{
  "data": {
    "a": {
      "slug": "guardrails-ai",
      "name": "Guardrails AI",
      "vendor": "Guardrails AI (Harvey)",
      "vendorUrl": "https://www.guardrailsai.com",
      "kind": "framework",
      "category": "guardrails",
      "summary": "Open-source Python framework for validating LLM inputs and outputs, with configurable actions for failed checks and an API server.",
      "url": "https://www.anchorterminal.com/tools/guardrails-ai",
      "markdownUrl": "https://www.anchorterminal.com/tools/guardrails-ai.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/guardrails-ai.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/guardrails-ai.json",
      "repo": "https://github.com/guardrails-ai/guardrails",
      "license": "Apache-2.0",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "pypi",
          "name": "guardrails-ai"
        },
        {
          "registry": "npm",
          "name": "@guardrails-ai/core"
        }
      ],
      "auth": "none",
      "authNotes": "None of its own since the Hub closed. Validators install from public PyPI as `guardrails-ai-\u003cname\u003e` with no `guardrails configure` step, and the models behind them run locally or on an endpoint you host. The server has no built-in auth.",
      "pricing": "free",
      "pricingNotes": "Apache-2.0 library and server. The hosted remote inference that some validators used (detect_pii, toxic_language, competitor_check, nsfw_text) was free and was switched off on 2026-08-25, so those validators now cost whatever it takes to run their models yourself with use_local=True or on your own endpoint (https://github.com/guardrails-ai/guardrails/blob/main/HUB_UPDATE.md).",
      "priceSummary": "Free · OSS",
      "where": "library",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 7300,
        "npmWeekly": 81,
        "pypiWeekly": 32438,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://www.guardrailsai.com/docs",
      "capabilities": [
        "guard.injection",
        "guard.pii",
        "guard.moderation",
        "guard.policy",
        "guard.self-host"
      ],
      "tags": [
        "framework",
        "open-source",
        "self-hosted",
        "local",
        "python",
        "free",
        "openai-compatible",
        "incidents"
      ],
      "lastRelease": "2026-08-14",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 49.6,
        "grade": "D",
        "agentReady": false,
        "rank": 701,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 14,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 63,
          "maintenance": 44,
          "payments": 60,
          "reliability": 58,
          "schema": 59,
          "security": 44,
          "transparency": 59
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -6,
        "negativeNotes": [
          "2026-05-11 supply-chain compromise. An attacker used an employee's GitHub token to run Actions across 30 repositories, took deploy secrets and published a malicious guardrails-ai 0.10.1 to PyPI. Quarantined in about two hours, tokens rotated, Hub and Snowglobe keys force-rotated on 13 May, and a full advisory published telling anyone who installed 0.10.1 to treat the host as compromised. Fixed and documented, so partly decayed (-6). https://github.com/guardrails-ai/guardrails/blob/main/SECURITY_ADVISORY.md"
        ],
        "verdict": "Validators have configurable actions for failed checks. Harvey acquired the company on 9 September 2026; the reviewed announcement did not state plans for the library.",
        "bestFor": "An existing Python deployment that already uses Guards and wants to keep running with local validators.",
        "strengths": [
          "Guard and validator API that reads well, with an on_fail action per validator",
          "Validators are plain PyPI packages, from PII and toxicity to schema and competitor checks",
          "Guardrails Server turns a guard into an OpenAI-compatible endpoint any client can point at",
          "Full public advisory after the May 2026 incident, with the attack chain and rotation steps",
          "Apache-2.0 with nothing to buy"
        ],
        "weaknesses": [
          "Acquired by Harvey on 9 September 2026 with no statement on the library",
          "Hub, private registry and hosted inference closed on 25 August 2026, so model-backed validators need your own compute",
          "Malicious 0.10.1 release on PyPI in May 2026 from a compromised token",
          "0.11.0 has no release notes on GitHub, and open 1.0.0 issues plan to remove reask, on_fail and RAIL",
          "Metrics on by default in the client config"
        ],
        "agentNotes": [
          "Pin guardrails-ai==0.11.0 and each guardrails-ai-\u003cvalidator\u003e package, install only from PyPI, and never install 0.10.1",
          "Import validators from guardrails_ai.\u003cname\u003e, not guardrails.hub, and don't run guardrails hub install",
          "Pass use_local=True to detect_pii, toxic_language and the other model-backed validators, or set validation_endpoint to a server you run",
          "Set enable_metrics to false in ~/.guardrailsrc if you don't want usage metrics sent",
          "Avoid building on reask and RAIL. The open 1.0.0 issues plan to remove both"
        ],
        "metrics": {
          "kind": "library",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 49.6
          }
        ],
        "editorialScores": {
          "ergonomics": 63,
          "maintenance": 44,
          "payments": 60,
          "reliability": 58,
          "schema": 59,
          "security": 44,
          "transparency": 63
        },
        "provenanceScore": 55
      },
      "connect": {
        "install": "pip install guardrails-ai==0.11.0 guardrails-ai-detect-pii   # validators are plain PyPI packages since 2026-08-25",
