Guardrails libraries operate on language: classify a prompt, redact an output, refuse a topic. They are useful but not enforcement. A model can produce a destructive tool call even with guardrails in place.