Nemotron 3.5 Content Safety
Compact 4B multimodal guardrail model for LLM and VLM traffic.
NVIDIA Nemotron 3.5 Content Safety is a 4B-parameter multimodal guardrail model fine-tuned from Gemma 3 4B. It moderates both inputs to and responses from LLMs and VLMs.
- Provider
- NVIDIA
- Type
- Safety classifier
- Released
- Jun 4, 2026
- Context window
- 131K tokens
- Max output
- 118K tokens
- Price
- $0.20 input / $0.20 output per 1M tokens
- Input
- text, image
- Output
- text
- Open weights
- Yes
Best for
- Enterprise
- High volume / low cost
- Vision
Strengths
- 4B — cheap to run inline
- Text + image
- Open weights
More from NVIDIA
- Nemotron 3 Super — NVIDIA. Open hybrid Mamba-Transformer MoE for multi-agent applications.
- Nemotron 3.5 Lightning — NVIDIA. Tiny open 30B-A3B model with the lowest first-token latency in the index.
- Nemotron 3 Ultra — NVIDIA. NVIDIA’s largest open model: hybrid Mamba-Transformer MoE, 55B active.
- Nemotron 3 Embed 1B — NVIDIA. Small open embedding model for high-throughput enterprise retrieval.
- Cosmos 3 — NVIDIA. NVIDIA’s open omni-modal world foundation model for physical AI.
- Isaac GR00T N1.7 — NVIDIA. Open 3B cross-embodiment VLA for humanoids and manipulators.
Tools that use it
- NeMo Guardrails — NVIDIA. Open-source toolkit for programmable LLM guardrails.