Landscape · where NIL sits
NILScript isn’t another tool in the stack.
It’s the layer underneath the write.
NILScript is a server-side governed-action contract for AI agents: the agent proposes intent, a deterministic kernel is the only component that commits, and an action a backend never declared is unexpressible rather than filtered. So it isn’t a substitute for one product — it’s the governance layer that guardrails, gateways, workflow engines, and agent frameworks all leave undefined.
Read this before the tables
Shipped today is narrow. The rest is stated as vision — and marked as such.
What NILScript 0.3.0 ships is one load-bearing guarantee: the governed action layer — propose → approve → commit → rollback, with undeclared actions structurally unexpressible. The broader enterprise story — a business ontology, business cycles, an executable digital twin of the whole enterprise — is where NIL is heading, not what today’s release delivers. Every matrix below tags that difference with a roadmap mark, so vision is never dressed up as done.
The stack
Everyone else operates above the effect. NIL is the effect boundary.
Guardrails inspect the conversation. Frameworks orchestrate the agent. Engines run the workflow. All of them still hand a namable write to the backend. NIL is the one layer where an unauthorized action has no representation to send.
Intent · governance · policies · execution · automation — across humans, AI agents & systems
The market
NILScript vs. the categories it’s compared to
Eleven categories, one relationship each. NIL sits below some, composes others inside itself, and runs the rest as executors — with the enterprise-modelling categories marked as direction.
| Category | Examples | Solves | Control | Where NILScript sits |
|---|---|---|---|---|
| LLM Guardrails | NeMo Guardrails, Guardrails AI, LLM Guard, Lakera | Protect conversations & model I/O | Probabilistic | NIL sits below the effect |
| Safety Models | Llama Guard, GA Guard | Classify harmful content | Probabilistic | Orthogonal — NIL governs the write, not the text |
| AI Gateways | Portkey, DeepInspect | Monitor request traffic | Semi-deterministic | NIL governs authorship, not just traffic |
| Policy Engines | Cedar (AWS), OPA | Enforce access policy | Deterministic | Composes inside NIL at the effect boundary |
| Workflow Engines | Camunda, Temporal, n8n, Airflow | Execute workflows | Deterministic | Each step runs through a governed NIL op |
| BPM Platforms | Pega, Appian, Bizagi | Manage business processes | Deterministic | Vision: NIL models cycles above execution |
| Agent Frameworks | LangGraph, CrewAI, AutoGen, OpenAI Agents SDK | Orchestrate agents | Low | They call NIL to act safely |
| Enterprise Integration | MuleSoft, Boomi, Apache Camel | Connect systems | Deterministic | NIL uses adapters as executors |
| Knowledge Graphs | Neo4j, Stardog, Ontotext | Represent knowledge | Deterministic | Vision: NIL adds governed execution over the model |
| Digital Twin Platforms | Azure Digital Twins, Siemens Digital Twin | Model systems | Deterministic | Vision: NIL makes the model executable |
| Intent-Based Systems | AWS AgentCore + Cedar, Containment.ai, OAP, AARM, OpenPort, AGT, OAGS | Enforce intent before action | Deterministic | Closest peers — NIL adds unexpressibility + honest reversibility |
Head to head
Capability matrix
Five representative tools, one per category, against NILScript. Competitor columns show what each does today; the NILScript column separates shipped from roadmap.
- shipped in 0.3.0
- partial
- not addressed
- NIL roadmap / vision
| Capability | NeMo | Guardrails AI | LangGraph | Camunda | Cedar | NILScript |
|---|---|---|---|---|---|---|
| LLM protection | Yes | Yes | No | No | No | Yes |
| Agent protection | Partial | Partial | No | No | Partial | Yes |
| Intent layer | No | No | No | No | Partial | Yes |
| Ontology | No | No | No | No | No | Roadmap / vision |
| Business cycles | No | No | No | Partial | No | Roadmap / vision |
| Enterprise modeling | No | No | No | Partial | No | Roadmap / vision |
| Governance | Partial | Partial | No | Yes | Yes | Yes |
| Automation | No | No | Partial | Yes | No | Yes |
| Multi-agent coordination | Partial | No | Yes | No | No | Partial |
| Human + AI + systems | No | No | No | Partial | No | Yes |
| Digital twin of the enterprise | No | No | No | No | No | Roadmap / vision |
This reflects each platform’s targeted capabilities as described in its own documentation or, for NILScript, its stated vision — not all are implemented to the same maturity, or shipping in current releases.
The closest peers
Five deterministic-gate efforts landed in 2026. That’s validation, not a moat.
OAP (APort), AARM (Errico), OpenPort (Accentrust), AGT (Microsoft), and OAGS (Sekuire) all converged on the same bet: a deterministic pre-action gate that yields a 0% unauthorized-action rate. NIL is honest that this validates the direction rather than fencing it off. What distinguishes NIL is a triad, not the gate alone:
Unexpressible
An undeclared verb has an empty preimage — nothing to send, not something filtered.
Honestly reversible
Every write declares REVERSIBLE / COMPENSABLE / IRREVERSIBLE, verified by a conformance run.
Earned, not asserted
Success is confirmed by reading the record back; claims that fail their run fail admission.
Straight answer
Which tool do you actually need?
NIL doesn’t replace these. Reach for the right layer for the job — and reach for NIL when the job is letting an agent write to your real systems.
| Protect chat & LLM input/output | NeMo Guardrails / Guardrails AI |
| Classify harmful content & outputs | Llama Guard / LLM Guard |
| Execute a workflow | Camunda / Temporal |
| Enforce access policy | Cedar / OPA |
| Coordinate several agents | LangGraph / CrewAI |
| Model knowledge | Neo4j / Stardog |
| Let an agent act on your real systems without trusting the agent — govern the write itself | NILScript |
Move the trust boundary to the server.
Let an agent operate your real systems without trusting the agent. Build the adapter once; every agent speaks to it. Free to adopt, no lock-in.