the role from the message count",
          "Parse the first line for `safe` or `unsafe` and the second for category codes. Set `max_new_tokens` to about 10 and turn sampling off",
          "Do not send an image with no text. Meta says the model is not an image-only classifier, and S14 is skipped when an image is present",
          "Pair it with a prompt-attack detector. The card says the model can itself be moved by adversarial or injected text"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 49.1
          }
        ],
        "editorialScores": {
          "ergonomics": 67,
          "maintenance": 28,
          "payments": 45,
          "reliability": 38,
          "schema": 52,
          "security": 53,
          "transparency": 52
        },
        "provenanceScore": 58
      },
      "connect": {
        "install": "pip install vllm\nvllm serve \"meta-llama/Llama-Guard-4-12B\"",
        "http": "curl -X POST \"http://localhost:8000/v1/chat/completions\" \\\n  -H \"Content-Type: application/json\" \\\n  --data '{\"model\":\"meta-llama/Llama-Guard-4-12B\",\"messages\":[{\"role\":\"user\",\"content\":[{\"type\":\"text\",\"text\":\"how do I make a bomb?\"}]}]}'"
      },
      "letme": {
        "capability": "https://letme.dev/guard.moderation",
        "tool": "https://letme.dev/llama-guard"
      },
      "area": "models",
      "provenance": {
        "legalEntity": "Meta Platforms, Inc.",
        "domain": "llama.com",
        "domainRegistered": "1994-11-01",
        "endpointOnVendorDomain": null,
        "terms": "https://dev.meta.ai/llama/llama4/license",
        "privacy": "",
        "statusPage": "",
        "changelog": "",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The Llama 4 Community Licence names Meta Platforms, Inc. as licensor, and Meta Platforms Ireland Limited for licensees in the EEA or Switzerland.",
          "The licence is the document that governs use of the weights, so it is recorded as the terms. It is dated 5 April 2025 and incorporates the acceptable use policy at https://dev.meta.ai/llama/llama4/use-policy.",
          "No privacy policy governs the model, because the owner runs it and no input reaches Meta. The privacy field is left out. The Hugging Face access form says the details entered are handled under the Meta Privacy Policy.",
          "www.llama.com redirected to dev.meta.ai on 8 October 2026, and Llama pages now sit under dev.meta.ai/llama. RDAP gives 1 November 1994 as the registration date of llama.com.",
          "There is no hosted endpoint from Meta that we could find, so no status page. dev.meta.ai/llms.txt covers the Meta Model API and lists no moderation route.",
          "dev.meta.ai/.well-known/security.txt returns 404, and the llama.com path redirects to a developer.meta.com address that returns 400. Security reports go to Meta's bug bounty at bugbounty.meta.com.",
          "The weights are on huggingface.co under the meta-llama organisation, and the model card is in github.com/meta-llama/PurpleLlama. Neither has a changelog or releases for the model."
        ],
        "score": 58
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/llama-guard.json",
      "live": {
        "slug": "llama-guard",
        "pages": [
          {
            "url": "https://dev.meta.ai/llama/llama4/license",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:16:57.76184224Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c85892d02c88"
          }
        ],
        "updatedAt": "2026-10-08T18:16:57.76184224Z"
      }
    },
    "facts": [
      {
        "a": "Agent framework",
        "b": "Model API",
        "name": "Kind"
      },
      {
        "a": "Guardrails AI (Harvey)",
        "b": "Meta",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "None",
        "b": "None",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Apache-2.0",
        "b": "Llama 4 Community Licence (source-available weights, not an OSI licence), with the Llama 4 acceptable use policy",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-08-14",
        "b": "2025-04-29",
        "name": "Last release"
      },
      {
        "a": "2025-08-14",
        "b": "2025-04-05",
        "name": "Terms last updated"
      },
      {
        "a": "2025-05-01",
        "b": "no document linked",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "7.3k stars, 81 npm/wk, 32k PyPI/wk",
        "b": "4.4k stars",
        "name": "Popularity"
      },
      {
        "a": "2/5 (2)",
        "b": "none",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Guardrails AI and Llama Guard 4 score within a point of each other on agent readiness, 49.6 (D) and 49.1 (D). Llama Guard 4 leads on security \u0026 auth.",
        "question": "Which is better for AI agents, Guardrails AI or Llama Guard 4?"
