Llama Guard 4 12B
Meta · released Apr 23, 2025 · meta-llama/Llama-Guard-4-12B
- Type
- Open weightsCustom licence
- Params
- 12B
- Context
- 1M
about 786K words of context · download allowed, licence restricts use
Our take
Written Aug 2, 2026Llama Guard 4 is a 12-billion-parameter safety classifier from Meta that reads text and images to judge content safety. It can handle up to one million tokens in a single request, making it unusual among moderation tools for long-document work.
Choose this for screening very long documents or conversation threads in one pass, or for multimodal content moderation where image and text need joint assessment. It is also the pick when you want a hosted safety classifier at the lower end of its narrow price range. Skip it if you need verified accuracy data, a permissive licence, or guaranteed fast throughput — only half of tracked offers list speed figures, and none list benchmark scores.
The case for it
- One-million-token request limit enables single-pass analysis of very long documents or conversation threads.
- Accepts both text and images for joint safety assessment.
- The cheapest tracked offers cost noticeably less than the most expensive ones in this small market.
The case against it
- No benchmark scores in our data, so performance as a safety classifier is entirely unverified.
- Custom restricted licence: commercial terms and redistribution rights are constrained, unlike Apache or MIT alternatives.
- Throughput is modest or unverified on most offers: only two of four list speed data, at 8 and 15 tokens per second.
How good is it?
We hold no score for this model.
We look for every model we track on every board we watch, and none of them has turned up Llama Guard 4 12B — so there is no intelligence, coding, agentic or writing score to show you, not a low one, none.
Can you run it yourself?
- Fits in memory
- weights load entirely on the card
- Spills to system RAM
- some weights offload; much slower
- Too large
- will not load even with offload
- est
- size is calculated; the verdict could change by 10%
Comfortable fit
GeForce RTX 4090 · 24 GB
Room to spare. 13.7 GB spare means a 10% error in the size would not change the answer.
GeForce RTX 5090 · 32 GB
Room to spare. 21.7 GB spare means a 10% error in the size would not change the answer.
Apple M1 (8-core GPU) · 16 GB
Room to spare. 2.9 GB spare means a 10% error in the size would not change the answer.
Memory use by level
Against a 24 GB card.
All 3 sizes here are calculated, not measured. We hold no measured file for this model, so each size comes from the parameter count and every verdict above inherits that uncertainty.
Check against your own machine → · All 71 devices, with every size →
Or rent it from someone else
Cheapest of 4 live listings. Picked at the widest standard context we hold, within one quantisation slice, so the numbers beside it are a price one host actually charges.
- per 1M tokens
- $0.18 in / $0.18 out
- Context served
- 1M
- Throughput
- Not measured
| Provider | In / out per 1M tokens | Context | Throughput | Trains on prompts | Logs prompts | Zero retention |
|---|---|---|---|---|---|---|
| OpenRouter | $0.18 / $0.18 | 1M | not measured | Unknown | Unknown | Unknown |
| DeepInfrabfloat16 | $0.18 / $0.18 | 164K | not measured | Unknown | Unknown | Unknown |
| DeepInfrabf16 | $0.18 / $0.18 | 164K | 7 tok/s | No | No | Confirmed |
| Together AI | $0.20 / $0.20 | 1M | 14 tok/s | No | No | Confirmed |
Across the 4 listings we hold: 2 say they do not train on prompts, 0 say they do and 2 do not say. 2 appear in the zero-retention registry we check; the rest are unknown to us rather than confirmed either way.
What each host's API supports
From the parameter list each endpoint publishes. Streaming is omitted: nothing we hold reports it, for any model.
- ✓
- Supported
- ✗
- Not supported
- Not published
- host gave no parameter list
| Provider | Tool calling | JSON output | Strict schema |
|---|---|---|---|
| OpenRouter | ✗ | ✓ | ✗ |
| DeepInfrabfloat16 | |||
| DeepInfrabf16 | ✗ | ✓ | ✗ |
| Together AI | ✗ | ✗ | ✗ |
Tool calling: 0 of 4 listings say yes, 3 say no, 1 publishes no parameter list. JSON output: 2 of 4 listings say yes, 1 says no, 1 publishes no parameter list. Strict schema: 0 of 4 listings say yes, 3 say no, 1 publishes no parameter list.
When we formed this view
Dates behind this page
Prices last checked 14h ago
What we do not know about this model yet
- We hold no measured file for it, so all 3 sizes on this page are calculated from the parameter count.
- No board we watch has turned up a score, so we hold no quality figures at all.
- 1 of 4 listings publish no parameter list, so what their API accepts is unknown to us.
- Nothing we hold says whether an endpoint streams, so we do not show it either way.
- 2 of 4 listings do not say whether they train on prompts.
- We hold no cached-input rate for any of its listings.
Licence and identifiers
What the licence allowsCustom licence, what it allows commercially, and the identifiers you need to pull this model — its Hugging Face repo, our slug and a machine-readable card.
Licence
Custom licence
This model ships custom license terms that don't map to a known template. We haven't parsed them, so commercial use, redistribution and derivatives are unverified — review the original terms before shipping.
Identifiers
- Hugging Face
- meta-llama/Llama-Guard-4-12B
- Modality record
- text+image->text
- Catalogue slug
- meta-llama-llama-guard-4-12b