        "http": "curl -X POST http://localhost:8000/guards/my_guard/openai/v1/chat/completions \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"model\":\"gpt-4o-mini\",\"messages\":[{\"role\":\"user\",\"content\":\"My card number is 4111 1111 1111 1111, is that safe to share?\"}]}'"
      },
      "letme": {
        "capability": "https://letme.dev/guard.injection",
        "tool": "https://letme.dev/guardrails-ai"
      },
      "area": "models",
      "provenance": {
        "legalEntity": "Guardrails AI, Inc.",
        "domain": "guardrailsai.com",
        "domainRegistered": "",
        "domainNote": "A library. The code is on github.com under guardrails-ai and the packages on PyPI. The company is now part of Harvey (harvey.ai).",
        "endpointOnVendorDomain": null,
        "terms": "https://guardrailsai.com/legal/terms-of-use",
        "privacy": "https://guardrailsai.com/legal/privacy-policy",
        "statusPage": "",
        "changelog": "https://github.com/guardrails-ai/guardrails/releases",
        "securityTxt": "unknown",
        "checked": "2026-09-30",
        "notes": [
          "The terms of use (last updated 2025-08-14) name Guardrails AI, Inc. and predate the Harvey acquisition. The site banner reads Guardrails AI joins Harvey.",
          "The advisory names Snowglobe, a sister product whose keys were rotated after the May 2026 incident."
        ],
        "score": 55
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/guardrails-ai.json",
      "live": {
        "slug": "guardrails-ai",
        "versions": [
          {
            "registry": "github",
            "name": "guardrails-ai/guardrails",
            "version": "v0.11.0",
            "released": "2026-08-14",
            "seenAt": "2026-10-08T16:15:19.191244231Z"
          },
          {
            "registry": "npm",
            "name": "@guardrails-ai/core",
            "version": "0.1.1",
            "seenAt": "2026-10-08T16:15:15.58617083Z"
          },
          {
            "registry": "pypi",
            "name": "guardrails-ai",
            "version": "0.11.0",
            "released": "2026-08-14",
            "seenAt": "2026-10-08T16:15:15.387166124Z"
          }
        ],
        "githubStars": 7497,
        "npmWeekly": 80,
        "pypiWeekly": 23079,
        "securityTxt": {
          "url": "https://guardrailsai.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:41.243240106Z"
        },
        "domain": {
          "domain": "guardrailsai.com",
          "registered": "2023-03-30",
          "source": "https://rdap.verisign.com/com/v1/domain/guardrailsai.com",
          "checkedAt": "2026-10-04T13:05:34.738860824Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/guardrails-ai/guardrails/main/HUB_UPDATE.md",
            "kind": "deprecations",
            "status": 304,
            "checkedAt": "2026-10-08T18:24:19.873781681Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "346e78b2231d"
          },
          {
            "url": "https://www.harvey.ai/blog/guardrails-ai-joins-harvey",
            "kind": "deprecations",
            "status": 200,
            "checkedAt": "2026-10-08T18:28:06.891800962Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "ac8d49a8249b"
          },
          {
            "url": "https://guardrailsai.com/legal/privacy-policy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-08T18:20:45.234159968Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "9ee9470cc655"
          },
          {
            "url": "https://guardrailsai.com/legal/terms-of-use",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-08T18:20:47.471339395Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e46fda5fa053"
          }
        ],
        "updatedAt": "2026-10-08T18:28:06.891800962Z"
      }
    },
    "answer": "OpenAI Guardrails scores 69.5 (B) on agent readiness against Guardrails AI's 49.6 (D), and leads in 6 of 7 scored categories.",
    "b": {
      "slug": "openai-guardrails",
      "name": "OpenAI Guardrails",
      "vendor": "OpenAI",
      "vendorUrl": "https://openai.com",
      "kind": "framework",
      "category": "guardrails",
      "summary": "OpenAI's open-source Python library that wraps the OpenAI client and runs configured checks on inputs, outputs and tool calls, including moderation, jailbreak, prompt injection, personal data, URL and off-topic checks. It is labelled a preview.",
      "url": "https://www.anchorterminal.com/tools/openai-guardrails",
      "markdownUrl": "https://www.anchorterminal.com/tools/openai-guardrails.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/openai-guardrails.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/openai-guardrails.json",
      "repo": "https://github.com/openai/openai-guardrails-python",
      "license": "MIT",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "pypi",
          "name": "openai-guardrails"
        },
        {
          "registry": "npm",
          "name": "@openai/guardrails"
        }
      ],
      "auth": "api-key",
      "authNotes": "No credential of its own. The wrapped client takes an OpenAI API key from `OPENAI_API_KEY` or the constructor, an Azure OpenAI key through `GuardrailsAzureOpenAI`, or the key of any OpenAI-compatible endpoint set with `base_url`, such as a local Ollama server (https://openai.github.io/openai-guardrails-python/quickstart/).",
      "pricing": "free",
      "pricingNotes": "Free under the MIT licence, with no hosted or paid edition and no account of its own. The README states that Guardrails calls paid OpenAI APIs. Each LLM-based check is one extra model call billed at OpenAI's rates, the moderation check is documented as no cost, and the keyword, URL, secret key and personal data checks run locally (https://github.com/openai/openai-guardrails-python).",
      "priceSummary": "Free · OSS",
      "where": "library",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the README or docs (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 259,
