Vaadin 25.3: AI you can audit, and observability without the Java agent Vaadin released version 25.3, adding auditable AI form-filling that marks every field the model changes with a revert control and, when source tracking is enabled, attaches a ValueSource carrying the model's ConfidenceLevel and SourceExtract snippets. The release also splits the AI modules so vaadin-ai-core-flow is free while the Grid, Chart and Form controllers plus field marker move to the commercially licensed vaadin-ai-extensions-flow, and it deprecates the SSO Kit, Collaboration Kit and AppSec Kit, none of which will ship in Vaadin 26. Vaadin 25.3 additionally replaces Flow's browser-side GWT-compiled Java engine with TypeScript and adds a Switch component, a Table family for HTML tables, date constraints and upload validation. Vaadin 25.3 is the third feature release in the 25.x line. Three of its larger additions answer the same question in different places: what just happened? You can see which form fields the AI filled and how confident it was, what your application is doing in production, and whether a coding agent's last edit reached the running app. Around them is the usual release work, and there is a fair amount of it: a Switch component, a Table family for HTML tables, date constraints, upload validation and chat style variants for Message List. Under the hood, Flow's browser-side engine is now TypeScript instead of Java compiled to JavaScript with GWT. And three kits are on their way out: SSO Kit, Collaboration Kit and AppSec Kit are deprecated and will not be in Vaadin 26. The upgrade section says what replaces each. AI you can audit 25.2 shipped the AI form filler. 25.3 adds the record behind it. Every field the AI changes now gets a marker. Clicking it opens a popover that says the value came from the AI, with a control to revert that one field. The user can see what the model wrote and undo or correct the wrong values, without retyping the ones that were already right. Turn on source tracking and each value the model fills from an attached document also carries a ValueSource : the ConfidenceLevel the model reports for it, and the SourceExtract snippets it says it read, with a SourceLocation on the page when it gives one. The confidence then shows next to the field, you can put the snippets into the marker's popover, and the location lets you highlight the passage in the source document. The controller does not check the snippets against the document, so they tell a reviewer where to look rather than proving the value. Tracking is off by default because it costs output tokens on every fill, and like the form filler itself it needs a commercial subscription. RequestInterceptor sees every user prompt and attachment before the orchestrator acts on it. You can inspect the request, replace its text or attachments to mask parts of it, or reject it. That makes a data-protection rule about what users send something you enforce in code. For each turn, ResponseMetadata gives your listeners the finish reason and the token usage, so you can log what a turn cost and spot a response that was cut off at the output limit. ToolException lets a tool tell the model why a call failed, in a message that is safe to pass back. The built-in providers also gain per-turn tool call limits, and opt-in background execution, which releases the session while a non-streaming turn runs you need push or polling to deliver the answer . The Spring AI https://vaadin.com/docs/latest/flow/ai-support/llm-providers and LangChain4j providers are built in as before, and you can write your own against the LLMProvider API. One packaging change to know about before you upgrade. The AI modules are now split. vaadin-ai-core-flow is free and holds the interceptor, the response metadata and the provider API. The Grid, Chart and Form controllers and the field marker live in vaadin-ai-extensions-flow and need a commercial subscription, checked in development mode. The vaadin dependency includes both. If you build on vaadin-core , the controllers are no longer included. If you depended on vaadin-ai-components-flow directly, that coordinate is gone and there is no automatic replacement. The AI integration is still a preview feature , as the API may still change. Enable it with the com.vaadin.experimental.aiComponents feature flag, from Copilot's experimental features tab or in src/main/resources/vaadin-featureflags.properties . Without it, the first prompt fails. Components Switch https://vaadin.com/docs/latest/components/switch is a new component for a setting that takes effect the moment you flip it, where a checkbox would need a save button next to it. It needs no feature flag, and it has the same features as other input field components, like helper text, a required indicator and an error message, plus icon, small and reverse style variants. Table https://vaadin.com/docs/latest/components/html-elements/table replaces NativeTable . Table , TableHead , TableBody , TableRow and their siblings give you