Safety & Security · Software component
Input Rail
Software componentSafety & SecuritySafety, Security & Governancearc:InputRail
A guardrail that screens each user message before LLM processing for jailbreak attempts, off-topic requests and sensitive data, rejecting or answering with predefined responses without invoking inference.
Responsibility. Blocks unsafe or out-of-scope user input before it reaches the LLM.
Also known as: Input rails, Pre-processing validation rail, Input guardrail, Input validation rail, Input validation filter, Layer 1 data governance and input controls, Input guardrails, Fairness input rail
Relationships
is configured by structural
invokes dependency
- Output Bias Detector abstract Ch9.4
- Canonical Form Matcher Ch7.1B Ch9.5
- Deny-List Content Filter Ch9.1
- Heuristic Jailbreak Detector Ref9.04
- Jailbreak Detector abstract Ch7.1A Ch7.1B +3
- PII Detector abstract Ch7.1A Ch7.1B +1
- Pattern PII Detector Ch9.1 Ref9.04
- Third-Party Moderation Service Ch9.5 Ref9.01
- Toxicity Classifier Ch9.1 Ref9.04
emits telemetry to dynamic
sends data to dynamic
guards control
is orchestrated by control
Design guidance
- SHOULD validate input before inference so that rejected requests consume no LLM compute.
- SHOULD flag detected PII for redaction or rejection before it enters logs, training data or third-party API calls.
- SHOULD validate input before the agent and validate output after it, sharing one guardrail layer across agents in multi-agent deployments.
- SHOULD exercise guardrails early in development rather than adding them only at production.
- SHOULD combine lightweight regex patterns, ML classifiers and deny lists so obvious attacks are blocked before consuming inference compute.
- SHOULD log which specific PII type or rule triggered a block to support compliance auditing.
- SHOULD reject or neutrally reframe biased queries without verbose error messages that invite adversarial probing.
Quantitative guidance
As stated by the sources; verify before use.
- Maximum input length 5000 characters in example configuration (Ref9.04).
- Example input validation limits input length to 5,000 characters (Ref9.01).
Classification
- Patterns
- Defense-in-depth guardrailsTopical boundary enforcementPredefined response substitutionRegex-based injection blockingIntent detectionInput format and size validationInput/output guardrail sandwich around a ReAct RAG agentShared guardrail layer across agents
- Technologies
- NVIDIA NeMo GuardrailsNeMo Guardrails
- Quality attributes
- Security (ISO/IEC 25010 | NIST AI RMF: secure and resilient)Cost efficiencySafety (ISO/IEC 25010 | NIST AI RMF: safe)
- Risks mitigated
- JailbreakOut-of-domain queries wasting computePII leakage into logs, training data or third-party APIsRegulatory non-compliancePrompts eliciting biased responses or discriminatory decisionsModel generating principle-violating content for clearly prohibited requestsTraining data extraction attacks
Sources
- Ch7.1A: T. Nguyen, "Advanced Implementation with Nvidia NEMO Framework and Nvlink," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 7.1A. ISBN: 9798244538229.
- Ch7.1B: T. Nguyen, "Nvidia NIM and Colang," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 7.1B. ISBN: 9798244538229.
- Ch8.2B: T. Nguyen, "NeMo Guardrails Integration," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 8.2B. ISBN: 9798244538229.
- Ch9.1: T. Nguyen, "Output Filtering and Content Moderation," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.1. ISBN: 9798244538229.
- Ch9.4: T. Nguyen, "Fairness and Bias Mitigation," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.4. ISBN: 9798244538229.
- Ch9.5: T. Nguyen, "Constitutional AI," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.5. ISBN: 9798244538229.
- Ch9.7: T. Nguyen, "GDPR and Data Protection Regulations," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.7. ISBN: 9798244538229.
- Ref7.03: NVIDIA, "Overview," NVIDIA NeMo Guardrails Library Developer Guide. Accessed: Sep. 27, 2026. [Online]. Available: https://docs.nvidia.com/nemo/guardrails/about-nemo-guardrails-library/overview
- Ref7.14: "NVIDIA Agentic AI Platform Ecosystem Integration," unpublished reference note (14-NVIDIA-Ecosystem-Integration.md), Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam supplementary materials, 2026. unpublished note
- Ref7.18: "Chapter 7 Summary: NVIDIA Platform Implementation," unpublished reference note (18-Chapter-7-Summary.md), Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam supplementary materials, 2026. unpublished note
- Ref9.01: "AI Safety Frameworks for Agent Systems," unpublished reference note (01-AI-Safety-Frameworks.md), Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam supplementary materials, 2026. unpublished note
- Ref9.04: "Safety Guardrails Implementation for Agent Systems," unpublished reference note (04-Safety-Guardrails-Implementation.md), Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam supplementary materials, 2026. unpublished note