Guides → Playground & Guide → Guardrail / Security Cost - Runtime Safety, Prompt-Injection and PII Screening

Guardrail / Security Cost - Runtime Safety, Prompt-Injection and PII Screening

Meet Nadia Haddad. Security engineer adding runtime guardrails to an agent. "Every request needs injection and PII screening. What does that safety layer add as a percent over our token bill?"

🔥 Security mandated guardrails on every call. I need to tell finance what that does to per-request cost.

The story

Guardrails are a per-request tax. Prompt-injection detection and PII screening run on traffic, adding latency and cost on top of the model call itself.

This calculator sizes that layer - screening calls per request, model tier for the screeners - and expresses it as the percent it adds over your base token bill.

Framing it as a percentage makes the safety/cost tradeoff concrete: you can see exactly what tightening or relaxing screening does to the bill.

🎮 Playground

Guardrail / Security Cost Playground

Here are the inputs that move the result the most. Play with the sliders and check it out. The number updates live.

What will runtime guardrails cost?

Calls x screens per call x screening tokens, priced on a cheap guardrail model. ~30 days.

Estimated monthly cost

💡Cost = calls x % screened x screens x tokens x the guardrail model rate. Swap the model in the full calculator.

Ready to run the numbers?

Open the full calculator. Pick a model, enter your tokens, see per-call, daily, monthly, and annual cost.

🚀 Open the full calculator →

Top 3 right now

Verified 13 hours ago

About this calculator: Guardrail / Security Cost - Runtime Safety, Prompt-Injection and PII Screening

Cost runtime safety for an agent: prompt-injection and PII screening per request, and the percent it adds over your base token bill.

🎛 Inputs you control

Each input shapes the cost. Click an input on the calculator to set it. The explanations below match the live calculator field by field.

Guardrail (classifier) model: The model that runs each screening pass; its rates price the guardrail.
How to choose: Use a cheap, fast model (Haiku or Flash class), not your frontier agent model.
Agent calls / month: Total agent calls per month.
How to choose: Use your real monthly call volume.
Calls screened pct: Share of calls that pass through guardrails.
How to choose: High-risk surfaces screen 100 pct; low-risk internal flows may screen less.
Passes per call: Guardrail passes per screened call: 1 safety, 2 adds prompt-injection, 3 adds PII redaction.
How to choose: Match your policy; more passes mean more cost and latency.
Tokens checked / pass: Content tokens sent to the classifier per pass.
How to choose: Roughly the size of the input or output being screened.
Verdict tokens / pass: Classifier output tokens per pass (usually a small label or score).
How to choose: Keep it small; a label plus reason is often 10-30 tokens.
Guardrail platform USD per month: Flat fee for a managed guardrail platform, if any. Inferred default.
How to choose: Zero for self-hosted; use the vendor quote for a managed platform.
Your agent token bill USD per month: Your agent monthly token spend, used to express guardrails as a percent uplift.
How to choose: Pull from the cost or agent-loop calculator, or leave 0 to skip the uplift.
📋 Typical values & starting points Don’t know a value yet? Start with these broad, sourced ballparks — the calculator’s ▾ Typical menus pre-load the same options.

Context: Runtime screening (prompt-injection + PII) per request; from 2026-08-02 the EU AI Act makes demonstrable runtime controls and event logging a legal requirement for high-risk deployers, not a quality preference.

Input Default Typical ballparks
callsPerMonth moves the needle 500,000 Pilot · 50K calls/mo = 50,000 · Mid production · 500K/mo = 500,000 · High volume · 5M/mo = 5,000,000
pctScreened moves the needle 100 Full input+output rails · 100% = 100 · Sampled output rail · 50% = 50 · High-volume sampling · 10% = 10
screensPerCall moves the needle 2 Input rail only = 1 · Input + output (common minimum) = 2 · + tool-call rail = 3 · All four rails (incl. retrieved-content) = 4
avgScreenInputTokens 1,500 Classifier-style input check · ~100 tok = 100 · Output-response check · ~400 tok = 400 · Full prompt+response screen · ~1.5K tok = 1,500 · Long-context screen · ~4K tok = 4,000
avgScreenOutputTokens 12 Verdict label only * = 12 · Verdict + category + reason * = 60 (rough estimates)
baseMonthlyTokenUsd 0 Pilot spend · ~$500/mo = 500 · Team · ~$5K/mo = 5,000 · Department · ~$50K/mo = 50,000 · Enterprise · ~$250K/mo = 250,000
guardrailModelSlug claude-haiku-3-5
platformMonthlyUsd 0

Ballparks are broad industry starting points (sourced ranges; * = rough estimate) — your result gets more accurate as you replace them with measured numbers. Try them live in the calculator; API & agent users get the same data from the MCP resource aicost://input-reference/guardrail-security-cost.