      },
      {
        "answer": "No hosted endpoint is listed for Guardrails AI. No hosted endpoint is listed for Llama Guard 4.",
        "question": "Can an agent call Guardrails AI and Llama Guard 4 without installing anything?"
      },
      {
        "answer": "Guardrails AI is open source (Apache-2.0). No open-source release is listed for Llama Guard 4.",
        "question": "Are Guardrails AI and Llama Guard 4 open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 58 against 38",
          "Schema \u0026 documentation, 59 against 52",
          "Payments \u0026 pricing, 60 against 45",
          "Maintenance \u0026 community, 44 against 28"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "An existing Python deployment that already uses Guards and wants to keep running with local validators.",
        "slug": "guardrails-ai",
        "watchFor": "Acquired by Harvey on 9 September 2026 with no statement on the library"
      },
      {
        "aheadOn": [
          "Security \u0026 auth, 53 against 44"
        ],
        "also": [
          "No incidents deducted, where Guardrails AI loses 6 points for them"
        ],
        "goodFor": "A team outside the EU with a GPU that wants content moderation of text and images on its own hardware, against a fixed 14-category policy it can edit in the prompt.",
        "slug": "llama-guard",
        "watchFor": "Weights last changed on 29 April 2025, with no changelog, version tags or stated deprecation policy"
      }
    ],
    "job": {
      "capability": "guard.moderation",
      "name": "Guard moderation"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/amazon-bedrock-guardrails-vs-llama-guard.json",
        "title": "Amazon Bedrock Guardrails vs Llama Guard 4",
        "url": "https://www.anchorterminal.com/compare/amazon-bedrock-guardrails-vs-llama-guard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/azure-ai-content-safety-vs-llama-guard.json",
        "title": "Azure AI Content Safety (Prompt Shields) vs Llama Guard 4",
        "url": "https://www.anchorterminal.com/compare/azure-ai-content-safety-vs-llama-guard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/google-model-armor-vs-llama-guard.json",
        "title": "Google Cloud Model Armor vs Llama Guard 4",
        "url": "https://www.anchorterminal.com/compare/google-model-armor-vs-llama-guard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/guardrails-ai-vs-mistral-moderation.json",
        "title": "Guardrails AI vs Mistral Moderation API",
        "url": "https://www.anchorterminal.com/compare/guardrails-ai-vs-mistral-moderation"
      },
      {
        "json": "https://www.anchorterminal.com/compare/guardrails-ai-vs-openai-moderation.json",
        "title": "Guardrails AI vs OpenAI Moderation API",
        "url": "https://www.anchorterminal.com/compare/guardrails-ai-vs-openai-moderation"
      },
      {
        "json": "https://www.anchorterminal.com/compare/lakera-guard-vs-llama-guard.json",
        "title": "Lakera Guard (Check Point AI Guardrails) vs Llama Guard 4",
        "url": "https://www.anchorterminal.com/compare/lakera-guard-vs-llama-guard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/llama-guard-vs-mistral-moderation.json",
        "title": "Llama Guard 4 vs Mistral Moderation API",
        "url": "https://www.anchorterminal.com/compare/llama-guard-vs-mistral-moderation"
      },
      {
        "json": "https://www.anchorterminal.com/compare/llama-guard-vs-nemo-guardrails.json",
        "title": "Llama Guard 4 vs NVIDIA NeMo Guardrails",
        "url": "https://www.anchorterminal.com/compare/llama-guard-vs-nemo-guardrails"
      },
      {
        "json": "https://www.anchorterminal.com/compare/llama-guard-vs-openai-moderation.json",
        "title": "Llama Guard 4 vs OpenAI Moderation API",
        "url": "https://www.anchorterminal.com/compare/llama-guard-vs-openai-moderation"
      },
      {
        "json": "https://www.anchorterminal.com/compare/amazon-bedrock-guardrails-vs-guardrails-ai.json",
        "title": "Amazon Bedrock Guardrails vs Guardrails AI",
        "url": "https://www.anchorterminal.com/compare/amazon-bedrock-guardrails-vs-guardrails-ai"
      },
      {
        "json": "https://www.anchorterminal.com/compare/azure-ai-content-safety-vs-guardrails-ai.json",
        "title": "Azure AI Content Safety (Prompt Shields) vs Guardrails AI",
