NotCheapMAKE EVERY CREDIT COUNT

AWS Bedrock Guardrails vs Azure AI Content Safety vs OpenAI Moderation: Real AI Safety Cost per 1 Million Requests in 2026

The short answer: OpenAI's Moderation endpoint is free and screens both text and images against OpenAI's fixed taxonomy, with no per-call charge and no usage-limit impact — but it only checks OpenAI's own categories, not a custom policy. AWS Bedrock Guardrails and Azure AI Content Safety both charge per unit of text screened, both round a partial unit up to a full one (AWS's own documentation confirms this explicitly), and both bill twice per request in a typical setup, once for the user's input and once for the model's output. At an ILLUSTRATIVE 500 characters per screening pass, that rounding means each pass consumes one full billed unit, not half of one: 1 million requests costs about $1,500 on AWS Bedrock Guardrails at a REPORTED $0.75-per-1,000-unit blanket rate (which conflicts with an official EU pricing page's more granular content-filter figure of roughly $559, and with a separately reported, more recently dated $0.15-per-1,000-unit rate that would put the same volume at about $300) and about $2,000 on Azure AI Content Safety. Guardrail cost is not a rounding error at scale: one industry analysis noted that for high-volume applications, guardrail costs can exceed the underlying model's own inference cost.

What each vendor bills

AWS Bedrock Guardrails (OFFICIAL for the billing-unit mechanism; unresolved source conflict on the dollar rate). Billed per policy type, per text unit, and AWS's own pricing page states the rounding rule explicitly: a text unit holds up to 1,000 characters, and any input is rounded up to the next whole text unit — a 5,600-character input is charged as 6 text units, and by the same rule a 500-character input is charged as a full 1 text unit, not a fractional 0.5. This confirmed rounding rule matters directly for this article's per-request math below. On the dollar rate itself, three conflicting figures were found: AWS's own EU pricing page lists content filters and denied topics at €0.2587283 per 1,000 text units (roughly $0.28), sensitive-information filters and contextual grounding checks at €0.1724855 per 1,000 (roughly $0.19), word filters and regex-based sensitive-information filters free; a March 2026 third-party guide states a blanket $0.75 per 1,000 text units for text and $1.00 per image; and a separate, more recently dated source describes a $0.15 per 1,000 text units rate, characterized as an 80% reduction from an original $0.75 rate introduced in late 2024. This article could not reconcile these three figures from the sources reviewed; treat AWS's own current console pricing page as authoritative before budgeting, and confirm which policies (content filters, denied topics, PII, grounding) you actually have enabled, since each is billed separately and only for the policies in use. Guardrails apply to Bedrock-hosted models and, via the separate ApplyGuardrail API, to third-party models including OpenAI and Google Gemini.

Azure AI Content Safety (REPORTED, Microsoft/Azure documentation and third-party pricing guides). Standard tier: $1 per 1,000 text records (a record is up to 1,000 Unicode characters; a longer input counts as multiple records), $1.50 per 1,000 images. All text-based features — harm categories, Prompt Shields (jailbreak detection), protected-material detection, and groundedness detection — share the same per-record rate, so enabling multiple text safety features on the same content does not multiply the charge the way AWS's per-policy billing can. A free tier offers roughly 5,000 text records a month before metered billing begins; usage simply stops rather than overaging once that free allotment is exhausted.

OpenAI Moderation (OFFICIAL, OpenAI pricing documentation). Free, for both text and image inputs, with no charge and no impact on other API usage limits. The tradeoff: it screens only against OpenAI's own fixed, non-customizable taxonomy (categories like hate, violence, self-harm, sexual content), not a business's own custom policy categories, and produces no per-decision audit log formatted for a compliance workflow the way the two paid platforms are built to support. For teams needing custom categories, multimodal video/audio screening, or a defensible decision log, OpenAI's free tier is not a substitute for a metered policy engine.

Both input and output get screened

Formula: screening events per request = 2 (user input, then model output), a standard production pattern noted explicitly in AWS's own guardrails guidance. This doubles the effective per-request cost on any per-unit-billed platform compared to screening only one side of the exchange.

