# Understanding AI packages

An AI package is a bundle curated by the operator: it defines which provider processes
your organisation's chat and semantic search, which models are used — and in which
jurisdiction. Instead of assembling providers, models and credentials yourself, you pick
a vetted combination with a clear classification.

You find the package selection in the **AI** area, on the **Access** page. A permanent
line states which package currently applies ("Current: …") or that your organisation uses
its [own configuration](https://lalabase.com/docs/en/guides/ai/byok).

## Pick the way first, then the content

The page asks an either/or question and shows only one answer at a time: below the
"Current" line sit two tiles, **System package** and **Own configuration**. Clicking one
opens its section; the other disappears while it is open.

The open tile is the one with the heavy frame. Separately from that, a small **Active**
marker shows which way is actually in force. Those are two different statements: you can
look at the other way without anything having been switched. Only a click on "Select this
package" or "Use own configuration" changes something.

The open section is part of the page address, so a bookmark leads back to it and clicking
a filter keeps the open section. If your organisation has neither picked a package nor
stored its own credentials, the page opens on the package catalogue, which is the
recommended way.

In that state the page says **No AI access set up yet** instead of a "Current" line, and
neither tile carries the "Active" marker. That is not an error but where every new
organisation starts: until you set up one of the two ways, AI cannot work, even if the AI
features are already enabled.

## The jurisdiction classification

Every package card carries a classification. It answers two separate questions: where is
the company based, and where is the data processed? Together they yield:

| Classification | Meaning |
|---|---|
| **European** | Provider based in the EU, processing in the EU. No third-country transfer. |
| **EU region, non-European provider** | Servers are in the EU, but the provider is a non-European company subject to the law of its home country. Legally this counts as a third-country transfer. |
| **EU provider, third-country region** | European company, processing outside the EU — the data leaves the EU. |
| **Outside the EU** | Provider and processing are outside the EU. |
| **Own server** | Processing runs on a self-operated server. The operator of the installation is responsible, not an external provider. |

<div class="docs-callout docs-callout--info">
  <div class="docs-callout__title">Derived, not just claimed</div>
  <p>Where the stored credentials allow it, the classification is derived from their facts (company seat and processing location) rather than merely claimed. If a fact changes later, the classification moves with it — without anyone re-saving the package.</p>
</div>

## What happens to your content

The jurisdiction classification says **where** processing happens. It does not say **what**
the provider does with your content. A second badge on every package card and a sentence
about the storage period answer that.

| Badge | Meaning |
|---|---|
| **No training** | The provider has contractually assured that your content is not used to train its models. |
| **Training by the provider** | The provider uses content you process through the AI features to train its models. |
| **Training not assured** | No contractual assurance exists for this package. |

<div class="docs-callout docs-callout--warning">
  <div class="docs-callout__title">"Not assured" is not an all-clear</div>
  <p>The grey badge does not mean training happens — it means we cannot evidence that it does not. That is exactly why it is shown: quietly omitting a missing statement would read like an assurance nobody gave.</p>
</div>

Below it sits a sentence about the **storage period** at the provider — from "not stored"
through a concrete limit to "with no assured time limit". That is a separate question: a
provider can exclude training and still keep your content for a while.

**A package is only as good as its weakest provider.** Chat and search can run on different
providers. If only one of them assures "no training", the card still shows "Training by the
provider" — never the other way round. For the storage period, the **longest** limit is named
for the same reason.

Packages classified as **Own server** carry no training badge. No external provider receives
your content there at all, so the question does not arise.

<div class="docs-callout docs-callout--info">
  <div class="docs-callout__title">Where these statements come from</div>
  <p>They come from the providers' contractual documents, recorded and assessed by the operator — not from a self-declaration inside the product. If a provider revises its terms and that is recorded, the display moves with it, without anyone re-saving the package.</p>
</div>

## Two filters, two questions

Above the package cards sit two independent filters: **Provider** (EU companies / also
non-European companies) and **Processing** (EU only / also outside the EU). The two
questions are deliberately separate — "I need a European provider" and "the data must
not leave the EU" are different requirements, and not every package answers both the
same way. The default is the strictest combination; every relaxation is a deliberate
decision.

## Performance tiers

Within the chosen package you pick a performance tier (e.g. "Fast & affordable" or
"Thorough"). Each tier has its own model and may also lead to a different curated
provider within the package — the transparency notice in the chat shows which one is
answering. The jurisdiction classification applies to the package as a whole: it takes
every included provider into account, and the stricter reading wins. Auxiliary tasks
such as participant detection, summaries and the indexing of connected repositories
always run on the lowest tier, regardless of your choice.

## What happens during the switch

If the switch triggered a search rebuild, the **Access** page shows how far along it is —
directly below the "Current" line, with the number of records still outstanding. The display
refreshes when you reload the page; depending on the provider and the amount of data, a
rebuild takes minutes to hours.

Besides ongoing progress, three states mean something different:

| Display | Meaning |
|---|---|
| **Rebuild complete** | The new index is complete and usually becomes active automatically within fifteen minutes. Nothing for you to do. |
| **Switch paused** | The monthly allowance is used up. The rebuild is on hold and resumes automatically once the allowance resets next month. |
| **Switch stalled** | A special case that will not resolve on its own — contact your system administrator. Your search keeps working unchanged in the meantime. |

If nothing is shown there, no switch is running.

## When your package is not in the catalogue

Two situations keep your own package from appearing among the cards. In both, it is still
shown to you — above the catalogue, with a note saying which case applies:

* **The filters hide it.** Your package does not meet the criteria set above, for example
  because you set "in the EU only" and your package carries a different classification. The
  card works normally and you can still change the service tier. Relax the filters and it
  reappears in the catalogue.
* **The operator withdrew it.** The package is no longer offered. It keeps running for you
  unchanged, but its service tier can no longer be changed. To change that, pick another
  package or switch to "Own configuration" through its tile.

## How to tell the active provider

Besides the "Current" line on the **Access** page, the chat also shows a permanent, short
transparency notice: it names the provider, the package's jurisdiction classification
and the processing location. Which providers are available at all and what happens to
the data is described in the installation's privacy policy.

<div class="docs-callout docs-callout--info">
  <div class="docs-callout__title">Switching to a different search index</div>
  <p>If a package uses a different search index than your current one, the card first takes you to a summary page. It states what changes legally, how many records have to be recalculated and roughly what that costs in credits — you start the switch from there. If your organisation already has a search index, your search keeps being served from it in the meantime and moves over once the new one is complete; content created along the way only becomes findable after that. If there is none yet, search returns nothing until the rebuild finishes. If the monthly quota no longer covers it, the switch is saved and the rebuild starts next month — the summary page states which of these applies to your organisation.</p>
</div>

The summary page puts both packages side by side — with **the same badges and sentences the
card carries**: jurisdiction, training assurance and storage period, for before and after.
Below each comparison sits a sentence about what changes.

If you move to a provider that uses your content for training while the previous one
contractually excluded it, the page says so explicitly. If one of the two sides carries no
assurance, it says that too — and claims neither an improvement nor a deterioration, because
a missing statement supports neither.

Packages without an external provider (**Own server**) and your own configuration carry no
training line: there is no provider assurance to compare against. What the switch means there
is stated by the jurisdiction line.
