NeMo Guardrailsnemoguardrails 0.24.1 · Python 3.10+
Dashboard
0%
1
Curious builder0 XP earned · 300 to level 2
0 daysFinish a lesson to begin
Badge collection0 of 6 unlocked
37 small wins to finish your pathNext lesson →

Server, CLI and rail library

The NeMo Guardrails CLI is the nemoguardrails command installed with the package: it chats with a config folder, serves configs over HTTP, and the package also ships a library of ready-made rails.

Last updated: 30 Sep, 2026 · NeMo Guardrails 0.24.1

This course used NeMo from Python, one config at a time. The same package runs as a server, and NeMo is one of several guardrail frameworks, which the video compares before choosing it.

Guardrail frameworks · from The Complete AI Security Course In 8 Hours · 16:34 to 19:28

The clip names four ways to add guardrails: NeMo Guardrails from NVIDIA, Guardrails AI, Llama Firewall from Meta, and AWS Bedrock Guardrails, a cloud-native service. Choose by use case, and by open source or paid.

Syntax:

bash
nemoguardrails chat --config=.        # talk to a config folder in the terminal
nemoguardrails server --config=configs  # serve every folder in configs/ over HTTP

The commands

Example
import subprocess
import sys

out = subprocess.run([sys.executable, "-m", "nemoguardrails", "--help"],
                     capture_output=True, text=True).stdout
for name in ["chat", "server", "actions-server", "eval", "convert"]:
    print(name, name in out)
  • chat opens an interactive conversation with a folder, handy for trying rails by hand.
  • server starts an HTTP server with an OpenAI-style chat endpoint, so other applications call your rails.
  • actions-server runs actions in a separate process; eval evaluates a config; convert moves Colang 1.0 files to 2.x.

The rail library

Example
import os

import nemoguardrails.library as library

folders = sorted(name for name in os.listdir(os.path.dirname(library.__file__))
                 if not name.startswith("_") and "." not in name)
print(len(folders))
print(", ".join(folders))

self_check is where self check input came from. jailbreak_detection, injection_detection, content_safety, llama_guard and sensitive_data_detection cover what this course wrote by hand, with models trained for the job. Each is switched on as self check input was: a flow name in config.yml, plus whatever model or key it needs.

Guardrail frameworks compared

FrameworkByRules written asRuns
NeMo GuardrailsNVIDIAColang flows and Python actionsSelf-hosted, open source
Guardrails AIGuardrails AIPython validatorsSelf-hosted or their cloud
Llama Firewall / Llama GuardMetaA model trained to classifySelf-hosted, open weights
AWS Bedrock GuardrailsAmazonConsole or API settingsAWS, paid per call

Where each fits

  • NeMo when the rules should be readable files, with your own flows and actions.
  • A trained classifier, such as Llama Guard from the rail library, when paraphrased attacks matter more than cost.
Watch out. NeMo also has Colang 2.x, a rewrite with different syntax. colang_version defaults to 1.0, which this course uses; 2.x examples in the documentation do not run in a 1.0 config.
Try it yourself
  • Run nemoguardrails chat --config=. in the folder from config.py on disk.
  • Open library/jailbreak_detection and find the flow names it defines.

Slow is fine. Stopping is the only problem.