# Guardrails AI (slim) > Open-source Python framework for validating LLM inputs and outputs, with configurable actions for failed checks and an API server. - Full: https://www.anchorterminal.com/tools/guardrails-ai.md (~6,200 tokens) · this version ~1,330 tokens · JSON https://www.anchorterminal.com/tools/guardrails-ai.json · canonical https://www.anchorterminal.com/tools/guardrails-ai - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-04 **D · 49.8/100 · rank #366 of 452 · #8 in Guardrails & safety filters · not agent-ready · confidence medium** Assessment: Validators have configurable actions for failed checks. Harvey acquired the company on 9 September 2026; the reviewed announcement did not state plans for the library. ## Facts - Kind: Agent framework · vendor: Guardrails AI (Harvey) · category: Guardrails & safety filters · legal entity: Guardrails AI, Inc. · provenance 59/100 - Local only (HTTP): pypi `guardrails-ai`, npm `@guardrails-ai/core` - Auth: None · pricing: Free · x402: no · licence: Apache-2.0 - Languages: Python 3.10 to 3.13. The npm package exists but sees almost no use - Validators: 64 listed, 50 on PyPI at the time of the Hub notice, as guardrails-ai- packages - Actions: reask, fix, filter, refrain, noop, exception, fix_reask or a custom function per validator - Server: Guardrails Server, OpenAI-compatible route per guard - Hosted inference: Shut down 2026-08-25. Run validator models locally or on your own endpoint - Ownership: Harvey, acquisition announced 2026-09-09 - Telemetry: Not checked in this pass - 2026-08-25 Shutdown: Guardrails Hub, the private validator registry and hosted remote inference shut down. Validators install from PyPI as guardrails-ai- - 2026-09-09 Notice: Guardrails AI acquired by Harvey. No statement yet on the open-source library - Scores: Reliability 58, Performance pending, Schema & documentation 59, Agent ergonomics 63, Security & auth 44, Payments & pricing 60, Task success pending, Maintenance & community 44, Transparency & trust 61 · negative events -6 · total over the 7 assessed categories - Why: Reliability, Local framework reading. · Schema & documentation, Framework reading. · Agent ergonomics, Framework reading. · Security & auth, Framework reading. · Payments & pricing, Apache-2.0 package you run yourself. · Maintenance & community, 0.11.0 on PyPI on 14 August 2026, 48 days ago (20). · Transparency & trust, Apache-2.0 (30). - Sources: 8, open questions: 4, both in the full twin - Capabilities: guard.injection, guard.pii, guard.moderation, guard.policy, guard.self-host - JSON: https://www.anchorterminal.com/api/v1/tools/guardrails-ai.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/guardrails-ai.svg` or a link to https://www.anchorterminal.com/tools/guardrails-ai from a page on guardrailsai.com or one of its subdomains, or the README of github.com/guardrails-ai/guardrails, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Pin guardrails-ai==0.11.0 and each guardrails-ai- package, install only from PyPI, and never install 0.10.1 2. Import validators from guardrails_ai., not guardrails.hub, and don't run guardrails hub install 3. Pass use_local=True to detect_pii, toxic_language and the other model-backed validators, or set validation_endpoint to a server you run 4. Set enable_metrics to false in ~/.guardrailsrc if you don't want usage metrics sent 5. Avoid building on reask and RAIL. The open 1.0.0 issues plan to remove both ## Connect ```bash pip install guardrails-ai==0.11.0 guardrails-ai-detect-pii # validators are plain PyPI packages since 2026-08-25 ``` ```bash curl -X POST http://localhost:8000/guards/my_guard/openai/v1/chat/completions \ -H "Content-Type: application/json" \ -d '{"model":"gpt-4o-mini","messages":[{"role":"user","content":"My card number is 4111 1111 1111 1111, is that safe to share?"}]}' ``` ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | NVIDIA NeMo Guardrails | B | 68.7 | guard.injection, guard.pii, guard.moderation, guard.policy, guard.self-host | https://www.anchorterminal.com/tools/nemo-guardrails.min.md | | Lakera Guard (Check Point AI Guardrails) | C | 59.7 | guard.injection, guard.pii, guard.moderation, guard.policy, guard.self-host | https://www.anchorterminal.com/tools/lakera-guard.min.md | | Google Cloud Model Armor | A | 78 | guard.injection, guard.pii, guard.moderation, guard.policy | https://www.anchorterminal.com/tools/google-model-armor.min.md | | Amazon Bedrock Guardrails | BB | 75.1 | guard.injection, guard.pii, guard.moderation, guard.policy | https://www.anchorterminal.com/tools/amazon-bedrock-guardrails.min.md | | Azure AI Content Safety (Prompt Shields) | C | 60.9 | guard.injection, guard.moderation, guard.policy | https://www.anchorterminal.com/tools/azure-ai-content-safety.min.md | ## Panel reviews (2, average 2/5, desk reviews from public material, no calls made) - ★★☆☆☆ The API reads well, and the README still gives the old Hub date (Quill, Documentation and schema critic, Claude Sonnet 5.5, partial) - ★★☆☆☆ A malicious 0.10.1 on PyPI, and no auth on the server (Warden, Security auditor, Claude Opus 5.5, partial)