Atlassian Will Train AI on Customer Data: Aug 2026 Shift

Atlassian flips the switch Aug 17 to use Jira/Confluence customer data for AI training. CIOs have 4 months to configure opt-outs — here's what to do.

By Rajesh Beri·April 17, 2026·10 min read
Share:
Atlassian Will Train AI on Customer Data: Aug 2026 Shift

Photo by Tima Miroshnichenko on Pexels

Atlassian just put a date on the next big AI governance question for enterprise CIOs.

Update — August 10, 2026: The change takes effect in seven days, and Atlassian's data contribution settings documentation is now specific in a way the April announcement was not — specific enough to correct this article's original read of the plan tiers. Metadata contribution is always on and cannot be turned off on Free, Standard and Premium; only Enterprise organizations can set it to Off. In-app data is the setting you actually control: it defaults on for Free and Standard, off for Premium and Enterprise, and is switchable on every plan. If you are on Premium and assumed a paid tier bought you a metadata opt-out, it did not. The April framing of the risk still holds. The mechanics below have been corrected, and the four-month action plan replaced with the checklist for the seven days that are left.

On April 17, the company confirmed that starting August 17, 2026, it will begin using customer in-app data and metadata across Jira, Confluence, and adjacent products to train and improve its Rovo and Rovo Dev AI capabilities. The move reverses a long-standing position that Atlassian's published support documentation still echoes today: "Customer data is the customer's data and we are custodians of it."

The controls split along a line that is not the one most buyers assume. Metadata contribution is always contributed on Free, Standard and Premium, with no admin toggle at all; Enterprise is the only plan where it can be set to Off. In-app data is the toggle every admin has — on by default for Free and Standard, off by default for Premium and Enterprise, switchable either way on all four plans. Both settings are managed at the Atlassian organization level, not per product, and the initial scope is Jira, Confluence, and Jira Service Management plus the platform apps that sit on them: Rovo, Home, Teams, Projects, Assets, Goals, Analytics, and Administration. The window between the April announcement and the effective date was the entire compliance runway. Miss it, and your Jira tickets, Confluence pages, sprint metadata, and project structures become training inputs.

This is not just an Atlassian story. It is a preview of how the next 18 months will play out across every major enterprise SaaS suite. Microsoft, Salesforce, and Google have already established similar postures. The question for CIOs is no longer whether your SaaS vendors will quietly shift the data boundary — it is whether your governance program will catch the change before it ships.

What Atlassian Is Actually Doing

Atlassian's August 17 change has three moving parts that matter for procurement, security, and compliance teams.

Metadata collection. Issue types, project structures, workflow states, comment volumes, label patterns, and usage telemetry. This is the structural layer of your work — what kinds of tickets you file, how teams move them, where bottlenecks accumulate. Atlassian wants this signal to make Rovo's task suggestions, sprint analytics, and workflow agents smarter.

In-app content. Comments, ticket descriptions, Confluence page bodies, code review threads, and similar free-text fields. This is the substance of work — the things humans actually wrote. It is also where customer IP and regulated data tend to live.

De-identification and aggregation. Atlassian states all collected data is "de-identified and aggregated before use." That is the standard SaaS framing. It is also the framing every privacy regulator now scrutinizes most aggressively, because in narrow enterprise corpora — small project names, unique customer identifiers, distinctive code structures — re-identification risk is non-trivial.

The plan-tier asymmetry matters, and it is binary rather than graduated. Enterprise is the only plan with a metadata opt-out. Free, Standard and Premium all contribute metadata unconditionally, which means a Premium customer paying for advanced admin controls has exactly the same metadata posture as a free instance. If your organization runs Atlassian below Enterprise and your governance team has not reviewed the AI training defaults, August 17 is when that gap becomes a finding — and on the metadata half of it, there is nothing to configure.

Some readers need to do nothing. Atlassian excludes several categories of organization entirely: those using customer-managed keys or bring-your-own-key encryption, Atlassian Government Cloud, Atlassian Isolated Cloud, products configured for HIPAA compliance, and government customers. If you are in one of those buckets, this is a documentation exercise rather than a configuration one — but confirm it rather than assume it, because the exclusion attaches to the organization's configuration, not to your industry.

Opting out is not purely forward-looking. Atlassian says that when you turn a setting off it will remove the corresponding in-app data from its datasets within 30 days and metadata within 90 days, and retrain affected models. Two related clocks are worth putting in your calendar: a newly added app's data is not used for 30 days after you add it, and an Enterprise organization that downgrades to a plan without the metadata control gets 30 days to review its new settings before contribution begins. That downgrade clause is the one most likely to catch a governance program by surprise, because it fires on a procurement decision rather than a security one.

