Independent project. Not a U.S. government website.

USASI
Model release

Llama Guard 4 12B

Release in the Llama family · version Llama-Guard-4-12B

Maintained by Meta18

Llama Guard 4 is a 12-billion-parameter safety classifier from Meta for text and images. Given a prompt sent to a language model, or a model's response, it generates text saying whether the content is safe or unsafe and, if unsafe, which categories it violates: 13 categories based on the MLCommons hazards taxonomy plus a text-only category for code interpreter abuse. It is a dense model pruned from the pre-trained Llama 4 Scout and fine-tuned for classification, and it accepts multiple images in one prompt. Meta released it on April 29, 2025, as one of its Llama protection tools.18Fact reviewed Oct 8, 2026

Last reviewedEntry updated Documented release Apr 29, 2025

Availability and license

Overall availability

Partial

The Hugging Face repository is gated with manual approval: requesters must accept the Llama 4 Community License and submit their name, date of birth, country, affiliation, and job title. The Llama 4 Acceptable Use Policy shipped with the model withholds the license grant for Llama 4 multimodal models from individuals domiciled in, and companies with a principal place of business in, the European Union; this catalog has not confirmed how Meta applies that clause to Llama Guard 4.453

Availability fact review: Oct 8, 2026

Availability is separate from permission: read the license before using or redistributing.

Custom Meta license, effective April 5, 2025; the Hugging Face metadata lists it as "other" with the name llama4. It grants a royalty-free, non-exclusive license to use, modify, and redistribute. Redistributors must include the agreement, show "Built with Llama", and keep an attribution notice, and distributed models trained or fine-tuned with Llama materials or outputs must start their names with "Llama". Use must follow the incorporated Llama 4 Acceptable Use Policy. Licensees whose products had more than 700 million monthly active users in the month before the Llama 4 release date must request a separate license. The license ends for anyone who sues alleging that the Llama materials or outputs infringe their rights. California law governs.243Fact reviewed Oct 8, 2026

Component reuse rights

A readable or downloadable component is not automatically reusable. These indicators concern recorded license evidence, not system certification.
weights
Unknown — no complete fact-level rights review
code
Unknown — no complete fact-level rights review
data
Unknown — no complete fact-level rights review
documentation
Unknown — no complete fact-level rights review

No complete system-rights review is recorded for this release.

Model-disclosure tier

Computed from the checklist below using USASI rubric v0.2. An editorial category, not a certification.
Model-disclosure tier (USASI rubric v0.2): Restricted weights

The weights can be obtained only by request, with approval, or by some users — for example a gated download that the publisher reviews. Not counted as open-weight.

How tiers are computed

Public materials checklist

Items for a model under USASI rubric v0.2. Unknown means unassessed or insufficient evidence.
Public materials checklist for Llama Guard 4 12B
ItemStatusNotes and evidence
WeightsCan the general public download the model parameters for this release?PartialBF16 safetensors (12,001,097,216 parameters per the repository metadata) in a Hugging Face repository gated with manual approval and a personal-information form.45
Inference codeIs code for running the model published?PublicThe repository metadata identifies the Hugging Face Transformers Llama 4 architecture (Llama4ForConditionalGeneration), and Meta's documentation specifies the prompt format, including how images are split into 336-by-336-pixel tiles. This review could not read the gated Hugging Face card.46
Training codeIs the code used to train the model published?UnknownNo training or pruning code for Llama Guard 4 was found in the repositories reviewed.
Training-data informationDoes the information cover provenance, scope, acquisition, selection, labeling, processing, and where data or alternatives can be obtained? Access alone does not establish completeness.PartialThe card says post-training used the Llama Guard 3 8B and 11B-vision training data plus multi-image samples (mostly two to five images) and multilingual data, written by human annotators or translated from English, at roughly three parts text-only to one part multimodal. The data is not released.1
Training-data accessCan the training data be obtained? This is independent of information completeness and reuse rights; original unshareable data need not be downloadable.UnknownNot assessed.
Complete training pipelineIs the complete base-training and preprocessing pipeline published, including configuration? Fine-tuning code or an inference SDK alone is insufficient.UnknownNot assessed.
Legacy data assessment (v0.1)Historical assessment combining download access and disclosure. Preserved for traceability; excluded from the v0.2 tier calculation. See the new separate assessments above.UnknownNot assessed.
Training recipeAre the training configuration and procedure documented in enough detail to follow?PartialThe card describes pruning the Llama 4 Scout pre-trained checkpoint by removing all routed experts and routers and keeping the shared expert, with no further pre-training, followed by post-training for classification. Hyperparameters are not given.1
Evaluation materialsPublic = evaluation code or prompts that let others re-run the evaluations are published. Partial = results only.PartialThe card reports recall, false positive rate, and F1 against Llama Guard 3 on an in-house test set that the card does not make available.1