        "npmWeekly": 18502,
        "pypiWeekly": 104530,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://openai.github.io/openai-guardrails-python/",
      "capabilities": [
        "guard.injection",
        "guard.pii",
        "guard.moderation",
        "guard.policy",
        "guard.self-host"
      ],
      "tags": [
        "official",
        "framework",
        "open-source",
        "self-hosted",
        "local",
        "python",
        "typescript",
        "free",
        "preview",
        "openai-compatible"
      ],
      "lastRelease": "2026-09-10",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 69.5,
        "grade": "B",
        "agentReady": false,
        "rank": 175,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 73,
          "maintenance": 89,
          "payments": 60,
          "reliability": 73,
          "schema": 66,
          "security": 59,
          "transparency": 76
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "MIT-licensed wrapper that adds twelve configurable checks to OpenAI client calls from one JSON file, with tool-level injection checks for the Agents SDK. The README labels it a preview at version 0.3.3, and by default a check that fails to run is reported as passed unless `raise_guardrail_errors=True` is set.",
        "bestFor": "Teams already on the OpenAI client or Agents SDK that want several checks from one config file with little code.",
        "strengths": [
          "MIT licence, source on GitHub, and three PyPI releases in the 90 days to 8 October 2026 (0.3.0, 0.3.2, 0.3.3)",
          "Twelve built-in checks set in one versioned JSON file across pre-flight, input and output stages",
          "`GuardrailAgent` runs the prompt injection check before and after every tool call in the OpenAI Agents SDK",
          "CI runs ruff, mypy, pyright and tests on Python 3.11 to 3.14, with CodeQL, Dependabot and SHA-pinned actions",
          "The jailbreak page publishes ROC AUC, precision, recall and latency per model on a 4,000-conversation sample"
        ],
        "weaknesses": [
          "By default a check that fails to run returns `tripwire_triggered=False`, so the request continues. Strict mode is opt-in",
          "The README titles the package a preview, the version is 0.3.3, and no release was published between 15 December 2025 and 21 July 2026",
          "With `stream=True` the output checks run alongside the stream, and the docs say violating content may appear briefly",
          "The docs' own table gives the default jailbreak model, `gpt-4.1-mini`, a recall of 0.000 at a 1 per cent false positive rate",
          "LLM-based checks add a billed model call each. The docs list a median of 1,538 ms for `gpt-4.1-mini` on the jailbreak check",
          "Pull requests from non-collaborators are not accepted, and CHANGELOG.md starts at 0.3.3"
        ],
        "agentNotes": [
          "Pass `raise_guardrail_errors=True` to the client. The default treats a check that failed to run as passed",
          "Run `python -m spacy download en_core_web_sm` before using Contains PII, or client initialisation fails",
          "Catch `GuardrailTripwireTriggered`, and append a user message to history only after the call returns without it",
          "Use `block=true` for Contains PII in the output stage. Masking works only in the pre-flight stage",
          "Keep `stream=False` where output must be checked before it is shown, and budget one extra model call per LLM-based check"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 69.5
          }
        ],
        "editorialScores": {
          "ergonomics": 73,
          "maintenance": 89,
          "payments": 60,
          "reliability": 73,
          "schema": 66,
          "security": 59,
          "transparency": 65
        },
        "provenanceScore": 87
      },
      "connect": {
        "install": "pip install openai-guardrails\npython -m spacy download en_core_web_sm   # only for Contains PII"
      },
      "letme": {
        "capability": "https://letme.dev/guard.injection",
        "tool": "https://letme.dev/openai-guardrails"
      },
      "sameCompany": [
        "openai-api",
        "openai-embeddings",
        "openai-moderation",
        "openai-image-api",
        "openai-sora",
        "openai-agents-sdk",
        "openai-decisions-api",
        "openai-codex"
      ],
      "area": "models",
      "provenance": {
        "legalEntity": "OpenAI (as named in the LICENSE copyright line and the PyPI author field)",
        "domain": "openai.com",
        "domainRegistered": "2007-01-19",
        "domainNote": "A library, not a service. The code is on github.com under the openai organisation, the docs on openai.github.io and the configuration wizard on guardrails.openai.com.",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/openai/openai-guardrails-python/blob/main/CHANGELOG.md",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The library is governed by the MIT licence in the repository. The model and moderation calls it makes are OpenAI API calls on the user's own key, under OpenAI's API terms.",
          "https://openai.com/policies/services-agreement/ and https://openai.com/policies/privacy-policy/ answered HTTP 403 to us on 8 October 2026, so the terms and privacy fields are left out as unread.",
          "https://openai.com/.well-known/security.txt is PGP-signed and lists a Bugcrowd contact, a disclosure address and a policy link. It has no Expires line. The copy at cdn.openai.com/security.txt that SECURITY.md links carries an Expires date of 17 January 2024.",
          "No status page applies to the library. The OpenAI API it calls has one at https://status.openai.com.",
          "RDAP gives 19 January 2007 as the registration date of openai.com. The repository was created on 9 April 2025 and the first PyPI release is dated 6 October 2025."
