Vaadin has dropped version 25.3, a release that focuses heavily on making AI integration transparent and manageable for enterprise developers. The update introduces audit trails for AI-driven form filling, replaces the OpenTelemetry Java agent with a dependency-based observability kit, and ships a new dev-loop daemon designed to help coding agents verify their changes. This isn't just a UI library update; it's a shift toward making the 'black box' of AI agents legible in production environments.
Auditable AI Form Filling
While version 25.2 shipped the AI form filler, 25.3 adds the critical layer of accountability. Every field modified by the AI now carries a marker that reveals the source of the value, including a confidence level and snippets from the source document the model used. This allows users to revert specific AI-filled fields without retyping correct data. The system also includes a RequestInterceptor that lets developers mask or reject user prompts before they reach the orchestrator, enforcing data protection rules at the code level. Note that the advanced controllers for Grid and Forms are behind a commercial subscription, while the core interceptor API remains free.
Observability Without the Java Agent
The biggest operational change is Observability Kit 5, which has been rebuilt on Micrometer. This eliminates the need for a separate OpenTelemetry Java agent and the associated -javaagent deployment flags. Developers simply add a dependency, and metrics flow through Spring Boot Actuator to any OTLP collector like Prometheus or Datadog. The new kit provides deep insights into UI state sizes and failed interactions, helping developers diagnose heap growth and latency issues. However, this is a commercial feature requiring Java 21, and it currently lacks support for client-side Hilla views.
A Dev Loop Built for Coding Agents
Addressing the friction of AI-assisted coding, Vaadin 25.3 introduces a dev-loop daemon and CLI in preview. This tool allows coding agents to apply changes and receive immediate feedback via exit codes, determining whether a CSS tweak or method body swap succeeded without a full restart. The CLI installs agent skills into .agents/skills/ and .claude/skills/, integrating directly with common AI workflows. While powerful, it has known limitations, such as failing to run annotation processors like Lombok during hot-swaps, which developers must account for in their agent pipelines.
Key Takeaways
- AI form filling now includes confidence levels and source snippets for auditability, though advanced controllers require a commercial license.
- Observability Kit 5 removes the Java agent requirement, using Micrometer for simpler deployment but requiring Java 21.
- A new dev-loop CLI helps coding agents verify changes instantly, with built-in support for Claude and other agent skill directories.
- The browser-side engine has migrated from GWT to TypeScript, improving debugging and build speeds.
The Bottom Line
Vaadin is finally admitting that AI agents need guardrails, not just magic. By making AI decisions auditable and giving coding agents a way to verify their own work, theyβre turning 'vibe coding' into a debuggable, enterprise-ready practice. If youβre building with LLMs in Java, this update is the missing link between prototype and production.