# Guardrails AI: validation and structured output for LLM applications

> Guardrails is an Apache-2.0 Python framework that wraps LLM calls with validators and Pydantic-based output schemas. It is useful when you need to reject or repair model output, but the recent move away from hosted inferencing changes how validators are installed.

**guardrails-ai/guardrails** — Adding guardrails to large language models.

- Repository: https://github.com/guardrails-ai/guardrails
- Website: https://www.guardrailsai.com/docs
- Stars: 7,472 · Forks: 711
- Language: Python
- License: Apache-2.0
- Published: 2026-09-09 · Updated: 2026-09-09 · Language: en
- Canonical page: https://hysenlabs.com/projects/guardrails-ai-guardrails

## The problem Guardrails solves for LLM application developers

An LLM returns text. Your application usually needs something narrower: a phone number in a known format, a JSON object matching a schema, or a response that does not name a competitor. Guardrails sits between the two. The README describes two functions: running Input/Output Guards that detect, quantify and mitigate specific risks, and generating structured data from LLMs.

The audience is Python developers building applications on top of foundation models. The package metadata lists openai, litellm and langchain-core among its dependencies, so it assumes an existing model-calling stack rather than replacing one. If you are writing Go or Java services, nothing here helps you directly.

What makes the project more than a validation library is the Guard object. A Guard is a container you attach validators to, and it can also own the prompt and the call to the model. That means validation and generation share one object, which is convenient inside a Python service and awkward if your generation happens somewhere else.

## How a Guard, validators and Pydantic models fit together

The README shows two distinct paths. The validation path starts with a Guard and one or more validators attached via `.use(...)`. Each validator carries an `on_fail` action, and the README example uses `OnFailAction.EXCEPTION`, which raises rather than returning a corrected value. Calling `guard.validate(...)` runs the chain and either passes or raises.

The structured generation path starts from a Pydantic `BaseModel`. The README states that `Guard.for_pydantic(output_class=Pet, prompt=prompt)` builds a Guard that calls the LLM so the output is formatted to that class. Under the hood the README names two mechanisms: function calling for models that support it, and prompt optimization for models that do not, where the expected schema is appended to the prompt.

That second mechanism is the interesting trade-off. Prompt-based schema injection depends on the model following instructions, and the README does not describe what happens when it does not beyond the general validation behaviour. Function calling is more constrained but only available on some models. The dependency on both openai and litellm suggests the project is trying to cover both cases behind one interface, which is also why the dependency list is long for what reads like a validation tool.

## Installing guardrails-ai and running a first validator

The README gives the install command directly. It requires Python 3.10 through 3.13 according to the pyproject constraint `>=3.10,<3.14`.

```bash
pip install guardrails-ai
```

The README then describes configuring the Hub CLI, which historically required a token. Note that the July 2026 news item says validators are moving to standard PyPI packages installed directly with pip, and that hosted remote inferencing is being discontinued with a planned cutoff of August 25, 2026.

```bash
pip install guardrails-ai
pip install guardrails-ai-regex-match
```

With the validator installed, the README builds a Guard around a phone-number regex and validates two strings. The first passes, the second raises because of `OnFailAction.EXCEPTION`.

```python
from guardrails import Guard, OnFailAction
from guardrails_ai.regex_match import RegexMatch

guard = Guard().use(
    RegexMatch, regex="\\(?\\d{3}\\)?-? *\\d{3}-? *-?\\d{4}", on_fail=OnFailAction.EXCEPTION
)

guard.validate("123-456-7890")
```

The README shows the failure message as `Validation failed for field with errors: Result must match ...`. Stacking validators works the same way: the README installs `guardrails-ai-competitor-check` and `guardrails-ai-toxic-language` and passes both into a single `.use(...)` call, with the failure output listing the matched competitor and the offending sentence.

## Where Guardrails is the wrong tool

The validators are the weak point. The README's installation section assumes a Hub CLI and a Hub-hosted catalogue, yet the same README announces that validators are moving to plain PyPI packages and that hosted remote inferencing is being discontinued. Anyone reading the getting-started steps without reading the news item will follow a workflow that is being replaced. The migration issue is linked from the README, but the install section itself was not rewritten to match, which is a documentation gap rather than a code problem.