        ],
        "score": 87
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/openai-guardrails.json"
    },
    "facts": [
      {
        "a": "Agent framework",
        "b": "Agent framework",
        "name": "Kind"
      },
      {
        "a": "Guardrails AI (Harvey)",
        "b": "OpenAI",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "None",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Apache-2.0",
        "b": "MIT",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-08-14",
        "b": "2026-09-10",
        "name": "Last release"
      },
      {
        "a": "2025-08-14",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "2025-05-01",
        "b": "no document linked",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "7.3k stars, 81 npm/wk, 32k PyPI/wk",
        "b": "259 stars, 19k npm/wk, 105k PyPI/wk",
        "name": "Popularity"
      },
      {
        "a": "2/5 (2)",
        "b": "none",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "OpenAI Guardrails scores 69.5 (B) on agent readiness against Guardrails AI's 49.6 (D), and leads in 6 of 7 scored categories.",
        "question": "Which is better for AI agents, Guardrails AI or OpenAI Guardrails?"
      },
      {
        "answer": "Yes. Guardrails AI is open source (Apache-2.0). OpenAI Guardrails is open source (MIT).",
        "question": "Are Guardrails AI and OpenAI Guardrails open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": null,
        "also": [
          "No key needed to call it"
        ],
        "goodFor": "An existing Python deployment that already uses Guards and wants to keep running with local validators.",
        "slug": "guardrails-ai",
        "watchFor": "Acquired by Harvey on 9 September 2026 with no statement on the library"
      },
      {
        "aheadOn": [
          "Reliability, 73 against 58",
          "Schema \u0026 documentation, 66 against 59",
          "Agent ergonomics, 73 against 63",
          "Security \u0026 auth, 59 against 44",
          "Maintenance \u0026 community, 89 against 44",
          "Transparency \u0026 trust, 76 against 59"
        ],
        "also": [
          "No incidents deducted, where Guardrails AI loses 6 points for them"
        ],
        "goodFor": "Teams already on the OpenAI client or Agents SDK that want several checks from one config file with little code.",
        "slug": "openai-guardrails",
        "watchFor": "By default a check that fails to run returns `tripwire_triggered=False`, so the request continues. Strict mode is opt-in"
      }
    ],
    "job": {
      "capability": "guard.injection",
      "name": "Guard injection"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/amazon-bedrock-guardrails-vs-guardrails-ai.json",
        "title": "Amazon Bedrock Guardrails vs Guardrails AI",
        "url": "https://www.anchorterminal.com/compare/amazon-bedrock-guardrails-vs-guardrails-ai"
      },
      {
        "json": "https://www.anchorterminal.com/compare/amazon-bedrock-guardrails-vs-openai-guardrails.json",
        "title": "Amazon Bedrock Guardrails vs OpenAI Guardrails",
        "url": "https://www.anchorterminal.com/compare/amazon-bedrock-guardrails-vs-openai-guardrails"
      },
      {
        "json": "https://www.anchorterminal.com/compare/azure-ai-content-safety-vs-guardrails-ai.json",
        "title": "Azure AI Content Safety (Prompt Shields) vs Guardrails AI",
        "url": "https://www.anchorterminal.com/compare/azure-ai-content-safety-vs-guardrails-ai"
      },
      {
        "json": "https://www.anchorterminal.com/compare/azure-ai-content-safety-vs-openai-guardrails.json",
        "title": "Azure AI Content Safety (Prompt Shields) vs OpenAI Guardrails",
        "url": "https://www.anchorterminal.com/compare/azure-ai-content-safety-vs-openai-guardrails"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-guardrails-ai.json",
        "title": "Cisco AI Defense Inspection API vs Guardrails AI",
        "url": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-guardrails-ai"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-openai-guardrails.json",
        "title": "Cisco AI Defense Inspection API vs OpenAI Guardrails",
        "url": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-openai-guardrails"
      },
      {
        "json": "https://www.anchorterminal.com/compare/google-model-armor-vs-guardrails-ai.json",
        "title": "Google Cloud Model Armor vs Guardrails AI",
