7456 stars · Apache-2.0 — read from /blob/main/LICENSE, plain unmodified text, appendix left as the stock '[yyyy] [name of copyright owner]' template so no copyright holder is asserted · v0.11.0 of 2026-08-14, the yearless GitHub date settled by PyPI · Track this in Scout
Adds checks around a language model's output, covering content as well as shape.
▶Repo detailsthe review · specs · pros & cons · install
What it is
A Python framework at 7,456 stars, created in January 2023, that puts an input guard and an output guard around a model call. Each guard runs small components called validators, and the answer can be forced into a defined shape. Version 0.11.0 is dated 14 August 2026 and code landed on 25 September 2026.
What it is good for. Anyone putting a language model in front of other people who needs the answer checked before it is shown, and needs the answer as structured data rather than a paragraph to be picked apart. It is worth the effort at the point where "usually correct" stops being acceptable.
- Apache-2.0, read from the licence file and entirely plain.
- The checks are separate, small and composable, so you add the two you need instead of adopting a whole opinionated system.
- The vendor account requirement has gone. Version 0.11.0 removed the private component registry and the tool that talked to it, and every check is now an ordinary Python package. Setting up now only asks whether you want to send anonymous usage figures.
- That change is a migration in progress, not a finished one. Anyone on an older version using the old install command has to move, and the page that documented the old hosted checking is already missing.
- The checks are now your problem to run. Many of them are machine-learning models that download their own files and run on your machine, and no memory, disk or processor figures are published anywhere for a project that until recently offered to do that work on its own servers.
- Still before version 1.0 after three and a half years, and the last two versions removed features that had shipped. The set of commands you write against is not settled.
- 54 open pull requests against 38 open issues, which suggests contributions arrive faster than they are reviewed. The Python window is fixed at 3.10 or later and below 3.14.
- NVIDIA/NeMo-Guardrails
The same job of putting rules around a model, at almost the same size and equally active, but organised around the shape of a conversation in a small modelling language of its own.
Track this in Scout
567-labs/instructorOverlaps only the structured-answer half — defined shapes and automatic retries — and is the leaner choice when a safety layer is not wanted.
Track this in Scout- protectai/llm-guard
Was the closest local equivalent with fifteen input and twenty output checks, archived by its owner on 9 July 2026, with its published models abandoned too.
Track this in Scout
python3 -m venv venv && source venv/bin/activate pip install guardrails-ai guardrails configure