Files
supabase/apps/studio/lib/ai
Matt Rossman a133ef60a6 fix(studio): correct the Assistant's blocked-tool privacy message (#50411)
When the Assistant calls a tool that's blocked on permissions, the
response had two problems.

First, it told users their data goes to Amazon Bedrock when production
inference [routes to
OpenAI](https://github.com/supabase/supabase/blob/b824acdfd204071f931a0aee01bee953ef164b6b/apps/studio/pages/api/ai/sql/generate-v4.ts#L170-L172).
It now says "third-party AI providers" like the [opt-in
settings](https://github.com/supabase/supabase/blob/b824acdfd204071f931a0aee01bee953ef164b6b/apps/studio/components/interfaces/Organization/GeneralSettings/AIOptInLevelSelector.tsx#L84-L88)
do. I verified that was the last user-facing Bedrock mention.

Second, HIPAA-restricted projects got that same copy telling them to
change data opt-in settings, but for those projects `getAIDetails`
[forces their level to
`disabled`](https://github.com/supabase/supabase/blob/b824acdfd204071f931a0aee01bee953ef164b6b/apps/studio/lib/ai/ai-details.ts#L70-L73).
They get separate copy now to prevent confusion.

Closes AI-1154


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
  - Added HIPAA-aware AI controls for eligible projects.
  - AI opt-in is automatically disabled when HIPAA requirements apply.
- Privacy messages now distinguish standard AI opt-in restrictions from
HIPAA-related restrictions.
- AI-assisted SQL and tool experiences consistently apply HIPAA
restrictions when determining available capabilities.
- **Bug Fixes**
- Improved handling of AI settings for HIPAA-sensitive projects and
invalid project or organization configurations.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-16 08:16:49 -04:00
..