Guardrails AI: validation and structured output for LLM applications
Adding guardrails to large language models.
At a glance
- What is it?
- Guardrails is an Apache-2.0 Python framework that wraps LLM calls with validators and Pydantic-based output schemas. It is useful when you need to reject or repair model output, but the recent move away from hosted inferencing changes how validators are installed.
- Who is it for?
- Adopt Guardrails if your application already runs Python and you need output validation tied to Pydantic models rather than a separate gateway service. Skip it if you need a language-agnostic proxy or cannot accept the validator packaging change that the July 2026 notice describes.
- Can I use it commercially?
- Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 6 days ago.
- What is it written in?
- Mainly Python, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.
Editorial analysis
The problem Guardrails solves for LLM application developers
An LLM returns text. Your application usually needs something narrower: a phone number in a known format, a JSON object matching a schema, or a response that does not name a competitor. Guardrails sits between the two. The README describes two functions: running Input/Output Guards that detect, quantify and mitigate specific risks, and generating structured data from LLMs.
The audience is Python developers building applications on top of foundation models. The package metadata lists openai, litellm and langchain-core among its dependencies, so it assumes an existing model-calling stack rather than replacing one. If you are writing Go or Java services, nothing here helps you directly.
What makes the project more than a validation library is the Guard object. A Guard is a container you attach validators to, and it can also own the prompt and the call to the model. That means validation and generation share one object, which is convenient inside a Python service and awkward if your generation happens somewhere else.
How a Guard, validators and Pydantic models fit together
The README shows two distinct paths. The validation path starts with a Guard and one or more validators attached via `.use(...)`. Each validator carries an `on_fail` action, and the README example uses `OnFailAction.EXCEPTION`, which raises rather than returning a corrected value. Calling `guard.validate(...)` runs the chain and either passes or raises.
The structured generation path starts from a Pydantic `BaseModel`. The README states that `Guard.for_pydantic(output_class=Pet, prompt=prompt)` builds a Guard that calls the LLM so the output is formatted to that class. Under the hood the README names two mechanisms: function calling for models that support it, and prompt optimization for models that do not, where the expected schema is appended to the prompt.
That second mechanism is the interesting trade-off. Prompt-based schema injection depends on the model following instructions, and the README does not describe what happens when it does not beyond the general validation behaviour. Function calling is more constrained but only available on some models. The dependency on both openai and litellm suggests the project is trying to cover both cases behind one interface, which is also why the dependency list is long for what reads like a validation tool.
Installing guardrails-ai and running a first validator
The README gives the install command directly. It requires Python 3.10 through 3.13 according to the pyproject constraint `>=3.10,<3.14`.
pip install guardrails-aiThe README then describes configuring the Hub CLI, which historically required a token. Note that the July 2026 news item says validators are moving to standard PyPI packages installed directly with pip, and that hosted remote inferencing is being discontinued with a planned cutoff of August 25, 2026.
pip install guardrails-ai
pip install guardrails-ai-regex-matchWith the validator installed, the README builds a Guard around a phone-number regex and validates two strings. The first passes, the second raises because of `OnFailAction.EXCEPTION`.
from guardrails import Guard, OnFailAction
from guardrails_ai.regex_match import RegexMatch
guard = Guard().use(
RegexMatch, regex="\\(?\\d{3}\\)?-? *\\d{3}-? *-?\\d{4}", on_fail=OnFailAction.EXCEPTION
)
guard.validate("123-456-7890")The README shows the failure message as `Validation failed for field with errors: Result must match ...`. Stacking validators works the same way: the README installs `guardrails-ai-competitor-check` and `guardrails-ai-toxic-language` and passes both into a single `.use(...)` call, with the failure output listing the matched competitor and the offending sentence.
Where Guardrails is the wrong tool
The validators are the weak point. The README's installation section assumes a Hub CLI and a Hub-hosted catalogue, yet the same README announces that validators are moving to plain PyPI packages and that hosted remote inferencing is being discontinued. Anyone reading the getting-started steps without reading the news item will follow a workflow that is being replaced. The migration issue is linked from the README, but the install section itself was not rewritten to match, which is a documentation gap rather than a code problem.