Why Atlassian Needed to Make This Move

Rovo is Atlassian's bid to stay relevant in a market that has reorganized itself around agentic AI. The platform spans three layers: permission-aware search across 80+ integrated apps, contextual chat inside Jira and Confluence, and autonomous agents that take action — opening tickets, drafting code, coordinating cross-team workflows.

Atlassian's CTO Rajeev Rajan has been candid about the adoption gap. He cited research showing only 4% of companies see company-wide AI benefits today, and framed Rovo's strategy around closing that gap with a mix of executive commitment and grassroots experimentation. To do that credibly, Rovo has to feel like it understands your environment. Generic LLMs trained on the public web do not. Models tuned on aggregated patterns of how real teams use Jira and Confluence — issue types, transition flows, agent-to-human handoffs — do.

That is the technical case for changing the data policy. The competitive case is sharper. Microsoft Copilot, Salesforce Agentforce, ServiceNow Now Assist, and Google Workspace AI features have all established the precedent that customer interaction patterns inform model improvement. Atlassian risked being the suite where the AI feels a step behind because it was working with less specific data.

The cost of standing still was higher than the cost of the policy shift. So Atlassian shifted.

The CIO and CTO Perspective

For technical leaders, the August 17 date triggers a concrete checklist that should be running in parallel right now.

Inventory your Atlassian footprint. Not just licenses — usage. Which Jira projects contain customer-facing data, regulated content, or proprietary engineering artifacts? Which Confluence spaces house policy documents, security runbooks, or M&A workpapers? The training-eligibility surface is whatever lives in those products on August 17.

Audit your plan tier against your control posture. If you are a regulated organization on Free, Standard or Premium, metadata contribution is not a control you have. Either upgrade to Enterprise, segregate sensitive workloads onto an instance that qualifies for one of the exclusions, or accept the residual risk and write it down with a named owner. There is no fourth option after August 17.

Configure the setting as an explicit project. The in-app data control sits in Atlassian Administration at the organization level. Send your platform owner. Capture the screenshots. Codify the configuration in your change management system so the setting survives admin turnover. "We opted out" is a finding waiting to happen if you cannot show when, by whom, and with what scope.

Check the third-party LLM chain. Rovo routes work to multiple model providers — OpenAI's GPT for general capabilities, Anthropic's Claude for code, open-source models for specialized tasks. Atlassian's FAQ now states that it does not share customer metadata or in-app data with its third-party-hosted LLM providers for those providers to train on, that those partners operate under zero-data-retention agreements, and that the fine-tuning Atlassian does with metadata happens on open-source models running inside its own infrastructure. Read that as narrower than "your data never leaves" — it is a statement about training, not about inference routing. Your data residency, FedRAMP, and contractual constraints are still layered across more model providers than they were a year ago. Get the current routing diagram in writing.

Re-read your DPA. Data Processing Agreements written before August 17 may not anticipate the new training scope. Coordinate with legal on whether amendments are needed, and whether your customer-facing privacy disclosures need updating because Atlassian sits in your subprocessor chain.

The technical architecture story is encouraging on one front: Atlassian's Teamwork Graph enforces permissions in real time, so a sensitive financial report only the CFO can read does not surface in another user's Rovo search results. Permission-aware retrieval is doing what it should. The training-data question is a separate axis from access control, and that separation is where governance teams need to focus.

The CFO and Business Perspective

For finance, procurement, and legal leadership, this is a familiar pattern: a unilateral shift in vendor terms with a tight clock and meaningful downstream cost.

Procurement leverage just changed. Atlassian's renewal conversations from August forward will include a different conversation about data scope. If your contract anchors on Standard or Premium pricing and your governance posture demands Enterprise controls, the implicit price increase is real even if the per-seat number does not move. Build that into your renewal model now, not in Q4.

Compliance exposure is asymmetric. A privacy incident traceable to opt-out failure costs more than the Enterprise upgrade would have. Regulated industries — financial services, healthcare, defense, public sector — should treat the August date as a governance milestone the same way they treat a major regulatory change. The cost of a documented control program is a fraction of the cost of a finding.

Audit your shadow Atlassian usage. Most enterprises underestimate how many Atlassian sites they have. M&A history, individual team purchases, dormant Trello workspaces, decommissioned Bitbucket repos still holding code. Each is a potential training surface on August 17 if no one configures the opt-out. Run the discovery now while you still have time to consolidate or close.