Most popular

Everything above is the 80% case. The last 20% is where the money is.

The gaps we just listed are real, and they are the expensive ones: your actual prompts, your switching cost, your MLOps overhead. An AICost expert spends the hour on your AI and cloud costs, not a generic playbook. You leave with a written report: the way forward, in 30 days of concrete steps.

  • An hour with the people who built the engines
  • Report the same day
  • The fee credits toward any AICost plan
  • Two slots a week
Book a Solution Session: $299 → or $99 for small business →

Not sure yet? The $39 AICost Blueprint credits toward a Session, and the Session fee credits toward any plan. You never pay twice for the same ground. See all pricing →

Ready to run your own numbers?

You have seen the shape of it. Open the calculator with your model, your tokens, your volume.

🚀 Open the full calculator →

Methodology

Editorial gate
8-layer defense, see aicost.ai/ai-cost-economics
Last verified
7/20/2026, 8:00:00 PM

Author: Subu Vdaygiri, Founder & CEO of CloudIntelligence.ai. 17 years Fortune 100 (Ingram Micro, Siemens). Wharton CTO program · Kellogg CPO program · 10× AWS+Azure certified.

📖 Data sources & methodology 158 text models · 9 embeddings · 37 vision · 55 audio · 8 vector DBs across 10 vendor pages · last verified 2026-07-21

Methodology

  • All prices are USD per 1 million tokens, current as of 2026-07-21.
  • Vendor-published values have no mark. Inferred/extrapolated values are marked with * and listed below.
  • Batch API discounts are 50% off standard rates across providers that offer Batch mode.
  • Prompt caching discounts vary by provider (typically 80-90% off cached input tokens).
  • Regional data-residency surcharges (Anthropic 1.1x, OpenAI 1.1x, Google regional tiers) are NOT included in base rates.
  • Long-context pricing tiers apply when input exceeds model threshold.
  • Embedding prices are input-only (no output tokens generated).

Primary sources

Last-verified date is the most recent successful daily snapshot (aicost_pricing_snapshots) or, when no snapshot exists yet, the latest successful crawler run (aicost_crawler_runs). 10 of 10 vendors are currently verified. Aggregator services (TokenCost, AI Pricing Guru, etc.) are not listed.

Anthropic
2026-07-21
https://www.anthropic.com/pricing
Daily snapshot since Sep 2023 · 624 days captured
Anthropic Docs
2026-07-21
https://platform.claude.com/docs/en/about-claude/pricing
Daily snapshot since Sep 2023 · 624 days captured
OpenAI
2026-07-21
https://openai.com/api/pricing/
Daily snapshot since Sep 2023 · 625 days captured
Google AI
2026-07-21
https://ai.google.dev/gemini-api/docs/pricing
Daily snapshot since Dec 2023 · 600 days captured
Google Vertex
2026-07-21
https://cloud.google.com/vertex-ai/generative-ai/pricing
Daily snapshot since Dec 2023 · 600 days captured
DeepSeek
2026-07-21
https://api-docs.deepseek.com/quick_start/pricing
Daily snapshot since May 2024 · 539 days captured
xAI
2026-07-21
https://x.ai/api
Daily snapshot since Nov 2024 · 457 days captured
Mistral
2026-07-21
https://mistral.ai/pricing
Daily snapshot since Dec 2023 · 598 days captured
Cohere
2026-07-21
https://cohere.com/pricing
Daily snapshot since Sep 2023 · 624 days captured

Inferred values (marked with * in calculator tables)

Derived from industry conventions, not directly published by the vendor. Typical conventions: cached input = 10% of base (90% off), Batch API = 50% of base (50% off).