There is also a scope limit. Guardrails validates text that passes through a Guard object in your Python process. It does not sit in front of an HTTP endpoint, does not inspect traffic from other services, and does not enforce anything at the network layer. If your models are called from several languages, or if you want policy enforced outside the application, a proxy-style tool fits better.
The dependency list is another cost to weigh. The project pulls in litellm, langchain-core, openai, tiktoken, jsonschema and OpenTelemetry packages. In a small service that only needs a regex check, that is a large surface to carry.
Guardrails compared with NeMo Guardrails and Bedrock Guardrails
People searching for this project often compare it with NeMo Guardrails and Bedrock Guardrails, and the difference is where the logic lives. Guardrails is a Python library you import; its validators run in your process, and its structured output path is built on Pydantic models you define. The Pydantic coupling is the clearest signal of intent: the schema is a Python class, and the Guard is a Python object.
NeMo Guardrails takes a configuration-driven approach, where dialogue flows and policy are expressed declaratively rather than as Python validator objects attached to a Guard. Bedrock Guardrails is a managed service inside AWS, so the policy is configured on the platform and applied to model calls made through it. Choosing between them is mostly a question of where you want the rules to live: in application code, in a config file, or in a cloud account.
Guardrails is the better fit when the validation logic is genuinely application logic, such as checking that a generated value matches a domain-specific format. It is a worse fit when the rules are policy that a platform team wants to own centrally.
Maintenance, licence and the validator migration
The repository is not archived, and the last push was on 2026-09-08, with v0.11.0 released on 2026-08-14. Releases are not frequent: v0.10.0 landed on 2026-04-03 and v0.10.2 on 2026-06-04. The version string in pyproject.toml matches the v0.11.0 tag.
The upgrade cost is concentrated in the validator packaging change. If you installed validators through the Hub CLI, the README points to a migration issue and states a planned cutoff of August 25, 2026 for hosted remote inferencing. That is the thing to plan around, because it changes both how validators are fetched and where they execute. The README does not document a rollback path for that migration.
The licence is Apache-2.0, declared in both the README badge and pyproject.toml. That is a permissive licence, and it is worth noting that the project also depends on packages under other licences; the dev extra includes liccheck, which suggests the maintainers check this themselves. This is not legal advice, and anyone redistributing the package should review the dependency licences independently.
Editorial conclusion
Adopt Guardrails if your application already runs Python and you need output validation tied to Pydantic models rather than a separate gateway service. Skip it if you need a language-agnostic proxy or cannot accept the validator packaging change that the July 2026 notice describes. Before committing, verify that every validator you depend on has a pip-installable replacement, since the hosted remote inferencing cutoff is listed as August 25, 2026.
Frequently asked questions
What is Guardrails AI?
It is a Python framework that runs Input/Output Guards to detect and mitigate specific risks in LLM interactions, and that generates structured data from LLMs. It is distributed as the guardrails-ai package under Apache-2.0.
How to install Guardrails AI?
The README gives `pip install guardrails-ai` as the install command. The pyproject file requires Python >=3.10,<3.14. Individual validators are installed separately, for example `pip install guardrails-ai-regex-match`.
How to use Guardrails with an LLM?
The README shows two patterns. You can attach validators to a Guard with `.use(...)` and call `guard.validate(...)`, or build a Guard from a Pydantic model with `Guard.for_pydantic(output_class=Pet, prompt=prompt)` so the model output is formatted to that class.
How to use Guardrails in LangChain?
The README does not describe a LangChain integration. The pyproject file lists langchain-core as a dependency, but there is no documented LangChain-specific usage, so there is nothing to confirm here.
What is the meaning of guardrails in software?
In this project the term refers to Input and Output Guards that intercept LLM inputs and outputs and check them against validators. The README describes them as measures of specific types of risk that can be combined into a Guard.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/guardrails-ai-guardrails)