There is also a scope limit. Guardrails validates text that passes through a Guard object in your Python process. It does not sit in front of an HTTP endpoint, does not inspect traffic from other services, and does not enforce anything at the network layer. If your models are called from several languages, or if you want policy enforced outside the application, a proxy-style tool fits better.

The dependency list is another cost to weigh. The project pulls in litellm, langchain-core, openai, tiktoken, jsonschema and OpenTelemetry packages. In a small service that only needs a regex check, that is a large surface to carry.

## Guardrails compared with NeMo Guardrails and Bedrock Guardrails

People searching for this project often compare it with NeMo Guardrails and Bedrock Guardrails, and the difference is where the logic lives. Guardrails is a Python library you import; its validators run in your process, and its structured output path is built on Pydantic models you define. The Pydantic coupling is the clearest signal of intent: the schema is a Python class, and the Guard is a Python object.

NeMo Guardrails takes a configuration-driven approach, where dialogue flows and policy are expressed declaratively rather than as Python validator objects attached to a Guard. Bedrock Guardrails is a managed service inside AWS, so the policy is configured on the platform and applied to model calls made through it. Choosing between them is mostly a question of where you want the rules to live: in application code, in a config file, or in a cloud account.

Guardrails is the better fit when the validation logic is genuinely application logic, such as checking that a generated value matches a domain-specific format. It is a worse fit when the rules are policy that a platform team wants to own centrally.

## Maintenance, licence and the validator migration

The repository is not archived, and the last push was on 2026-09-08, with v0.11.0 released on 2026-08-14. Releases are not frequent: v0.10.0 landed on 2026-04-03 and v0.10.2 on 2026-06-04. The version string in pyproject.toml matches the v0.11.0 tag.

The upgrade cost is concentrated in the validator packaging change. If you installed validators through the Hub CLI, the README points to a migration issue and states a planned cutoff of August 25, 2026 for hosted remote inferencing. That is the thing to plan around, because it changes both how validators are fetched and where they execute. The README does not document a rollback path for that migration.

The licence is Apache-2.0, declared in both the README badge and pyproject.toml. That is a permissive licence, and it is worth noting that the project also depends on packages under other licences; the dev extra includes liccheck, which suggests the maintainers check this themselves. This is not legal advice, and anyone redistributing the package should review the dependency licences independently.

## Conclusion

Adopt Guardrails if your application already runs Python and you need output validation tied to Pydantic models rather than a separate gateway service. Skip it if you need a language-agnostic proxy or cannot accept the validator packaging change that the July 2026 notice describes. Before committing, verify that every validator you depend on has a pip-installable replacement, since the hosted remote inferencing cutoff is listed as August 25, 2026.

## FAQ

### What is Guardrails AI?

It is a Python framework that runs Input/Output Guards to detect and mitigate specific risks in LLM interactions, and that generates structured data from LLMs. It is distributed as the guardrails-ai package under Apache-2.0.

### How to install Guardrails AI?

The README gives `pip install guardrails-ai` as the install command. The pyproject file requires Python >=3.10,<3.14. Individual validators are installed separately, for example `pip install guardrails-ai-regex-match`.

### How to use Guardrails with an LLM?

The README shows two patterns. You can attach validators to a Guard with `.use(...)` and call `guard.validate(...)`, or build a Guard from a Pydantic model with `Guard.for_pydantic(output_class=Pet, prompt=prompt)` so the model output is formatted to that class.

### How to use Guardrails in LangChain?

The README does not describe a LangChain integration. The pyproject file lists langchain-core as a dependency, but there is no documented LangChain-specific usage, so there is nothing to confirm here.

### What is the meaning of guardrails in software?

In this project the term refers to Input and Output Guards that intercept LLM inputs and outputs and check them against validators. The README describes them as measures of specific types of risk that can be combined into a Guard.

## Sources

- [guardrails-ai/guardrails on GitHub](https://github.com/guardrails-ai/guardrails)
- [License: Apache-2.0](https://github.com/guardrails-ai/guardrails/blob/main/LICENSE)
- [Project website](https://www.guardrailsai.com/docs)
- [README](https://github.com/guardrails-ai/guardrails/blob/main/README.md)
- [Releases](https://github.com/guardrails-ai/guardrails/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/guardrails-ai-guardrails