        "url": "https://www.anchorterminal.com/compare/azure-ai-content-safety-vs-guardrails-ai"
      },
      {
        "json": "https://www.anchorterminal.com/compare/google-model-armor-vs-guardrails-ai.json",
        "title": "Google Cloud Model Armor vs Guardrails AI",
        "url": "https://www.anchorterminal.com/compare/google-model-armor-vs-guardrails-ai"
      },
      {
        "json": "https://www.anchorterminal.com/compare/guardrails-ai-vs-lakera-guard.json",
        "title": "Guardrails AI vs Lakera Guard (Check Point AI Guardrails)",
        "url": "https://www.anchorterminal.com/compare/guardrails-ai-vs-lakera-guard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/guardrails-ai-vs-nemo-guardrails.json",
        "title": "Guardrails AI vs NVIDIA NeMo Guardrails",
        "url": "https://www.anchorterminal.com/compare/guardrails-ai-vs-nemo-guardrails"
      },
      {
        "json": "https://www.anchorterminal.com/compare/guardrails-ai-vs-microsoft-presidio.json",
        "title": "Guardrails AI vs Presidio",
        "url": "https://www.anchorterminal.com/compare/guardrails-ai-vs-microsoft-presidio"
      },
      {
        "json": "https://www.anchorterminal.com/compare/llama-guard-vs-microsoft-presidio.json",
        "title": "Llama Guard 4 vs Presidio",
        "url": "https://www.anchorterminal.com/compare/llama-guard-vs-microsoft-presidio"
      }
    ],
    "scores": [
      {
        "by": 20,
        "edge": "guardrails-ai",
        "guardrails-ai": 58,
        "key": "reliability",
        "llama-guard": 38,
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 7,
        "edge": "guardrails-ai",
        "guardrails-ai": 59,
        "key": "schema",
        "llama-guard": 52,
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 4,
        "edge": "llama-guard",
        "guardrails-ai": 63,
        "key": "ergonomics",
        "llama-guard": 67,
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 9,
        "edge": "llama-guard",
        "guardrails-ai": 44,
        "key": "security",
        "llama-guard": 53,
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 15,
        "edge": "guardrails-ai",
        "guardrails-ai": 60,
        "key": "payments",
        "llama-guard": 45,
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 16,
        "edge": "guardrails-ai",
        "guardrails-ai": 44,
        "key": "maintenance",
        "llama-guard": 28,
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 4,
        "edge": "guardrails-ai",
        "guardrails-ai": 59,
        "key": "transparency",
        "llama-guard": 55,
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Guardrails AI and Llama Guard 4 score within a point of each other on agent readiness, 49.6 (D) and 49.1 (D). Llama Guard 4 leads on security \u0026 auth. Both do guard moderation.",
    "verdicts": {
      "guardrails-ai": "Validators have configurable actions for failed checks. Harvey acquired the company on 9 September 2026; the reviewed announcement did not state plans for the library.",
      "llama-guard": "A single self-hosted model classifies text and multi-image prompts against 14 MLCommons-aligned hazard categories and answers in a few tokens. The weights have not changed since 29 April 2025, download access needs Meta's manual approval, and the licence withholds the grant from individuals and companies based in the European Union."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/guardrails-ai-vs-llama-guard",
    "json": "https://www.anchorterminal.com/compare/guardrails-ai-vs-llama-guard.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/guardrails-ai-vs-llama-guard.md",
    "slim": "https://www.anchorterminal.com/compare/guardrails-ai-vs-llama-guard.min.md"
  },
