Nemotron 3.5 Content Safety
By NVIDIA · United States
Updated 2026-08-28
Overview
NVIDIA's purpose-built content moderation model: a 4.3B multimodal (text+vision) classifier for flagging sensitive content, with 128K context and multilingual coverage under Apache 2.0.
When to pick this model
- Trust & safety pipelines needing automated text and image moderation
- Multilingual content filtering at scale
- Teams needing an Apache 2.0 model for commercial moderation tooling
- Pre-filtering pipelines ahead of a general-purpose LLM
VRAM requirements by quantization
| Quantization | VRAM required |
|---|---|
| Q4_K_M (recommended) | 2.5 GB |
| Q5_K_M | 3.1 GB |
| Q8_0 | 4.6 GB |
| FP16 (no quantization) | 9 GB |
VRAM figures include model weights plus a typical 8k KV cache and ~600 MB runtime overhead (Ollama / llama.cpp baseline). Add headroom for higher context lengths.
In practice, Nemotron 3.5 Content Safety fits an 8 GB consumer card at Q4_K_M (2.5 GB). Stepping up to Q8_0 nearly doubles the footprint to 4.6 GB, and unquantized FP16 weights take 9 GB — plan your GPU around the Q4 or Q5 figure unless you specifically need the higher fidelity.
Without a GPU, Nemotron 3.5 Content Safety needs roughly 6 GB of system RAM to run on CPU via llama.cpp or Ollama — workable for background jobs, but far slower than GPU inference. Throughput estimates from our compatibility engine: around 32 tokens/sec on entry-level GPUs, on the order of 50 tokens/sec on a mid-range card, and up to 75 tokens/sec on high-end hardware — assuming the chosen quantization fully fits in VRAM.
What hardware do you need
The table below matches Nemotron 3.5 Content Safety to common GPU memory tiers, using the highest-fidelity quantization that fully fits each card class. Spilling layers to system RAM works but costs most of the speed, so size your card to the quantization you actually want to run.
| GPU memory | Example cards | Best fit for Nemotron 3.5 Content Safety |
|---|---|---|
| 8 GB | RTX 5070 Laptop, RTX 5060, RTX 5060 Ti 8GB | Q8_0 (4.6 GB used) |
| 12 GB | RTX 5070, RTX 5070 Ti Laptop, RTX 4080 Laptop | FP16 (9 GB used) |
| 16 GB | RTX 5080, RTX 4080 Super, Radeon RX 9070 XT | FP16 (9 GB used) |
| 24 GB | RTX 4090, Radeon RX 7900 XTX, RTX 5090 Laptop | FP16 (9 GB used) |
| 32 GB | RTX 5090 | FP16 (9 GB used) |
Which GPU should you buy to run Nemotron 3.5 Content Safety?
To run Nemotron 3.5 Content Safety locally at Q4, you need ~2.5 GB of VRAM. The best value for this is a RTX 5060 (8 GB VRAM).
As an Amazon Associate, BestLLMfor earns from qualifying purchases, at no extra cost to you. It does not influence our independent rankings.
Strengths
- Apache 2.0 license for unrestricted commercial use
- Multimodal vision-language (SigLIP encoder)
- Multilingual coverage
- Native 128K context
- Purpose-trained specifically for content moderation
Limitations
- Specialized for safety — not a general-purpose model
- No official Ollama tag — install via HuggingFace
- Public benchmarks still limited
Typical workloads
In our catalog grid, Nemotron 3.5 Content Safety is filed under Multimodal Moderation, Sensitive Content Detection, Text+Image Filtering — the use cases where its size/quality trade-off makes the most sense. Its tags translate to concrete workloads: multi-step reasoning and math-flavoured tasks; vision-language work — screenshots, charts, scanned documents; multilingual workloads.
The 125k-token context window covers long chats and mid-sized documents, though very large retrieval workloads will need chunking. The Apache 2.0 license is permissive, so shipping it inside a commercial product raises no special legal questions.
Architecture & training
Architecture: Dense Transformer · 4.3B parameters · vision-language (SigLIP encoder) · 128K context
Training: Nemotron 3.5 Content Safety (NVIDIA): a multimodal model dedicated to classifying and moderating sensitive content (text + image). Vision-language architecture with a SigLIP encoder, covering multiple languages.
A dedicated, Apache-2.0 multimodal moderation classifier — narrow scope, but purpose-built and production-ready for trust & safety.
Quick start
# HuggingFace : nvidia/Nemotron-3.5-Content-SafetyOr use the open-source MCP server to query this model from Claude Desktop, Cursor, or any MCP-compatible client.
Similar models worth comparing
Frequently asked questions
How much VRAM does Nemotron 3.5 Content Safety need?
At the recommended Q4_K_M quantization, Nemotron 3.5 Content Safety needs about 2.5 GB of VRAM. Q8_0 takes 4.6 GB, and unquantized FP16 weights take 9 GB.
Can Nemotron 3.5 Content Safety run without a GPU?
Yes — with roughly 6 GB of system RAM it runs CPU-only through llama.cpp or Ollama. Expect a fraction of GPU speed, which is fine for background or batch jobs but slow for interactive chat.
What context window does Nemotron 3.5 Content Safety support?
Nemotron 3.5 Content Safety supports a 125k-token context window (128,000 tokens).
Can I use Nemotron 3.5 Content Safety commercially?
Yes. Nemotron 3.5 Content Safety is released under Apache 2.0, a permissive open-source license that allows commercial use, modification and redistribution.
How fast is Nemotron 3.5 Content Safety on consumer hardware?
Our compatibility engine estimates on the order of 50 tokens/sec on a mid-range GPU and up to 75 tokens/sec on high-end cards, assuming the quantization fully fits in VRAM.
Which quantization of Nemotron 3.5 Content Safety should I download first?
Start with Q4_K_M (2.5 GB) — the standard size/quality sweet spot. Step up to Q5_K_M or Q8_0 only if you have VRAM headroom. It already fits an 8 GB card at Q8_0.
Is Nemotron 3.5 Content Safety the right pick for you?