Skip to main content
Favicon of NVIDIA NeMo Guardrails

NVIDIA NeMo Guardrails

What is NVIDIA NeMo Guardrails?

NVIDIA NeMo Guardrails is an open-source Python library for developers that adds programmable safety checks around LLM inputs, outputs, and retrieved content. It combines YAML and Colang with Content Safety, Jailbreak Protection, Topic Control, PII Detection, and Hallucinations & Fact-Checking, and supports Custom Actions plus third-party APIs. The docs point to GitHub, PyPI, and LangGraph integrations, and the package ships as versioned releases from 0.14.1 through 0.21.0.

Last verifiedHow we evaluate

Screenshot of NVIDIA NeMo Guardrails website

At a glance

Best for
NeMo Guardrails is best for developers who need to add policy checks around LLM inputs and outputs.
API
Yes — The library includes a local API server with chat-completions endpoints such as /v1/chat/completions.

What it actually does differently

Most LLM guardrails products are input/output classifiers: check the prompt, check the response, block or pass. NeMo Guardrails adds a third layer most competitors skip — dialog rails, written in a purpose-built language called Colang, that can steer a multi-turn conversation along a predefined path (enforce an authentication step before answering account questions, refuse to discuss a topic across the whole conversation rather than per-message, follow a scripted support flow). This is architecturally closer to a dialogue-management system than a moderation filter. The approach was published and peer-reviewed at EMNLP 2023 (Rebedea et al., "NeMo Guardrails: A Toolkit for Controllable and Safe LLM Applications with Programmable Rails") rather than only described in vendor blog posts (https://aclanthology.org/2023.emnlp-demo.40, https://arxiv.org/abs/2310.10501).

Model and vendor independence

Despite the NVIDIA branding, the library is not locked to NVIDIA models. It ships with LLM self-checking (any provider), and separately integrates NVIDIA's own NemoGuard/Llama-3.1-Nemotron-Safety-Guard models, community models (LlamaGuard), and third-party moderation APIs (ActiveFence, Cisco AI Defense, Prompt Security, Pangea, Microsoft Presidio, Polygraf, GuardrailsAI Hub) as swappable options, documented at https://docs.nvidia.com/nemo/guardrails/about-nemo-guardrails-library/overview. It also runs with OpenAI, Azure OpenAI, and any LangChain-compatible provider via an opt-in LangChain framework switch.

Maturity, stability, and API churn

The project is active: version 0.24.0 shipped 26 August 2026, dependency and bugfix PRs continue to merge weekly (most recently 15 September 2026), and GitHub shows 7,131 stars, 837 forks, and 230 open issues as of today (https://api.github.com/repos/NVIDIA-NeMo/Guardrails). It has moved from NVIDIA/NeMo-Guardrails to a new org, NVIDIA-NeMo/Guardrails — the old URL now 301-redirects and is not archived or dead. Set against that: PyPI's own classifier still lists it as "Development Status :: 4 - Beta" (https://pypi.org/pypi/nemoguardrails/json), and each of the last three releases (0.22, 0.23, 0.24) shipped multiple breaking changes to the Python API and configuration format — renamed methods, changed return types, removed install extras. A team adopting this should expect to revisit integration code on most upgrades, not just read a changelog.

What the security policy tells you not to expect

NVIDIA's own SECURITY.md is unusually explicit about scope: the guardrails server ships with no built-in authentication, no TLS termination, and no rate limiting, and any caller that clears your own gateway can invoke any registered action with no further per-endpoint authorization — these are documented as intentional design decisions, not gaps to be reported as vulnerabilities (https://github.com/NVIDIA-NeMo/Guardrails/blob/develop/SECURITY.md). The assumed deployment model is behind an API gateway, reverse proxy, or service-mesh sidecar that handles authn/authz/TLS/rate-limiting itself. This is a reasonable design for a library component, but it means "guardrails" here does not include securing the guardrails service itself.

Telemetry

The library phones home by default: instantiating LLMRails, IORails, or Guardrails sends an anonymous usage event to NVIDIA, followed by periodic heartbeats from a background thread, and also writes a local audit copy to ~/.config/nemoguardrails/usage_stats.json. NVIDIA documents the payload in detail — installed version, Python/OS, which rail categories and built-in features are configured (by name), counts of custom flows (not their content), and a per-process random UUID — and states no prompts, completions, API keys, or model names are collected. Opt-out is a documented environment variable (NEMO_GUARDRAILS_NO_USAGE_STATS=1 or DO_NOT_TRACK=1) that must be set before the library starts (per the PyPI project README, https://pypi.org/pypi/nemoguardrails/json).

Library vs. the paid path

The Python library itself is free and open source (Apache-2.0, pip install nemoguardrails) with no usage limits — you can run it entirely on your own infrastructure with any model provider. NVIDIA also sells a production "NeMo Guardrails microservice" — a Kubernetes/Helm-deployed container using the same configuration format — that requires an NVIDIA AI Enterprise license. NVIDIA does not publish a price for AI Enterprise anywhere we found; the product page routes to a sales contact and a 90-day free trial rather than a rate card (https://www.nvidia.com/en-us/data-center/products/ai-enterprise). Third-party reviews describe it as priced per GPU, but that is a reviewer's characterization, not a vendor-confirmed figure, so treat it as unverified (https://www.aws.amazon.com/marketplace/pp/prodview-ozgjkov6vq3l6).

Frequently asked questions

What is NVIDIA NeMo Guardrails?

NVIDIA NeMo Guardrails is an open-source Python library for developers that adds programmable safety checks around LLM inputs, outputs, and retrieved content. It combines YAML and Colang with Content Safety, Jailbreak Protection, Topic Control, PII Detection, and Hallucinations & Fact-Checking, and supports Custom Actions plus third-party APIs. The docs point to GitHub, PyPI, and LangGraph integrations, and the package ships as versioned releases from 0.14.1 through 0.21.0.

What is NVIDIA NeMo Guardrails used for? Who is it for?

NVIDIA NeMo Guardrails is used for Content Safety, Jailbreak Protection, and Topic Control. It's built for LLM application developers, Platform engineers, and AI product teams.

Does NVIDIA NeMo Guardrails have an API and what does it integrate with?

The library includes a local API server with chat-completions endpoints such as /v1/chat/completions.

Share:

Sponsored
Favicon

 

  
 

Explore other Agent Tools & Integrations

Favicon

 

  
  
Favicon

 

  
  
Favicon