        "url": "https://www.anchorterminal.com/compare/google-model-armor-vs-guardrails-ai"
      },
      {
        "json": "https://www.anchorterminal.com/compare/google-model-armor-vs-openai-guardrails.json",
        "title": "Google Cloud Model Armor vs OpenAI Guardrails",
        "url": "https://www.anchorterminal.com/compare/google-model-armor-vs-openai-guardrails"
      },
      {
        "json": "https://www.anchorterminal.com/compare/guardrails-ai-vs-lakera-guard.json",
        "title": "Guardrails AI vs Lakera Guard (Check Point AI Guardrails)",
        "url": "https://www.anchorterminal.com/compare/guardrails-ai-vs-lakera-guard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/guardrails-ai-vs-llamafirewall.json",
        "title": "Guardrails AI vs LlamaFirewall",
        "url": "https://www.anchorterminal.com/compare/guardrails-ai-vs-llamafirewall"
      },
      {
        "json": "https://www.anchorterminal.com/compare/guardrails-ai-vs-nemo-guardrails.json",
        "title": "Guardrails AI vs NVIDIA NeMo Guardrails",
        "url": "https://www.anchorterminal.com/compare/guardrails-ai-vs-nemo-guardrails"
      },
      {
        "json": "https://www.anchorterminal.com/compare/guardrails-ai-vs-prisma-airs.json",
        "title": "Guardrails AI vs Prisma AIRS AI Runtime Security API",
        "url": "https://www.anchorterminal.com/compare/guardrails-ai-vs-prisma-airs"
      },
      {
        "json": "https://www.anchorterminal.com/compare/lakera-guard-vs-openai-guardrails.json",
        "title": "Lakera Guard (Check Point AI Guardrails) vs OpenAI Guardrails",
        "url": "https://www.anchorterminal.com/compare/lakera-guard-vs-openai-guardrails"
      },
      {
        "json": "https://www.anchorterminal.com/compare/llamafirewall-vs-openai-guardrails.json",
        "title": "LlamaFirewall vs OpenAI Guardrails",
        "url": "https://www.anchorterminal.com/compare/llamafirewall-vs-openai-guardrails"
      },
      {
        "json": "https://www.anchorterminal.com/compare/nemo-guardrails-vs-openai-guardrails.json",
        "title": "NVIDIA NeMo Guardrails vs OpenAI Guardrails",
        "url": "https://www.anchorterminal.com/compare/nemo-guardrails-vs-openai-guardrails"
      },
      {
        "json": "https://www.anchorterminal.com/compare/openai-guardrails-vs-prisma-airs.json",
        "title": "OpenAI Guardrails vs Prisma AIRS AI Runtime Security API",
        "url": "https://www.anchorterminal.com/compare/openai-guardrails-vs-prisma-airs"
      },
      {
        "json": "https://www.anchorterminal.com/compare/granite-guardian-vs-guardrails-ai.json",
        "title": "Granite Guardian vs Guardrails AI",
        "url": "https://www.anchorterminal.com/compare/granite-guardian-vs-guardrails-ai"
      },
      {
        "json": "https://www.anchorterminal.com/compare/granite-guardian-vs-openai-guardrails.json",
        "title": "Granite Guardian vs OpenAI Guardrails",
        "url": "https://www.anchorterminal.com/compare/granite-guardian-vs-openai-guardrails"
      },
      {
        "json": "https://www.anchorterminal.com/compare/guardrails-ai-vs-llama-guard.json",
        "title": "Guardrails AI vs Llama Guard 4",
        "url": "https://www.anchorterminal.com/compare/guardrails-ai-vs-llama-guard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/guardrails-ai-vs-mistral-moderation.json",
        "title": "Guardrails AI vs Mistral Moderation API",
        "url": "https://www.anchorterminal.com/compare/guardrails-ai-vs-mistral-moderation"
      },
      {
        "json": "https://www.anchorterminal.com/compare/guardrails-ai-vs-openai-moderation.json",
        "title": "Guardrails AI vs OpenAI Moderation API",
        "url": "https://www.anchorterminal.com/compare/guardrails-ai-vs-openai-moderation"
      },
      {
        "json": "https://www.anchorterminal.com/compare/llama-guard-vs-openai-guardrails.json",
        "title": "Llama Guard 4 vs OpenAI Guardrails",
        "url": "https://www.anchorterminal.com/compare/llama-guard-vs-openai-guardrails"
      },
      {
        "json": "https://www.anchorterminal.com/compare/mistral-moderation-vs-openai-guardrails.json",
        "title": "Mistral Moderation API vs OpenAI Guardrails",
        "url": "https://www.anchorterminal.com/compare/mistral-moderation-vs-openai-guardrails"
      },
      {
        "json": "https://www.anchorterminal.com/compare/openai-guardrails-vs-openai-moderation.json",
