NeMo Guardrails
NVIDIA NeMo Guardrails: what it is, how it works and what it is not
What the open-source NeMo Guardrails toolkit does, its five rail types, how you integrate it, its stated limits and where it sits next to a gateway and a policy engine.
NeMo Guardrails is an open-source Python package from NVIDIA for adding programmable guardrails to LLM applications. It runs checks at five stages: input, retrieval, dialog, execution and output. It is licensed under Apache 2.0. It is a content and flow control library, not an access-control, approval or audit system, and NVIDIA says its guardrails are not perfect.
Last verified 2026-10-07. Sources are listed at the end of the page.
What is NVIDIA NeMo Guardrails?
NVIDIA describes NeMo Guardrails as an open-source Python package for adding programmable guardrails to LLM-based applications. Its aim is to block, alter or validate unsafe, off-topic, malicious or policy-violating user inputs and model responses without changing your core application or model code. The library sits between your application and the model, tools or retrieval systems and evaluates messages against the rails you configure.
The source is on GitHub at NVIDIA-NeMo/Guardrails. On 2026-10-07 the repository README showed Apache License 2.0 and a latest released version of 0.24.1. Check the repository for the current release before you pin a version, because this page is a dated snapshot.
What are the five rail types?
| Rail type | When it runs | What the docs say it does |
|---|---|---|
| Input rails | Before the model is called | Validate and sanitise user input. The docs give content safety, jailbreak detection, topic control and PII masking as common uses. |
| Retrieval rails | In a retrieval-augmented pipeline | Filter and validate retrieved documents and chunks so only trusted context reaches the model. |
| Dialog rails | During multi-turn conversation | Steer and constrain the conversation, enforcing flow logic and policies across turns. These are written in Colang. |
| Execution rails | Around tool and function calls | Control and validate tool calls, their arguments and their results so the system interacts safely with external systems. |
| Output rails | After the model responds | Evaluate and post-process responses, filtering, editing or blocking unsafe or off-policy content before it reaches the user. |
Rail names and descriptions are from the NVIDIA documentation page on rail types, read on 2026-10-07. The docs state that input and output rails are the most common.
What is Colang?
Colang is NVIDIA's modelling language for dialogue flows and guardrail logic. A configuration combines YAML files with Colang files. The YAML is where you set up the model and the rails to apply, and Colang defines the flows, for example how the assistant should respond when a user asks about a topic you have placed out of scope.
The README says Colang 1.0 and 2.0 are both supported and that 1.0 is the default. Colang 2.0 has its own section in the documentation. If you start a new project, read that section first and decide on one version early. This page did not verify whether flows move between versions without changes.
How do you integrate NeMo Guardrails?
1. Install the package
Run pip install nemoguardrails. The README lists Python 3.10, 3.11, 3.12 and 3.13 as the supported versions.
2. Write a configuration
Create the YAML and Colang files: which model to call, which input, retrieval, execution and output rails to switch on, and any custom actions. The docs also list a catalogue of guardrails, including PII detection and third-party API checks.
3. Choose how to call it
The docs describe the Python SDK, a guardrails server (a FastAPI service with an OpenAI-compatible chat completions endpoint) and integrations with LangChain and LangGraph.
4. Test with your own cases
NVIDIA recommends thorough evaluation and regression-testing suites. Include cases the rails should block and cases they should allow, because the docs warn that safety rails can occasionally block safe requests.
5. Run it with the caller's authority
NVIDIA's guidelines say calls to a resource should execute in the authorisation context of the user, and that the model should have no access to keys or tokens. Build that into the service, not into the rails.
What limits does NVIDIA state?
The README says the built-in guardrails may or may not be suitable for a given production use case, and that developers should work with their application team to check they meet the requirements of the industry and use case. The security guidelines go further. They say to consider the model to be, in effect, a web browser under the complete control of the user, and all content it generates untrusted.
The same guidelines say the guardrails are not perfect, that some safety rails can occasionally block otherwise safe requests, and that this is more likely when several are used together. They also note that model behaviour is non-deterministic, which makes some problems hard to reproduce.
The how-it-works page lists the steps the runtime can take, including generating a canonical user intent, running a custom action, retrieving chunks and calling the application model. It does not quantify added latency or cost. Not verified: any number for either. Measure both in your own configuration before you commit to a rail set.
What is NeMo Guardrails not?