What it is useful for

Filtering the inputs to a generative model, its outputs, or both, as part of a larger system. Meta's documentation says it is designed to work with Llama 4 Scout and Maverick and can be used as a drop-in replacement for Llama Guard 3 8B and 11B. Meta's Llama Protections page says it is also available through the moderations endpoint of Meta's Llama API.167Fact reviewed Oct 8, 2026

Run and use notes

Documented facts only. No hardware or performance claims are made without a cited source and stated assumptions.
  • Meta's card and documentation say the model can be run on a single GPU; neither gives a memory figure or a precision for that statement.16
  • The card says the model was tested mostly with prompts containing a few images (most often three), that categories such as defamation, intellectual property, and elections may need up-to-date facts to judge, and that as a language model it may be open to prompt injection; it points to Meta's Prompt Guard 2 for detecting prompt attacks.1

Organization context

Provenance and derivatives

Meta built Llama Guard 4 by pruning the pre-trained Llama 4 Scout mixture-of-experts checkpoint into a dense model and post-training it for safety classification. It shares Llama 4 Scout and Maverick's tokenizer and vision encoder.1

Other releases in the Llama family

Llama family overview

What this catalog does not know

Unknown means the sources reviewed for this record do not document it. It is not evidence that something does not exist.
  • Training code: unknown.
  • Training-data access: unknown.
  • Complete training pipeline: unknown.
  • Legacy data assessment (v0.1): unknown.

Have a primary source? How to report a correction.

U.S. eligibility

Project eligibility rests on documented governing or maintaining entities, not on contributors.

Eligible · basis: U.S. headquarters

Meta publishes the model and its card in its PurpleLlama repository and announced it on its AI blog. Meta Platforms, Inc. is a Delaware corporation whose Form 10-K for fiscal 2025 gives its address as Menlo Park, California, on the cover page.189

Assessed Oct 8, 2026

Sources

  1. 1.
    Llama Guard 4 model card (external site: raw.githubusercontent.com)

    Meta, PurpleLlama (GitHub) · Model card · accessed Oct 8, 2026

  2. 2.
    Llama Guard 4 LICENSE (Llama 4 Community License Agreement) (external site: raw.githubusercontent.com)

    Meta, PurpleLlama (GitHub) · License · published Apr 5, 2025 · accessed Oct 8, 2026

  3. 3.
  4. 4.
  5. 5.
  6. 6.
  7. 7.
    Llama Protections (external site: dev.meta.ai)

    Meta · Official page · accessed Oct 8, 2026

  8. 8.
  9. 9.
    Meta Platforms, Inc. Form 10-K for fiscal 2025, cover page (XBRL viewer) (external site: sec.gov)

    Meta Platforms, Inc. (via U.S. Securities and Exchange Commission EDGAR) · Filing · accessed Oct 8, 2026

Support Us

Help keep USASI useful.

Optional. No USASI account required. Payment takes place on the linked provider’s website (Buy Me a Coffee).

About supporting this project