See how ChatGPT, Perplexity and Google AI Overviews describe you today

Free AI Visibility Audit
NVIDIA model°

Nemotron 3.5 Content Safety

Nemotron 3.5 Content Safety is a compact multimodal guardrail model from NVIDIA, built to moderate the text and images going into an LLM or VLM and the responses coming back out. It is a 4B-parameter model fine-tuned from Google Gemma-3-4B.

NVIDIAVerified 04/10/2026Released 04/06/2026

01 / decision

Decision snapshot

Each figure sits next to the middle of the field, so it can be read as dear or cheap, wide or narrow, rather than floating on its own. Compared against the 232 models we track, not against an absolute standard.

Capability

Not measured

No published benchmark scores yet

Input / 1M tokens

$0.20

field median $0.41

Output / 1M tokens

$0.20

field median $2.00

Context

131K

field median 500K

02 / overview

What Nemotron 3.5 Content Safety is, and when to reach for it

Four questions, answered separately, because somebody arrives at one of them rather than at the top of the page.

What it is

The job it was built for, and the job it is not for.

This is a safety classifier, not an assistant. Its job is to sit either side of a generative model and judge whether a prompt or a response should be allowed through, across both text and image input. It will not write your product copy, answer customer questions or reason through a task, and it is not meant to be the model a user talks to.

When it arrived, and when to use it

Where it sits in its line, and when a sibling is the better pick.

Nemotron 3.5 Content Safety first appeared in June 2026, as the guardrail member of NVIDIA's Nemotron 3.5 line rather than one of its general-purpose siblings. Reach for it when you need moderation on a pipeline you already run, particularly one that takes image uploads as well as text. It is the wrong pick if you want a model to generate anything, or if your moderation needs are text-only and already covered by a provider's built-in filter.

How you reach it

The API, the apps it powers, and what its limits let you do.

It runs as an ordinary API model, called before and after your main generation step rather than in place of it. The context window is large enough to pass a full conversation plus the candidate response in one call, so you can classify an exchange in context rather than judging isolated turns, and the image modality means user-uploaded pictures go through the same check as the text around them. At 4B parameters it is small enough to self-host alongside the model it is guarding.

Why it matters

What changes because this exists, or why it does not.

Teams building on open or self-hosted models have generally had to bolt together text-only classifiers and separate image checks, or accept whatever moderation their API provider bundled in. A single small model that reads both, on both sides of the call, makes the guardrail layer something you own and can run cheaply on your own hardware rather than a dependency on someone else's policy.

Follows Nemotron 3 Nano Omni (free). Superseded by Nemotron 3 Ultra. See the whole line.

03 / evidence

How much of this is verified

Split by category, so a strong number never hides a thin evidence base. Verified means we read it on the benchmark's own published results; a provider's claim about its own model is shown and labelled rather than dropped.

No published benchmark scores for this model yet.

We publish a score only where we can link the result to where it was published. Until a benchmark result for this model exists in a source we read, this section stays empty rather than being filled with a provider's marketing figure.

How we decide what counts as evidence

04 / ledger

Benchmark ledger

Every published row, grouped by category, each compared with the best published score on the same benchmark. 'Is 64% good' is a question nobody can answer; '26 points behind the leader' is one anybody can.

Nothing in the ledger yet.

Each row here carries a score, the benchmark it came from, what the leading model scored on the same test, and a link to the published result. Rows appear as results are published and read.

How we decide what counts as evidence

05 / capability

Capability shape

Where this model is strong, and against how many peers. Ranks are against models with evidence in that category, not against everything we track: ranking against models nobody tested would rank who published, not who is better.

No category scores to shape yet.

A category score is the weighted mean of the benchmarks published for it. With no published rows there is nothing to average, and an empty chart drawn at zero would say something false.

How we decide what counts as evidence

06 / cost

What it costs

List API rates as last read from the provider, with the source on every row, plus every change we have recorded since we started tracking it.

Nemotron 3.5 Content Safety API pricingSurge45°
ChargePriceUnitRead onSource
Input$0.20per 1M tokens2026-09-24Check
Output$0.20per 1M tokens2026-09-24Check

Input and output are charged at the same flat, very low rate, which is what you would expect from a 4B model doing classification rather than generation. That makes it cheap enough to run on every request in a pipeline without thinking about it, which is the point, a guardrail you skip to save money is not a guardrail.

What a month costsSurge45°
WorkloadInput / monthOutput / monthCost
A small product team20M tokens5M tokens$5.00
A busy support assistant200M tokens40M tokens$48.00
A document pipeline1000M tokens100M tokens$220.00

List API rates, no caching and no batch discount, which both providers offer and which change the answer a great deal. Treat these as the ceiling, not the bill.

07 / specs

Specifications

As listed by the provider's own catalogue and re-read every few hours. Anything absent is absent there too.

SpecificationSurge45°
Context window131,072 tokens
Maximum output117,964 tokens
Modalitiestext, image
Released04/06/2026
StatusCurrent
Catalogue identifiernvidia/nemotron-3.5-content-safety

08 / lineage

Lineage

What this model replaced, what replaced it, and what else its provider has in the field.

Also from NVIDIA

09 / line

The line

Every model in this family in release order, so a page from eight months ago says in one glance that two newer ones exist.

  1. 01Nemotron 3 Super11/03/2026
  2. 02Nemotron 3 Nano Omni (free)28/04/2026
  3. 03Nemotron 3.5 Content Safety04/06/2026
  4. 04Nemotron 3 Ultra04/06/2026
  5. 05Nemotron 3.5 Lightning11/08/2026

Ordered by release date and worked out from the naming, so a new member slots in as soon as its page exists. A retired model keeps its page and its place in the line.

10 / notes

Our notes

What this model changes for a brand trying to be cited in AI answers, and every change we have logged since it launched.

What it changes for you

A moderation model does not read your marketing site or cite your brand, so it does not change how you get surfaced in AI answers. What it does change is upstream: if your product feeds user content into an LLM, the safety layer is now something you can run yourself rather than inherit, which affects what you can honestly say about data handling and content controls in the trust and security pages that buyers and AI engines do read.

Where buyers meet this model

Buyers rarely meet this one directly. It shows up in the API, inside products that accept user-generated text and images, and in the safety layer of AI features that a SaaS team has assembled themselves. There is no consumer app and no AI search surface running on it, the models it guards are the ones users actually see.

Change log

Nothing published here yet. Changes appear within hours of a provider announcing them.

11 / questions

Questions

The things people ask about this model, answered from what is on this page rather than from anywhere else.

Can Nemotron 3.5 Content Safety be used as a general chat model?
No. It is a guardrail model fine-tuned for moderation, judging whether inputs and responses should pass. It is designed to sit around a generative model, not to be one.
Does it handle images as well as text?
Yes. It is multimodal and accepts text and image input, so uploaded images can be checked by the same model that screens the text around them.
What is it fine-tuned from?
Google Gemma-3-4B. NVIDIA fine-tuned that base into a 4B-parameter content safety model for moderating LLM and VLM traffic.
Does it moderate prompts, responses, or both?
Both. It is built to screen inputs going into an LLM or VLM and the responses those models produce.
Surge45°

Is Nemotron 3.5 Content Safety recommending you?

Models change what gets cited. We measure whether AI answers name your brand or your competitors across every assistant, and show you what to change.