# How AI builds on Foundation (/docs/ai/how-ai-builds-on-foundation)



AI does not replace Foundation. It depends on Foundation to provide the secure and operational foundation on which AI application services run.

## Foundation capabilities used by AI [#foundation-capabilities-used-by-ai]

| Foundation capability    | How AI uses it                                                                |
| ------------------------ | ----------------------------------------------------------------------------- |
| Networking and exposure  | Publish the portal, APIs, MLflow, and other user-facing services              |
| Identity and access      | Authenticate users and services through Keycloak and related access controls  |
| Secrets and certificates | Protect service credentials, client secrets, and TLS configuration            |
| Inference                | Run installed models through KServe and platform-managed vLLM profiles        |
| Data and storage         | Persist operational state in PostgreSQL and objects in Rook-Ceph              |
| Workflows                | Support automation and event-driven patterns where needed                     |
| Observability            | Collect metrics, logs, and traces from AI services                            |
| GitOps and delivery      | Deploy and update AI services through Argo CD and the platform delivery chain |

## Practical boundary [#practical-boundary]

* Foundation provides the shared operational platform
* AI provides reusable AI application capabilities
* Data and business use cases consume both

## Example [#example]

When a team publishes a GenAI assistant, Foundation still handles Gateway API routes, certificates, storage, and inference operations. AI adds the portal, APIs, tenant-aware model lifecycle, vector workflows, tools, and GenAI observability that make the assistant usable.