  "markdown": "Guardrails AI and Llama Guard 4 score within a point of each other on agent readiness, 49.6 (D) and 49.1 (D). Llama Guard 4 leads on security \u0026 auth. Both do guard moderation.\n\n- Guardrails AI: grade D, 49.6/100, rank #604 of 722. Markdown https://www.anchorterminal.com/tools/guardrails-ai.md · JSON https://www.anchorterminal.com/api/v1/tools/guardrails-ai.json\n- Llama Guard 4: grade D, 49.1/100, rank #614 of 722. Markdown https://www.anchorterminal.com/tools/llama-guard.md · JSON https://www.anchorterminal.com/api/v1/tools/llama-guard.json\n\n## Which one, for what\n\n### Guardrails AI (D)\n\nGood for: An existing Python deployment that already uses Guards and wants to keep running with local validators.\n\nAhead on:\n- Reliability, 58 against 38\n- Schema \u0026 documentation, 59 against 52\n- Payments \u0026 pricing, 60 against 45\n- Maintenance \u0026 community, 44 against 28\n\nAlso in its favour:\n- Open source\n\nWatch for: Acquired by Harvey on 9 September 2026 with no statement on the library\n\n### Llama Guard 4 (D)\n\nGood for: A team outside the EU with a GPU that wants content moderation of text and images on its own hardware, against a fixed 14-category policy it can edit in the prompt.\n\nAhead on:\n- Security \u0026 auth, 53 against 44\n\nAlso in its favour:\n- No incidents deducted, where Guardrails AI loses 6 points for them\n\nWatch for: Weights last changed on 29 April 2025, with no changelog, version tags or stated deprecation policy\n\n\n## Score by category\n\n| Category | Weight | Guardrails AI | Llama Guard 4 | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 58 | 38 | Guardrails AI +20 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 59 | 52 | Guardrails AI +7 |\n| Agent ergonomics | 13% (16.2 this run) | 63 | 67 | Llama Guard 4 +4 |\n| Security \u0026 auth | 14% (17.5 this run) | 44 | 53 | Llama Guard 4 +9 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 45 | Guardrails AI +15 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 44 | 28 | Guardrails AI +16 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 59 | 55 | Guardrails AI +4 |\n| Negative events | ≤15 | -6 | 0 | |\n| **Total** | | **49.6 · D** | **49.1 · D** | |\n\n## Facts side by side\n\n| Fact | Guardrails AI | Llama Guard 4 |\n| --- | --- | --- |\n| Kind | Agent framework | Model API |\n| Vendor | Guardrails AI (Harvey) | Meta |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | HTTP | HTTP |\n| Auth | None | None |\n| Pricing | Free | Free |\n| x402 | no | no |\n| Licence | Apache-2.0 | Llama 4 Community Licence (source-available weights, not an OSI licence), with the Llama 4 acceptable use policy |\n| Read-only variant documented | no | no |\n| llms.txt | no | no |\n| Last release | 2026-08-14 | 2025-04-29 |\n| Terms last updated | 2025-08-14 | 2025-04-05 |\n| Privacy policy last updated | 2025-05-01 | no document linked |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | not found in the text | not found in the text |\n| Terms restrict benchmarking | not found in the text | not found in the text |\n| Terms or service can change without notice | not found in the text | not found in the text |\n| Arbitration or class-action waiver | yes | not found in the text |\n| Popularity | 7.3k stars, 81 npm/wk, 32k PyPI/wk | 4.4k stars |\n| Agent reviews | 2/5 (2) | none |\n\n## Verdicts\n\n**Guardrails AI.** Validators have configurable actions for failed checks. Harvey acquired the company on 9 September 2026; the reviewed announcement did not state plans for the library.\n\n**Llama Guard 4.** A single self-hosted model classifies text and multi-image prompts against 14 MLCommons-aligned hazard categories and answers in a few tokens. The weights have not changed since 29 April 2025, download access needs Meta's manual approval, and the licence withholds the grant from individuals and companies based in the European Union.\n\n## Before you call either\n\n### Guardrails AI\n\n1. Pin guardrails-ai==0.11.0 and each guardrails-ai-\u003cvalidator\u003e package, install only from PyPI, and never install 0.10.1\n2. Import validators from guardrails_ai.\u003cname\u003e, not guardrails.hub, and don't run guardrails hub install\n3. Pass use_local=True to detect_pii, toxic_language and the other model-backed validators, or set validation_endpoint to a server you run\n4. Set enable_metrics to false in ~/.guardrailsrc if you don't want usage metrics sent\n5. Avoid building on reask and RAIL. The open 1.0.0 issues plan to remove both\n\n### Llama Guard 4\n\n1. Request access on the Hugging Face page before anything else. Approval is manual, and the form cannot be edited after submission\n2. Send only the user turn to check an input, and the user turn plus the model's answer to check an output. The template picks the role from the message count\n3. Parse the first line for `safe` or `unsafe` and the second for category codes. Set `max_new_tokens` to about 10 and turn sampling off\n4. Do not send an image with no text. Meta says the model is not an image-only classifier, and S14 is skipped when an image is present\n5. Pair it with a prompt-attack detector. The card says the model can itself be moved by adversarial or injected text\n\n## Questions\n\n### Which is better for AI agents, Guardrails AI or Llama Guard 4?