Vendor / Model Field Why it’s inferred
Anthropic — Claude Sonnet 4.6 cachedInput Derived at 10% of input rate — Anthropic publishes 90% cache-hit discount on this tier.
Anthropic — Claude Sonnet 4.5 cachedInput Derived at 10% of input rate; same 90% cache-hit convention as Sonnet 4.6.
Anthropic — Claude Sonnet 4.5 batchInput Derived at 50% of standard input — Anthropic documents uniform 50% Batch discount.
Anthropic — Claude Sonnet 4.5 batchOutput Derived at 50% of standard output — Anthropic documents uniform 50% Batch discount.
Anthropic — Claude Haiku 4.5 cachedInput Derived at 10% of input rate — Anthropic 90% cache-hit discount convention.
OpenAI — GPT-5.4 Mini cachedInput Derived at 10% of input — OpenAI documents automatic 90% discount on cache hits across GPT-5.x tier.
OpenAI — GPT-5.4 Nano cachedInput Derived at 10% of input — OpenAI 90% cache-hit convention.
OpenAI — GPT-5.4 Nano batchInput Derived at 50% of input — OpenAI Batch API uniform 50% discount.
OpenAI — GPT-5.4 Nano batchOutput Derived at 50% of output — OpenAI Batch API uniform 50% discount.
OpenAI — GPT-5.4 Pro cachedInput Derived at 10% of input — OpenAI 90% cache-hit convention.
OpenAI — GPT-5.4 Pro batchInput Derived at 50% of input — OpenAI Batch API uniform 50% discount.
OpenAI — GPT-5.4 Pro batchOutput Derived at 50% of output — OpenAI Batch API uniform 50% discount.
OpenAI — GPT-5.2 cachedInput Derived at 10% of input; no residency uplift.
OpenAI — GPT-5.2 batchInput Derived at 50% of input.
OpenAI — GPT-5.2 batchOutput Derived at 50% of output.
OpenAI — GPT-5 cachedInput Derived at 10% of input.
OpenAI — GPT-5 batchInput Derived at 50% of input.
OpenAI — GPT-5 batchOutput Derived at 50% of output.
OpenAI — GPT-5.5 Pro cachedInput Derived at 10% of input — OpenAI does not publish a cached rate for *-pro models; using the family convention.
OpenAI — GPT-5.5 Pro batchInput Derived at 50% of input.
OpenAI — GPT-5.5 Pro batchOutput Derived at 50% of output.
OpenAI — GPT-5.2 Pro cachedInput Derived at 10% of input — pro-tier convention.
OpenAI — GPT-5.2 Pro batchInput Derived at 50% of input.
OpenAI — GPT-5.2 Pro batchOutput Derived at 50% of output.
OpenAI — GPT-5.1 batchInput Derived at 50% of input.
OpenAI — GPT-5.1 batchOutput Derived at 50% of output.
OpenAI — GPT-5 Pro batchInput Derived at 50% of input.
OpenAI — GPT-5 Pro batchOutput Derived at 50% of output.
OpenAI — GPT-5 Nano cachedInput Derived at 10% of input.
OpenAI — GPT-5 Nano batchInput Derived at 50% of input.
OpenAI — GPT-5 Nano batchOutput Derived at 50% of output.
Google — Gemini 3 Flash cachedInput Derived at 10% of input — Google caching discount convention ~90%.
Google — Gemini 3.1 Flash-Lite cachedInput Derived at 10% of input — Google caching convention.
Google — Gemini 3.1 Flash-Lite batchInput Derived at 50% of input — Google Batch API uniform 50% discount.
Google — Gemini 3.1 Flash-Lite batchOutput Derived at 50% of output — Google Batch API uniform 50% discount.
Google — Gemini 2.5 Pro cachedInput Derived at 10% of input.
Google — Gemini 2.5 Flash cachedInput Derived at 10% of input.
Google — Gemini 2.5 Flash-Lite cachedInput Derived at 10% of input — Google caching convention.
Google — Gemini 2.5 Flash-Lite batchInput Derived at 50% of input — Google Batch API uniform 50% discount.
Google — Gemini 2.5 Flash-Lite batchOutput Derived at 50% of output — Google Batch API uniform 50% discount.
Google — Gemini 2.0 Flash cachedInput Derived at 25% of input per Google 2.0 family caching rates.
Google — Gemini 2.0 Flash batchInput Derived at 50% of input — Google Batch API uniform 50% discount.
Google — Gemini 2.0 Flash batchOutput Derived at 50% of output — Google Batch API uniform 50% discount.
Google — Gemini 2.0 Flash-Lite cachedInput Derived at 10% of input — Google caching convention.
Google — Gemini 2.0 Flash-Lite batchInput Derived at 50% of input — Google Batch API uniform 50% discount.
Google — Gemini 2.0 Flash-Lite batchOutput Derived at 50% of output — Google Batch API uniform 50% discount.
xAI — Grok 4 (legacy) cachedInput Extrapolated at 25% of base.

Pricing is cross-verified against the LiteLLM community registry when available. Daily snapshots are kept in aicost_pricing_snapshots; every change is logged to aicost_price_changelog with old & new values for full audit trail. Read the full methodology →