Bedrock Guardrails: The 6 Safety Policies, Configured Step by Step

By Carlos Montiel | Enterprise AI Specialist
Leer en español →
Published: 2026-07-28 | By: Carlos Montiel | Reading time: ~4 minutes

You don't need to build your own guardrails layer from scratch if you're already on AWS Bedrock — it ships with six configurable safety policies, ready to apply on top of any model in the catalog.

The 6 available safety policies

Amazon Bedrock Guardrails offers six configurable protection policies for generative AI applications: content moderation (content and word filters), prompt attack detection, topic classification (denied topics), redaction of personally identifiable information (sensitive information filters), and hallucination detection (contextual grounding checks and automated reasoning checks).

Content filters: six categories, adjustable sensitivity

Content filters detect and filter harmful text or image content in input prompts or model responses, based on predefined categories: hate, insults, sexual, violence, misconduct, and prompt attacks. You can adjust the sensitivity of each category independently, from low to high, depending on how strict you need to be along each specific dimension.

Denied topics: block entire conversation areas

Denied topics let you define specific subjects the model must refuse to engage with. Each denied topic appears in the configuration list with its name and description, and after creating the guardrail, you can test it by sending a prompt that matches a denied topic to verify the response returns your configured blocked message.

PII redaction: block or anonymize, category by category

Sensitive information filters detect and handle personally identifiable information — names, emails, phone numbers, credit card numbers — and you control the action for each PII type individually: block the entire request, or anonymize it by replacing the data with a placeholder. That granularity is useful: you can, for example, block credit card numbers but only anonymize names.

The 2025 update that widened real-world coverage

As of June 2025, Bedrock Guardrails introduced tiers for content filters and denied topics, with a new Standard tier that detects and filters unwanted content with better contextual understanding — including evasion attempts like deliberate typos — and support for up to 60 languages. That closed a real gap: earlier guardrails were easier to evade with intentional misspellings or by switching languages.

When it's worth using Bedrock Guardrails vs. a custom solution

If you're already building on Bedrock, turning on Guardrails has a much lower implementation cost than building your own validation layer — it's natively integrated into the same service you already use to call the model. The reason to consider a custom or third-party solution (like Guardrails AI or NeMo Guardrails) is when you need validation logic very specific to your domain that Bedrock's predefined categories don't cover, or when your architecture is multi-cloud and you need a consistent guardrails layer independent of the model provider.

Carlos Montiel
Enterprise AI Solutions Architect
Specialist in LLMs, Agents, and Orchestration
guatemalia.com/en/#contact · info@guatemalia.com

Need to implement AI at your company?

Carlos Montiel is an enterprise AI solutions architect. He implements LLMs, Agents, RAG, and orchestrators for companies across Guatemala and Latin America. Reach out for a consultation.

Contact Carlos Montiel

info@guatemalia.com