Cost per volume

Formula: AWS = requests × 2 × units per pass × rate per 1,000 units, where units per pass = ceiling(chars ÷ 1,000); Azure = requests × 2 × records per request × rate per 1,000 records, at an ILLUSTRATIVE 500 characters per screening pass. Because AWS rounds any partial text unit up to a full one, a 500-character pass consumes one full unit, not half of one — so units per request = 2 (one for input, one for output), the same whole-number pattern Azure already uses for its own per-record billing.

Requests/monthAWS (REPORTED $0.75/1k blanket rate)AWS (OFFICIAL EU content-filter rate, ~$0.28/1k)AWS (REPORTED newer $0.15/1k rate)Azure AI Content SafetyOpenAI Moderation
100,000$150.00$55.89$30.00$200.00$0
1,000,000$1,500.00$558.86$300.00$2,000.00$0
10,000,000$15,000.00$5,588.57$3,000.00$20,000.00$0

Once the rounding is corrected, Azure's price relative to AWS ranges from only about 1.3x AWS's blanket $0.75 rate, to roughly 3.6x AWS's official EU content-filter rate, to about 6.7x AWS's reported newer $0.15 rate — a wide range driven entirely by which of the three conflicting AWS figures is actually current, not by a single clean multiplier. The two platforms are not applying identical policy sets either, so none of these ratios is a precise apples-to-apples comparison; they reflect different unit-pricing structures and an unresolved AWS rate conflict more than a definitive "AWS is cheaper" conclusion.

When guardrail cost exceeds the model's own cost

At high request volume with a cheap underlying model, the guardrail line can dominate the bill. Formula: guardrail share = guardrail cost ÷ (guardrail cost + model cost). Pairing Azure's Content Safety at $2,000 per million requests against an ILLUSTRATIVE cheap model call (500 input + 200 output tokens at $0.10/$0.40 per million tokens, about $0.00013 per request, or about $130 per 1 million requests) puts guardrail cost at roughly 94% of the combined bill — the safety layer costs more than fifteen times what the underlying generation itself costs. This is the scenario one industry writeup was referencing when it warned that guardrail costs can exceed model costs at volume; it is most likely on cheap, high-volume, latency-tolerant model tiers, and least likely on expensive frontier models where the guardrail cost is a rounding error by comparison.

Sensitivity

  1. Which AWS rate is real. A 5x spread across three conflicting sources (a REPORTED $0.15/1,000-unit rate, an OFFICIAL-looking EU per-policy rate of roughly $0.28/1,000, and a REPORTED blanket $0.75/1,000 rate) is the single largest unresolved number in this article; confirm directly against your account's live console pricing before committing to a volume-based budget.
  2. Number of policies enabled on AWS. Content filters, denied topics, PII filters, and grounding checks are billed separately (except the free ones); enabling all of them multiplies the AWS side of this comparison in a way Azure's flat per-record rate does not replicate.
  3. Screening both input and output versus input only. Halves the cost on either paid platform if only one side is actually screened, though this reduces the safety coverage correspondingly.
  4. Whether OpenAI's fixed taxonomy is sufficient. The free option is only free because it does not offer customization; a business with its own policy categories cannot substitute the free tier for a policy engine without also building custom classification logic itself.

Budgeting traps

  • Multiplying per-request cost by request count without accounting for the input-plus-output screening pattern. This alone can understate AWS's or Azure's real bill by half.
  • Enabling every AWS Guardrails policy type without checking the marginal cost of each. Word filters and regex PII filters are free; content filters, denied topics, and grounding checks are not.
  • Assuming OpenAI's free Moderation endpoint covers a custom trust-and-safety policy. It only checks OpenAI's own fixed categories.
  • Treating guardrail cost as a rounding error next to model inference cost. On cheap, high-volume model tiers specifically, it can be the larger of the two.

What to ask before you buy

Confirm AWS's current per-policy Guardrails rate directly in your account's console, given the unresolved conflict between sources in this article. Model your guardrail cost against your specific underlying model's inference cost at your actual volume before assuming either line item is negligible, since which one dominates depends heavily on model tier.