7,189 stars · Apache-2.0 (read from /blob/develop/LICENSE.md — the default branch is develop and /blob/develop/LICENSE returns 404; standard text, 'NVIDIA CORPORATION & AFFILIATES', no added clause and no commercial condition) · v0.24.1 (2026-09-16, year confirmed by PyPI's nemoguardrails project page) · Track this in Scout
Puts rules you write around a language model's input and output, and enforces them before the answer reaches anybody.
▶Repo detailsthe review · specs · pros & cons · install
What it is
This is a Python library from NVIDIA that wraps a model application in configurable rails. A rail is a rule applied at one point in the flow: the user's question, the documents retrieved to answer it, a tool the model wants to call, or the answer itself. Rules are written in a small language of its own called Colang, alongside YAML settings.
What it is good for. Anybody whose application answers in public. The failure that matters is not a wrong answer, it is a confident answer about something the application was never meant to discuss, or a model persuaded by a visitor to abandon its instructions. This library is the layer that refuses before the answer is sent.
- Checks happen at several separate points, not just on the final text, so a bad document retrieved from your own store can be caught before the model ever reads it.
- The licence is plain Apache-2.0, read from the file, with NVIDIA named as the copyright holder and no added commercial condition.
- It is one of the two serious projects in this field and it is actively worked on: version 0.24.1 landed on 16 September 2026 and code moved on 24 September 2026.
- ⚠ Colang is a language you have to learn. It is Python-like but it is not Python, and it sits on top of the Python and YAML you are already writing.
- ⚠ Every rail costs money and time. Checking a question and checking an answer are extra model requests on top of the one you wanted, and the project publishes no figure for either the added delay or the added cost.
- The jailbreak and content-safety checks download local models, so disk and memory use is substantial and undocumented. There are 153 waiting problems and 107 waiting changes, and development happens on a branch called
develop, which makes the state of the project hard to read at a glance.
guardrails-ai/guardrailsThe same job of checking what goes into and out of a model, at almost the same size and equally active; the difference is that the checks come from a hosted catalogue rather than rules written in a language of its own.
Track this in Scout- meta-llama/PurpleLlama
The same safety-filtering goal, but it ships trained models and benchmarks rather than a framework to organise them, and the models are under the Llama Community License, which is not an approved open-source licence.
Track this in Scout - protectai/llm-guard
The same input and output scanning, with 15 checks on the question and 20 on the answer, and archived by its owner on 9 July 2026.
Track this in Scout
pip install nemoguardrails