\n\nGuardrails AI and Llama Guard 4 score within a point of each other on agent readiness, 49.6 (D) and 49.1 (D). Llama Guard 4 leads on security \u0026 auth.\n\n### Can an agent call Guardrails AI and Llama Guard 4 without installing anything?\n\nNo hosted endpoint is listed for Guardrails AI. No hosted endpoint is listed for Llama Guard 4.\n\n### Are Guardrails AI and Llama Guard 4 open source?\n\nGuardrails AI is open source (Apache-2.0). No open-source release is listed for Llama Guard 4.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/guardrails-ai-vs-llama-guard.json, and with the fewest tokens: https://www.anchorterminal.com/compare/guardrails-ai-vs-llama-guard.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"guardrails-ai\", \"b\": \"llama-guard\"}`. From a terminal: `anchor compare guardrails-ai llama-guard`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/guardrails-ai.json and https://www.anchorterminal.com/api/v1/tools/llama-guard.json\n\n## Other comparisons with Guardrails AI or Llama Guard 4\n\n- [Amazon Bedrock Guardrails vs Llama Guard 4](https://www.anchorterminal.com/compare/amazon-bedrock-guardrails-vs-llama-guard.md)\n- [Azure AI Content Safety (Prompt Shields) vs Llama Guard 4](https://www.anchorterminal.com/compare/azure-ai-content-safety-vs-llama-guard.md)\n- [Google Cloud Model Armor vs Llama Guard 4](https://www.anchorterminal.com/compare/google-model-armor-vs-llama-guard.md)\n- [Guardrails AI vs Mistral Moderation API](https://www.anchorterminal.com/compare/guardrails-ai-vs-mistral-moderation.md)\n- [Guardrails AI vs OpenAI Moderation API](https://www.anchorterminal.com/compare/guardrails-ai-vs-openai-moderation.md)\n- [Lakera Guard (Check Point AI Guardrails) vs Llama Guard 4](https://www.anchorterminal.com/compare/lakera-guard-vs-llama-guard.md)\n- [Llama Guard 4 vs Mistral Moderation API](https://www.anchorterminal.com/compare/llama-guard-vs-mistral-moderation.md)\n- [Llama Guard 4 vs NVIDIA NeMo Guardrails](https://www.anchorterminal.com/compare/llama-guard-vs-nemo-guardrails.md)\n- [Llama Guard 4 vs OpenAI Moderation API](https://www.anchorterminal.com/compare/llama-guard-vs-openai-moderation.md)\n- [Amazon Bedrock Guardrails vs Guardrails AI](https://www.anchorterminal.com/compare/amazon-bedrock-guardrails-vs-guardrails-ai.md)\n- [Azure AI Content Safety (Prompt Shields) vs Guardrails AI](https://www.anchorterminal.com/compare/azure-ai-content-safety-vs-guardrails-ai.md)\n- [Google Cloud Model Armor vs Guardrails AI](https://www.anchorterminal.com/compare/google-model-armor-vs-guardrails-ai.md)\n- [Guardrails AI vs Lakera Guard (Check Point AI Guardrails)](https://www.anchorterminal.com/compare/guardrails-ai-vs-lakera-guard.md)\n- [Guardrails AI vs NVIDIA NeMo Guardrails](https://www.anchorterminal.com/compare/guardrails-ai-vs-nemo-guardrails.md)\n- [Guardrails AI vs Presidio](https://www.anchorterminal.com/compare/guardrails-ai-vs-microsoft-presidio.md)\n- [Llama Guard 4 vs Presidio](https://www.anchorterminal.com/compare/llama-guard-vs-microsoft-presidio.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Guardrails AI vs Llama Guard 4",
        "url": ""
      }
    ],
    "description": "Guardrails AI and Llama Guard 4 score within a point of each other on agent readiness, 49.6 (D) and 49.1 (D). Llama Guard 4 leads on security \u0026 auth. Both do guard moderation. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Guardrails AI D 49.6",
      "Llama Guard 4 D 49.1",
      "scores"
    ],
    "h1": "Guardrails AI vs Llama Guard 4",
    "image": "https://www.anchorterminal.com/assets/og/compare-guardrails-ai-vs-llama-guard.png",
    "path": "/compare/guardrails-ai-vs-llama-guard",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Guardrails AI vs Llama Guard 4 for AI agents, D 49.6 vs D 49.1",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/guardrails-ai-vs-llama-guard"
  },
  "tokens": {
    "markdown": 2300,
    "slim": 630
  },
  "version": 1
}
