<nil>NILScript

Landscape · where NIL sits

NILScript isn’t another tool in the stack.
It’s the layer underneath the write.

NILScript is a server-side governed-action contract for AI agents: the agent proposes intent, a deterministic kernel is the only component that commits, and an action a backend never declared is unexpressible rather than filtered. So it isn’t a substitute for one product — it’s the governance layer that guardrails, gateways, workflow engines, and agent frameworks all leave undefined.

Read this before the tables

Shipped today is narrow. The rest is stated as vision — and marked as such.

What NILScript 0.3.0 ships is one load-bearing guarantee: the governed action layer — propose → approve → commit → rollback, with undeclared actions structurally unexpressible. The broader enterprise story — a business ontology, business cycles, an executable digital twin of the whole enterprise — is where NIL is heading, not what today’s release delivers. Every matrix below tags that difference with a roadmap mark, so vision is never dressed up as done.

The stack

Everyone else operates above the effect. NIL is the effect boundary.

Guardrails inspect the conversation. Frameworks orchestrate the agent. Engines run the workflow. All of them still hand a namable write to the backend. NIL is the one layer where an unauthorized action has no representation to send.

ApplicationChatbots · copilots · assistants
LLM GuardrailsNeMo · Llama Guard · Lakera · Guardrails AI
Agent FrameworksLangGraph · CrewAI · AutoGen
Workflow EnginesCamunda · Temporal · n8n
Policy EnginesCedar · OPA
Knowledge LayerNeo4j · ontologies
NILScriptthe governed action layer

Intent · governance · policies · execution · automation — across humans, AI agents & systems

The market

NILScript vs. the categories it’s compared to

Eleven categories, one relationship each. NIL sits below some, composes others inside itself, and runs the rest as executors — with the enterprise-modelling categories marked as direction.

CategoryExamplesSolvesControlWhere NILScript sits
LLM GuardrailsNeMo Guardrails, Guardrails AI, LLM Guard, LakeraProtect conversations & model I/OProbabilisticNIL sits below the effect
Safety ModelsLlama Guard, GA GuardClassify harmful contentProbabilisticOrthogonal — NIL governs the write, not the text
AI GatewaysPortkey, DeepInspectMonitor request trafficSemi-deterministicNIL governs authorship, not just traffic
Policy EnginesCedar (AWS), OPAEnforce access policyDeterministicComposes inside NIL at the effect boundary
Workflow EnginesCamunda, Temporal, n8n, AirflowExecute workflowsDeterministicEach step runs through a governed NIL op
BPM PlatformsPega, Appian, BizagiManage business processesDeterministicVision: NIL models cycles above execution
Agent FrameworksLangGraph, CrewAI, AutoGen, OpenAI Agents SDKOrchestrate agentsLowThey call NIL to act safely
Enterprise IntegrationMuleSoft, Boomi, Apache CamelConnect systemsDeterministicNIL uses adapters as executors
Knowledge GraphsNeo4j, Stardog, OntotextRepresent knowledgeDeterministicVision: NIL adds governed execution over the model
Digital Twin PlatformsAzure Digital Twins, Siemens Digital TwinModel systemsDeterministicVision: NIL makes the model executable
Intent-Based SystemsAWS AgentCore + Cedar, Containment.ai, OAP, AARM, OpenPort, AGT, OAGSEnforce intent before actionDeterministicClosest peers — NIL adds unexpressibility + honest reversibility

Head to head

Capability matrix

Five representative tools, one per category, against NILScript. Competitor columns show what each does today; the NILScript column separates shipped from roadmap.

  • shipped in 0.3.0
  • partial
  • not addressed
  • NIL roadmap / vision
CapabilityNeMoGuardrails AILangGraphCamundaCedarNILScript
LLM protectionYesYesNoNoNoYes
Agent protectionPartialPartialNoNoPartialYes
Intent layerNoNoNoNoPartialYes
OntologyNoNoNoNoNoRoadmap / vision
Business cyclesNoNoNoPartialNoRoadmap / vision
Enterprise modelingNoNoNoPartialNoRoadmap / vision
GovernancePartialPartialNoYesYesYes
AutomationNoNoPartialYesNoYes
Multi-agent coordinationPartialNoYesNoNoPartial
Human + AI + systemsNoNoNoPartialNoYes
Digital twin of the enterpriseNoNoNoNoNoRoadmap / vision

This reflects each platform’s targeted capabilities as described in its own documentation or, for NILScript, its stated vision — not all are implemented to the same maturity, or shipping in current releases.

The closest peers

Five deterministic-gate efforts landed in 2026. That’s validation, not a moat.

OAP (APort), AARM (Errico), OpenPort (Accentrust), AGT (Microsoft), and OAGS (Sekuire) all converged on the same bet: a deterministic pre-action gate that yields a 0% unauthorized-action rate. NIL is honest that this validates the direction rather than fencing it off. What distinguishes NIL is a triad, not the gate alone:

  • Unexpressible

    An undeclared verb has an empty preimage — nothing to send, not something filtered.

  • Honestly reversible

    Every write declares REVERSIBLE / COMPENSABLE / IRREVERSIBLE, verified by a conformance run.

  • Earned, not asserted

    Success is confirmed by reading the record back; claims that fail their run fail admission.

Straight answer

Which tool do you actually need?

NIL doesn’t replace these. Reach for the right layer for the job — and reach for NIL when the job is letting an agent write to your real systems.

Protect chat & LLM input/outputNeMo Guardrails / Guardrails AI
Classify harmful content & outputsLlama Guard / LLM Guard
Execute a workflowCamunda / Temporal
Enforce access policyCedar / OPA
Coordinate several agentsLangGraph / CrewAI
Model knowledgeNeo4j / Stardog
Let an agent act on your real systems without trusting the agent — govern the write itselfNILScript

Move the trust boundary to the server.

Let an agent operate your real systems without trusting the agent. Build the adapter once; every agent speaks to it. Free to adopt, no lock-in.