The documents describe rails that block, alter or validate messages and flows. They do not describe the functions below as part of the library, so plan for them elsewhere.
| Need | Does NeMo Guardrails provide it? | Where it usually lives |
|---|---|---|
| Authenticate the caller and decide who may do what | Not described. NVIDIA's guidelines place authorisation in the application and the services it calls. | Your identity provider, API gateway and the services themselves. |
| Human approval of a consequential action | Not described as a feature of the library. | An approval step in your workflow or agent platform. See human in the loop. |
| Audit evidence for a regulator or an auditor | Not described. The docs read for this page do not present the library as an audit record. | A gateway or ledger that records who acted, under which policy, with what outcome. See the AI audit trail. |
| Key custody, routing, budgets and fallback between providers | Not described. | An LLM gateway. See how to set up an LLM gateway. |
| Content and flow checks on messages | Yes. This is its purpose. | The library, with your tests. |
Where does it fit next to a gateway and a policy engine?
Think of three layers. The guardrail library asks whether a message or a flow is acceptable. The gateway holds provider keys, routes calls, sets budgets and logs usage. The policy engine and approval layer decide whether this identity may take this action now, and keep the evidence. NeMo Guardrails belongs in the first layer.
The layers can be ordered either way. You can put the library in the application, ahead of the gateway call, or run the guardrails server and let it call the gateway. Pick the order by where you need the check to see the raw text, and where you need the log to be written. Whatever you choose, treat the guardrail as one layer, as the LLM guardrails page explains.
Where Swfte fits
Swfte does not bundle or integrate NeMo Guardrails. On 2026-10-07 a search of the agents-service, Cortex, Nexus and website repositories found no reference to it, so Swfte makes no integration claim and has not tested the setup below.
As a deployment pattern only, you could run the NeMo Guardrails server in your own environment and point its model configuration at an OpenAI-compatible endpoint such as a Connect gateway, bringing your own provider keys. Connect already offers its own content-policy evaluator for secrets and personal data with a redact action (Built). Whether your NeMo version can use a custom base URL is something to confirm in NVIDIA's configuration guide. This page did not verify it.
You do not need Swfte to use NeMo Guardrails. If you have one application and one provider, the library alone, plus your own access control, may be all you need. Governance of agents is a separate question, covered on the AI governance page.
Sources and last verified
Every dated or technical fact on this page was read from the pages below on 2026-10-07. Anything that could not be confirmed is left out or marked as not verified.
- NeMo Guardrails documentation: overview. What the package is and the five rail types.
- NeMo Guardrails documentation: rail types. What each rail type does and when it runs.
- NeMo Guardrails documentation: how it works. Runtime steps, Python SDK and guardrails server, and the absence of latency figures.
- NeMo Guardrails documentation: security guidelines. Threat model, authorisation context and the statements on imperfection.
- NVIDIA-NeMo/Guardrails on GitHub. Licence, latest released version, Python versions and install command.
- NeMo Guardrails README (develop branch). Colang versions and the production suitability disclaimer.
- OWASP LLM01 Prompt Injection. The statement that fool-proof prevention may not exist.
Frequently asked questions
Is NeMo Guardrails free to use?
Yes, the library is open source under the Apache License 2.0, as the repository README states. You still pay for the models it calls, including any extra model calls made by the rails, and for the infrastructure you run it on. The documentation read for this page does not give a cost figure.
What are the rail types in NeMo Guardrails?
There are five: input rails, retrieval rails, dialog rails, execution rails and output rails. Input and output rails are the most common according to the documentation. Retrieval rails filter chunks in a retrieval pipeline, dialog rails shape multi-turn flow in Colang, and execution rails check tool calls.
What is Colang?
Colang is NVIDIA's language for defining conversation flows and guardrail logic. It sits beside YAML files in a NeMo Guardrails configuration. The README says versions 1.0 and 2.0 are supported, with 1.0 as the default, so check which version your flows target.
Does NeMo Guardrails stop prompt injection?
It can reduce it but does not stop it. Input rails list jailbreak detection as a common use, but NVIDIA states the guardrails are not perfect, and OWASP says it is unclear whether fool-proof prevention of prompt injection exists. Combine it with least-privilege tools and approval on risky actions.
Which Python versions does it support?
The repository README, read on 2026-10-07, lists Python 3.10, 3.11, 3.12 and 3.13. Requirements change between releases, so check the installation guide and the README of the version you intend to deploy rather than relying on this page.
Can I use NeMo Guardrails with Swfte?
Swfte does not claim an integration and has not tested one. As a deployment pattern, you can run the guardrails server yourself and point it at an OpenAI-compatible gateway. Confirm that your version supports a custom endpoint, and test the combination before you rely on it.