Files
Matt RossmanandJoshen Lim 4bb36b944f feat(studio): let High Compliance projects opt-in to Assistant data access (#50548)
Orgs with the HIPAA add-on had the Assistant's opt-in level forced to
`disabled` on any project marked High Compliance, regardless of what the
org picked in its AI settings. The restriction predated our AI provider
BAAs. The consequence is those users see the Assistant failing to answer
questions about their data w/ no clear path how to fix it, even though
the LLM provider supports this use case.

This PR removes these Assistant restrictions on the server and client so
those projects honor the org's chosen level. Braintrust conversation
tracing is unchanged and still blocked for these projects, see [this
test
case](https://github.com/supabase/supabase/blob/b9800ccf16/apps/studio/lib/ai/braintrust-logger.test.ts#L16-L20).
See
[comments](https://linear.app/supabase/issue/AI-1153/allow-hipaa-orgs-to-opt-in-to-assistant-data-access-for-high#comment-485a0d46)
for legal approval and conditions.

The client-side changes enable features like "Debug with AI" on SQL
query failures, “Generate/Rename with AI” for snippet titles, and
generated Assistant chat titles for these customers.

The AI opt-in copy now adds a reminder to obtain consent from data
subjects, linking the [shared responsibility
model](https://supabase.com/docs/guides/deployment/shared-responsibility-model)
based also on [this
comment](https://linear.app/supabase/issue/AI-1153/allow-hipaa-orgs-to-opt-in-to-assistant-data-access-for-high#comment-f81ee610).

<img width="400" alt="CleanShot 2026-09-17 at 5 01 02 PM@2x"
src="https://github.com/user-attachments/assets/d02123f2-3e32-4d83-9f98-7d15e59222ef"
/>

To test with a HIPAA-enabled project in staging, you can use this [Plan
Change
[Staging]](https://app.hex.tech/supabase/app/Plan-Change-Staging-032BD32jo1EaisCS85qunf/latest)
Hex to add the HIPAA add-on. Once the add-on is present, you can turn on
High Compliance from a project's settings. Also in org settings, crank
up the Assistant data opt-in level and verify the Assistant is able to
answer questions about the project's data.

My results testing with opt-in level "Schema, Logs & Database Data":

| High compliance setting | Data opt-in working |
|--------|--------|
| <img width="1302" height="422" alt="CleanShot 2026-09-17 at 5 03 36
PM@2x"
src="https://github.com/user-attachments/assets/c416371b-2eb8-49df-9c07-6d8eababb443"
/> | <img width="1566" height="1516" alt="CleanShot 2026-09-17 at 5 05
14 PM@2x"
src="https://github.com/user-attachments/assets/39624355-7f8f-46ce-9f08-a8acfb9da830"
/> |

Closes AI-1153


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## New Features

- AI-assisted query renaming, snippet title generation, debugging, and
tools now follow organization AI opt-in settings rather than project
HIPAA status.
- Debugging assistance and AI actions remain available for eligible
users without additional HIPAA-based blocking.
- AI metadata warnings consistently show standard opt-in messaging and
permission settings.
- AI settings remind users to obtain consent before entering personal
data and link to shared responsibility guidance.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-09-18 08:21:50 -04:00

139 lines
4.7 KiB
TypeScript
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
import { ReactNode } from 'react'
import { Control } from 'react-hook-form'
import { FormField, RadioGroup, RadioGroupItem } from 'ui'
import { FormItemLayout } from 'ui-patterns/form/FormItemLayout/FormItemLayout'
import { OptInToOpenAIToggle } from './OptInToOpenAIToggle'
import { InlineLink } from '@/components/ui/InlineLink'
import { AIOptInFormValues } from '@/hooks/forms/useAIOptInForm'
import { useIsFeatureEnabled } from '@/hooks/misc/useIsFeatureEnabled'
import { DOCS_URL } from '@/lib/constants'
interface AIOptInLevelSelectorProps {
control: Control<AIOptInFormValues>
disabled?: boolean
label?: ReactNode
layout?: 'horizontal' | 'vertical' | 'flex-row-reverse'
}
export const AIOptInLevelSelector = ({
control,
disabled,
label,
layout = 'vertical',
}: AIOptInLevelSelectorProps) => {
const {
aiOptInLevelDisabled,
aiOptInLevelSchema,
aiOptInLevelSchemaAndLog,
aiOptInLevelSchemaAndLogAndData,
} = useIsFeatureEnabled([
'ai:opt_in_level_disabled',
'ai:opt_in_level_schema',
'ai:opt_in_level_schema_and_log',
'ai:opt_in_level_schema_and_log_and_data',
])
const AI_OPT_IN_LEVELS = [
...(aiOptInLevelDisabled
? [
{
value: 'disabled',
title: 'Disabled',
description:
'You do not consent to sharing any database information with third-party AI providers and understand that responses will be generic and not tailored to your database',
},
]
: []),
...(aiOptInLevelSchema
? [
{
value: 'schema',
title: 'Schema Only',
description:
'You consent to sharing your database’s schema metadata (such as table and column names, data types, and relationships—but not actual database data) with third-party AI providers',
},
]
: []),
...(aiOptInLevelSchemaAndLog
? [
{
value: 'schema_and_log',
title: 'Schema & Logs',
description:
'You consent to sharing your schema and logs (which may contain PII/database data) with third-party AI providers for better results',
},
]
: []),
...(aiOptInLevelSchemaAndLogAndData
? [
{
value: 'schema_and_log_and_data',
title: 'Schema, Logs & Database Data',
description:
'You consent to give third-party AI providers full access to run database read-only queries and analyze results for optimal results',
},
]
: []),
]
return (
<FormItemLayout
label={label}
layout={layout}
description={
<div className="flex flex-col gap-y-4 my-4 max-w-xl">
<p>
Supabase AI can provide more relevant answers if you choose to share different levels of
data. This feature is powered by third-party AI providers. This is an organization-wide
setting, so please select the level of data you are comfortable sharing.
</p>
<p>
For organizations with HIPAA compliance enabled in their Supabase configuration, any
consented information will only be shared with third-party AI providers with whom
Supabase has established a Business Associate Agreement (BAA). Don't input personal data
unless you've{' '}
<InlineLink href={`${DOCS_URL}/guides/deployment/shared-responsibility-model`}>
obtained consent
</InlineLink>{' '}
from the individuals it relates to.
</p>
<OptInToOpenAIToggle />
</div>
}
>
<div className="max-w-xl">
<FormField
control={control}
name="aiOptInLevel"
render={({ field }) => (
<RadioGroup
value={field.value}
onValueChange={field.onChange}
disabled={disabled}
className="space-y-2 mb-6"
>
{AI_OPT_IN_LEVELS.map((item) => (
<div key={item.value} className="flex items-start space-x-3">
<RadioGroupItem
value={item.value}
id={`ai-opt-in-${item.value}`}
className="mt-0.5"
/>
<label
htmlFor={`ai-opt-in-${item.value}`}
className="cursor-pointer flex flex-col"
>
<span className="text-sm font-medium text-foreground">{item.title}</span>
<span className="text-sm text-foreground-light">{item.description}</span>
</label>
</div>
))}
</RadioGroup>
)}
/>
</div>
</FormItemLayout>
)
}