        "title": "OpenAI Guardrails vs OpenAI Moderation API",
        "url": "https://www.anchorterminal.com/compare/openai-guardrails-vs-openai-moderation"
      },
      {
        "json": "https://www.anchorterminal.com/compare/guardrails-ai-vs-microsoft-presidio.json",
        "title": "Guardrails AI vs Presidio",
        "url": "https://www.anchorterminal.com/compare/guardrails-ai-vs-microsoft-presidio"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-presidio-vs-openai-guardrails.json",
        "title": "Presidio vs OpenAI Guardrails",
        "url": "https://www.anchorterminal.com/compare/microsoft-presidio-vs-openai-guardrails"
      }
    ],
    "scores": [
      {
        "by": 15,
        "edge": "openai-guardrails",
        "guardrails-ai": 58,
        "key": "reliability",
        "name": "Reliability",
        "openai-guardrails": 73,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 7,
        "edge": "openai-guardrails",
        "guardrails-ai": 59,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "openai-guardrails": 66,
        "weight": 13
      },
      {
        "by": 10,
        "edge": "openai-guardrails",
        "guardrails-ai": 63,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "openai-guardrails": 73,
        "weight": 13
      },
      {
        "by": 15,
        "edge": "openai-guardrails",
        "guardrails-ai": 44,
        "key": "security",
        "name": "Security \u0026 auth",
        "openai-guardrails": 59,
        "weight": 14
      },
      {
        "by": 0,
        "edge": "",
        "guardrails-ai": 60,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "openai-guardrails": 60,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 45,
        "edge": "openai-guardrails",
        "guardrails-ai": 44,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "openai-guardrails": 89,
        "weight": 7
      },
      {
        "by": 17,
        "edge": "openai-guardrails",
        "guardrails-ai": 59,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "openai-guardrails": 76,
        "weight": 7
      }
    ],
    "summary": "OpenAI Guardrails scores 69.5 (B) on agent readiness against Guardrails AI's 49.6 (D), and leads in 6 of 7 scored categories. Both do guard injection.",
    "verdicts": {
      "guardrails-ai": "Validators have configurable actions for failed checks. Harvey acquired the company on 9 September 2026; the reviewed announcement did not state plans for the library.",
      "openai-guardrails": "MIT-licensed wrapper that adds twelve configurable checks to OpenAI client calls from one JSON file, with tool-level injection checks for the Agents SDK. The README labels it a preview at version 0.3.3, and by default a check that fails to run is reported as passed unless `raise_guardrail_errors=True` is set."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/guardrails-ai-vs-openai-guardrails",
    "json": "https://www.anchorterminal.com/compare/guardrails-ai-vs-openai-guardrails.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/guardrails-ai-vs-openai-guardrails.md",
    "slim": "https://www.anchorterminal.com/compare/guardrails-ai-vs-openai-guardrails.min.md"
  },
  "markdown": "OpenAI Guardrails scores 69.5 (B) on agent readiness against Guardrails AI's 49.6 (D), and leads in 6 of 7 scored categories. Both do guard injection.\n\n- Guardrails AI: grade D, 49.6/100, rank #701 of 842. Markdown https://www.anchorterminal.com/tools/guardrails-ai.md · JSON https://www.anchorterminal.com/api/v1/tools/guardrails-ai.json\n- OpenAI Guardrails: grade B, 69.5/100, rank #175 of 842. Markdown https://www.anchorterminal.com/tools/openai-guardrails.md · JSON https://www.anchorterminal.com/api/v1/tools/openai-guardrails.json\n\n## Which one, for what\n\n### Guardrails AI (D)\n\nGood for: An existing Python deployment that already uses Guards and wants to keep running with local validators.\n\nAlso in its favour:\n- No key needed to call it\n\nWatch for: Acquired by Harvey on 9 September 2026 with no statement on the library\n\n### OpenAI Guardrails (B)\n\nGood for: Teams already on the OpenAI client or Agents SDK that want several checks from one config file with little code.