Llama Guard 4 12B
Meta · released Apr 23, 2025 · meta-llama/Llama-Guard-4-12B
- Type
- Open weightsCustom licence
- Params
- 12B
- Context
- 1M
about 786K words of context · download allowed, licence restricts use
Our take
Written Sep 1, 2026Llama Guard 4 12B is a safety-classifier model from Meta that reads text and images to judge whether content is safe. Its one-million-token request limit is unusually large for this model class, though it carries a restricted licence and no measured quality scores yet.
Use this for long-context safety filtering on documents or extended conversations, or for multimodal checks on image-plus-text inputs. Skip it if you need a permissive licence for redistribution, if you require benchmarked accuracy data, or if throughput consistency matters and you cannot test hosts yourself.
The case for it
- One-million-token request limit — among the longest we hold for a safety classifier.
- Handles both text and image inputs for multimodal safety checks.
The case against it
- Custom restricted licence with narrower terms than Apache 2.0; check redistribution and modification rights before deploying.
- No benchmark scores recorded, so accuracy is unverified in our data.
- Throughput is modest or unverified on half the tracked offers.
How good is it?
We hold no score for this model.
So there is no figure here for everyday use, coding, agent work or writing. That is a gap in our data, not a low score.
Can you run it yourself?
Comfortable fit
GeForce RTX 4090 · 24 GB
Room to spare. 13.7 GB spare means a 10% error in the size would not change the answer.
GeForce RTX 5090 · 32 GB
Room to spare. 21.7 GB spare means a 10% error in the size would not change the answer.
Apple M1 (8-core GPU) · 16 GB
Room to spare. 2.9 GB spare means a 10% error in the size would not change the answer.
Memory use by level
Against a 24 GB card.
What is quantisation? →This model on every device we track71 devicesThe Q4 build most people download, on each device: what the weights come to, how much context the memory leaves, and whether it runs. Smallest device that runs it first.
Check against your own machine → · Where to rent it hosted →
Or rent it from someone else
Prices checked 2 hours ago — each listing carries its own date.
- per 1M tokens
- $0.18 in / $0.18 out
- Context served
- 164K
- Throughput
- Not measured
| Provider | In / out per 1M tokens | Context | Throughput | Trains on prompts | Logs prompts | Zero retention |
|---|---|---|---|---|---|---|
| OpenRouterOpenRouter's own listing | $0.18 / $0.18checked 2 hours ago | 164K | not measured | Unknown | Unknown | Unknown |
| DeepInfrabf16Direct and through OpenRouter | $0.18 / $0.18checked 2 hours ago | 164K16K max reply through OpenRouter | 10 tok/sthrough OpenRouter | DirectUnknownThrough OpenRouterNo | DirectUnknownThrough OpenRouterNo | DirectUnknownThrough OpenRouterConfirmed |
Across the 2 listings we hold: 1 says it does not train on prompts (only through OpenRouter), 0 say they do and 1 does not say. 1 appears in the zero-retention registry we check (only through OpenRouter); the rest are unknown to us.
What each host's API supports
From the parameter list each endpoint publishes. Streaming is omitted: nothing we hold reports it, for any model.
| Provider | Tool calling | JSON output | Strict schema |
|---|---|---|---|
| OpenRouterOpenRouter's own listing | ✗ | ✗ | ✗ |
| DeepInfrabf16Direct and through OpenRouter | ✗ | ✗ | ✗ |
Tool calling: 0 of 2 listings say yes, 2 say no. JSON output: 0 of 2 listings say yes, 2 say no. Strict schema: 0 of 2 listings say yes, 2 say no.
When we formed this view
Recent changes
What moved
first indexed by our pipelineEach date is the day we first saw the change, or the day the maker announced it.
What we do not know about this model yet
- We hold no measured file for it, so all 3 sizes on this page are calculated from the parameter count.
- No independent board has scored it, so we hold no quality figures at all.
- Nothing we hold says whether an endpoint streams, so we do not show it either way.
- 1 of 2 listings does not say whether it trains on prompts, and 1 answers only through OpenRouter, not for its own listing.
- We hold no cached-input rate for any of its listings.
- We hold no batch or off-peak rate for any of its listings.
- We hold a decode speed for it, but no prompt-processing (prefill) figure, so how long the input side of a job takes is unknown to us.
Licence and identifiers
What the licence allowsCustom licence, what it allows commercially, and the identifiers you need to pull this model — its Hugging Face repo, our slug and a machine-readable card.
Licence
Custom licence
This model ships custom license terms that don't map to a known template. We haven't parsed them, so commercial use, redistribution and derivatives are unverified — review the original terms before shipping.
Identifiers
- Hugging Face
- meta-llama/Llama-Guard-4-12B
- Takes in, gives back
- Text and images in, text out
- Catalogue slug
- meta-llama-llama-guard-4-12b