Prompt Guard
Tiny classifiers that catch attempts to hack a bot: prompt injections and rule bypassing. The 86M version is multilingual, 22M is English only.
- Developer
- Meta, USA
- First release
- Jul 2024
- Latest release
- Apr 2025
- Sizes
- 22M – 86M
- License
- Commercial use with conditionsLlama 3.1 and 4 licenses: commercial use allowed with restrictions
- Russian
- Not supported
- Running
- On your own serverAlso runs without a GPU
- Industries
- Security, Software development
What it does
- Protecting a bot from prompt injections
- Checking emails and documents that reach an AI agent
- Fast filter in front of a large model
Where it is used
Hardware requirements
Versions
- Llama Prompt Guard 2 22M и 86M
- Prompt Guard 86M
How to run it
I can set this up end to end: pick the model size, deploy it on your server and connect it to your systems.
Frequently asked questions
Can Prompt Guard be used in a commercial project?
With conditions. License: Llama 3.1 and 4 licenses: commercial use allowed with restrictions. Restrictions vary — region, company revenue, attribution requirements. Have a lawyer check the terms before a commercial launch.
What hardware does Prompt Guard need?
At minimum: Laptop or regular PC, up to 8 GB of VRAM — smaller versions. Some versions also run on an ordinary CPU, without a GPU. You can calculate the exact VRAM for your model size and context in the hardware calculator.
Does Prompt Guard support Russian?
No. The model card lists its languages and Russian is not among them.
Where can I download Prompt Guard and what does it cost?
The Prompt Guard weights are open and free to download. You only pay for the hardware it runs on and for the setup. Source links are at the bottom of this page.
How I deploy it for clients
- SelectionI pick the model size for your task and hardware and test it on your examples.
- DeploymentI deploy it on your server or in a closed network and provide an API.
- Fine-tuningI fine-tune it on your data (LoRA) or connect a knowledge base — whichever is cheaper for the task.
- IntegrationI connect it to your CRM, ERP, bot, website or team chat and set up monitoring.
Similar models
Filter models that check chatbot requests and replies for dangerous topics against a list of categories. Version 4 also checks images. Russian is not officially supported.
DetailsModeration and safetyGranite GuardianIBM · USACommercial use allowedIBM judge models: they catch harm, profanity and jailbreak attempts, and in RAG and agents check whether an answer is grounded in the documents. You can state your own rule in words.
DetailsModeration and safetyQwen3GuardAlibaba (Qwen) · ChinaCommercial use allowedSafety filters for 119 languages, Russian among them. The Stream version checks a bot's reply while it is being generated and can cut it off on the fly.
DetailsSource: huggingface.co/meta-llama/Llama-Prompt-Guard-2-22M. Data checked against the model card on 22 Sep 2026. Have a lawyer review the license before commercial launch.