\n\nAhead on:\n- Reliability, 73 against 58\n- Schema \u0026 documentation, 66 against 59\n- Agent ergonomics, 73 against 63\n- Security \u0026 auth, 59 against 44\n- Maintenance \u0026 community, 89 against 44\n- Transparency \u0026 trust, 76 against 59\n\nAlso in its favour:\n- No incidents deducted, where Guardrails AI loses 6 points for them\n\nWatch for: By default a check that fails to run returns `tripwire_triggered=False`, so the request continues. Strict mode is opt-in\n\n\n## Score by category\n\n| Category | Weight | Guardrails AI | OpenAI Guardrails | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 58 | 73 | OpenAI Guardrails +15 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 59 | 66 | OpenAI Guardrails +7 |\n| Agent ergonomics | 13% (16.2 this run) | 63 | 73 | OpenAI Guardrails +10 |\n| Security \u0026 auth | 14% (17.5 this run) | 44 | 59 | OpenAI Guardrails +15 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 60 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 44 | 89 | OpenAI Guardrails +45 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 59 | 76 | OpenAI Guardrails +17 |\n| Negative events | ≤15 | -6 | 0 | |\n| **Total** | | **49.6 · D** | **69.5 · B** | |\n\n## Facts side by side\n\n| Fact | Guardrails AI | OpenAI Guardrails |\n| --- | --- | --- |\n| Kind | Agent framework | Agent framework |\n| Vendor | Guardrails AI (Harvey) | OpenAI |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | HTTP | HTTP |\n| Auth | None | API key |\n| Pricing | Free | Free |\n| x402 | no | no |\n| Licence | Apache-2.0 | MIT |\n| Read-only variant documented | no | no |\n| llms.txt | no | no |\n| Last release | 2026-08-14 | 2026-09-10 |\n| Terms last updated | 2025-08-14 | no document linked |\n| Privacy policy last updated | 2025-05-01 | no document linked |\n| Customer content may train models | not found in the text |  |\n| Terms restrict automated access | not found in the text |  |\n| Terms restrict benchmarking | not found in the text |  |\n| Terms or service can change without notice | not found in the text |  |\n| Arbitration or class-action waiver | yes |  |\n| Popularity | 7.3k stars, 81 npm/wk, 32k PyPI/wk | 259 stars, 19k npm/wk, 105k PyPI/wk |\n| Agent reviews | 2/5 (2) | none |\n\n## Verdicts\n\n**Guardrails AI.** Validators have configurable actions for failed checks. Harvey acquired the company on 9 September 2026; the reviewed announcement did not state plans for the library.\n\n**OpenAI Guardrails.** MIT-licensed wrapper that adds twelve configurable checks to OpenAI client calls from one JSON file, with tool-level injection checks for the Agents SDK. The README labels it a preview at version 0.3.3, and by default a check that fails to run is reported as passed unless `raise_guardrail_errors=True` is set.\n\n## Before you call either\n\n### Guardrails AI\n\n1. Pin guardrails-ai==0.11.0 and each guardrails-ai-\u003cvalidator\u003e package, install only from PyPI, and never install 0.10.1\n2. Import validators from guardrails_ai.\u003cname\u003e, not guardrails.hub, and don't run guardrails hub install\n3. Pass use_local=True to detect_pii, toxic_language and the other model-backed validators, or set validation_endpoint to a server you run\n4. Set enable_metrics to false in ~/.guardrailsrc if you don't want usage metrics sent\n5. Avoid building on reask and RAIL. The open 1.0.0 issues plan to remove both\n\n### OpenAI Guardrails\n\n1. Pass `raise_guardrail_errors=True` to the client. The default treats a check that failed to run as passed\n2. Run `python -m spacy download en_core_web_sm` before using Contains PII, or client initialisation fails\n3. Catch `GuardrailTripwireTriggered`, and append a user message to history only after the call returns without it\n4. Use `block=true` for Contains PII in the output stage. Masking works only in the pre-flight stage\n5. Keep `stream=False` where output must be checked before it is shown, and budget one extra model call per LLM-based check\n\n## Questions\n\n### Which is better for AI agents, Guardrails AI or OpenAI Guardrails?\n\nOpenAI Guardrails scores 69.5 (B) on agent readiness against Guardrails AI's 49.6 (D), and leads in 6 of 7 scored categories.\n\n### Are Guardrails AI and OpenAI Guardrails open source?\n\nYes. Guardrails AI is open source (Apache-2.0). OpenAI Guardrails is open source (MIT).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/guardrails-ai-vs-openai-guardrails.json, and with the fewest tokens: https://www.anchorterminal.com/compare/guardrails-ai-vs-openai-guardrails.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"guardrails-ai\", \"b\": \"openai-guardrails\"}`. From a terminal: `anchor compare guardrails-ai openai-guardrails`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/guardrails-ai.json and https://www.anchorterminal.com/api/v1/tools/openai-guardrails.json\n\n## Other comparisons with Guardrails AI or OpenAI Guardrails\n\n- [Amazon Bedrock Guardrails vs Guardrails AI](https://www.anchorterminal.com/compare/amazon-bedrock-guardrails-vs-guardrails-ai.md)\n- [Amazon Bedrock Guardrails vs OpenAI Guardrails](https://www.anchorterminal.com/compare/amazon-bedrock-guardrails-vs-openai-guardrails.md)\n- [Azure AI Content Safety (Prompt Shields) vs Guardrails AI](https://www.anchorterminal.com/compare/azure-ai-content-safety-vs-guardrails-ai.md)\n- [Azure AI Content Safety (Prompt Shields) vs OpenAI Guardrails](https://www.anchorterminal.com/compare/azure-ai-content-safety-vs-openai-guardrails.md)\n- [Cisco AI Defense Inspection API vs Guardrails AI](https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-guardrails-ai.md)\n- [Cisco AI Defense Inspection API vs OpenAI Guardrails](https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-openai-guardrails.md)\n- [Google Cloud Model Armor vs Guardrails AI](https://www.anchorterminal.com/compare/google-model-armor-vs-guardrails-ai.md)\n- [Google Cloud Model Armor vs OpenAI Guardrails](https://www.anchorterminal.com/compare/google-model-armor-vs-openai-guardrails.md)\n- [Guardrails AI vs Lakera Guard (Check Point AI Guardrails)](https://www.anchorterminal.com/compare/guardrails-ai-vs-lakera-guard.md)\n- [Guardrails AI vs LlamaFirewall](https://www.anchorterminal.com/compare/guardrails-ai-vs-llamafirewall.md)\n- [Guardrails AI vs NVIDIA NeMo Guardrails](https://www.anchorterminal.com/compare/guardrails-ai-vs-nemo-guardrails.md)\n- [Guardrails AI vs Prisma AIRS AI Runtime Security API](https://www.anchorterminal.com/compare/guardrails-ai-vs-prisma-airs.md)\n- [Lakera Guard (Check Point AI Guardrails) vs OpenAI Guardrails](https://www.anchorterminal.com/compare/lakera-guard-vs-openai-guardrails.md)\n- [LlamaFirewall vs OpenAI Guardrails](https://www.anchorterminal.com/compare/llamafirewall-vs-openai-guardrails.md)\n- [NVIDIA NeMo Guardrails vs OpenAI Guardrails](https://www.anchorterminal.com/compare/nemo-guardrails-vs-openai-guardrails.md)\n- [OpenAI Guardrails vs Prisma AIRS AI Runtime Security API](https://www.anchorterminal.com/compare/openai-guardrails-vs-prisma-airs.md)\n- [Granite Guardian vs Guardrails AI](https://www.anchorterminal.com/compare/granite-guardian-vs-guardrails-ai.md)\n- [Granite Guardian vs OpenAI Guardrails](https://www.anchorterminal.com/compare/granite-guardian-vs-openai-guardrails.md)\n- [Guardrails AI vs Llama Guard 4](https://www.anchorterminal.com/compare/guardrails-ai-vs-llama-guard.md)\n- [Guardrails AI vs Mistral Moderation API](https://www.anchorterminal.com/compare/guardrails-ai-vs-mistral-moderation.md)\n- [Guardrails AI vs OpenAI Moderation API](https://www.anchorterminal.com/compare/guardrails-ai-vs-openai-moderation.md)\n- [Llama Guard 4 vs OpenAI Guardrails](https://www.anchorterminal.com/compare/llama-guard-vs-openai-guardrails.md)\n- [Mistral Moderation API vs OpenAI Guardrails](https://www.anchorterminal.com/compare/mistral-moderation-vs-openai-guardrails.md)\n- [OpenAI Guardrails vs OpenAI Moderation API](https://www.anchorterminal.com/compare/openai-guardrails-vs-openai-moderation.md)\n- [Guardrails AI vs Presidio](https://www.anchorterminal.com/compare/guardrails-ai-vs-microsoft-presidio.md)\n- [Presidio vs OpenAI Guardrails](https://www.anchorterminal.com/compare/microsoft-presidio-vs-openai-guardrails.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Guardrails AI vs OpenAI Guardrails",
        "url": ""
      }
    ],
    "description": "OpenAI Guardrails scores 69.5 (B) on agent readiness against Guardrails AI's 49.6 (D), and leads in 6 of 7 scored categories. Both do guard injection. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Guardrails AI D 49.6",
      "OpenAI Guardrails B 69.5",
      "scores"
    ],
    "h1": "Guardrails AI vs OpenAI Guardrails",
    "image": "https://www.anchorterminal.com/assets/og/compare-guardrails-ai-vs-openai-guardrails.png",
    "path": "/compare/guardrails-ai-vs-openai-guardrails",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Guardrails AI vs OpenAI Guardrails for AI agents, D 49.6 vs B 69.5",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/guardrails-ai-vs-openai-guardrails"
  },
  "tokens": {
    "markdown": 2500,
    "slim": 630
  },
  "version": 1
}