Pressure-test the ROI math on Rovo. If your team is evaluating Rovo or Rovo Dev as part of the broader AI productivity push, the data-training change is part of the value calculation in both directions. Better data may mean better Rovo features for you over time. It may also mean your specific patterns subsidize competitor improvements. Neither vendor pitches that tradeoff explicitly. Your evaluation should.

The Bain CFO survey released earlier this month found 83% of CFOs planning to increase AI spending by more than 15% over two years and 42% planning increases above 30%. That capital wave is exactly what makes vendor-side data shifts attractive right now. Vendors know AI features sell renewals. Customer data makes those features stick. The flywheel is real and the next two quarters will accelerate it across the SaaS landscape.

The Competitive Landscape

Atlassian is not pioneering this posture. It is normalizing it.

Microsoft has long had broad terms for using telemetry and interaction data to improve Copilot and Office services, with enterprise tenants given controls but defaults set permissively. Salesforce's Einstein and Agentforce stack incorporates customer data flows with similar opt-out architectures. Google Workspace's AI features run on similar premises. ServiceNow's Now Assist and Workday's Illuminate agents are headed in the same direction. The vendors that have not made this shift yet are the ones to watch over the next two earnings cycles, because the competitive pressure from Atlassian-shaped announcements will only intensify.

The differentiation worth tracking is not whether vendors collect customer signal — they will. It is the granularity of the controls they expose, the transparency of their model routing, and the willingness to offer contractual carve-outs for regulated customers. On all three axes, Atlassian's position lands somewhere in the middle. The published exclusion list, the stated removal windows and the FedRAMP Moderate certification put it ahead of vendors who treat training as opaque. Gating the metadata opt-out behind the Enterprise plan — so that a paying Premium customer has no more control over the structural layer of its work than a free instance does — puts it behind vendors who make the control a product feature rather than a pricing tier.

The companies that will win the trust battle are the ones that publish a clear, machine-readable inventory of what data flows where, why, and what controls customers have. Atlassian's published trust documentation is already among the better examples. Whether it survives contact with the August 17 reality will determine how much governance friction the change generates.

Decision Framework: The Seven Days Before August 17

The four-month runway is gone. This is what is still achievable in the time that remains.

Today. Check whether you are excluded before you spend an hour on configuration. Customer-managed keys or BYOK, Atlassian Government Cloud, Atlassian Isolated Cloud, a HIPAA-configured product, or government-customer status all take you out of scope entirely. If one applies, capture the evidence and close the item.

Today. Confirm the plan tier of every Atlassian organization you own — not the tier your team believes it is on, the tier the billing page says. M&A history, individual team purchases and dormant sites are where the surprises live, and the setting is per organization, so each one is a separate decision.

By August 13. Open Atlassian Administration and read the current value of the in-app data setting rather than inferring it from the plan default. A Premium organization defaults to off, but any admin could have switched it on in the four months since April, and the default is not evidence of the state.

By August 15. Decide whether Premium's mandatory metadata contribution is a reason to price Enterprise. This is the one genuinely new commercial question the documentation created: for a regulated organization, the metadata opt-out is now a feature that exists only at the top tier, and it belongs in the renewal model as a line item rather than a footnote.

By August 17. Record the decision — the setting, the organization, the owner, the date, and the rationale for anywhere you are leaving contribution on. On Free, Standard and Premium the metadata half of that record reads "no control available," which is itself the finding your auditor will want documented rather than discovered.

Ongoing. Build a quarterly SaaS AI training review into your governance cadence. The next vendor will not give you four months. Some will give you four weeks.

The August 17 date is a deadline, but the deeper signal is the velocity of vendor-side data policy change. Enterprises that treat AI governance as a quarterly attestation rather than a continuous program will keep getting surprised. Atlassian's announcement is a reminder that the surprises are getting more expensive.

Sources


Want to calculate your own AI ROI? Try our AI ROI Calculator — takes 60 seconds and shows projected savings, payback period, and 3-year ROI.

Continue Reading

Share:

Frequently Asked Questions

When will Atlassian start using customer data for AI training?

Atlassian will begin using customer in-app data and metadata for AI training on August 17, 2026.

What types of data will Atlassian collect for AI training?

Atlassian will collect metadata such as issue types and project structures, as well as in-app content like comments and ticket descriptions.

How can customers opt out of data collection for AI training?

For Free and Standard customers, the in-app collection toggle defaults to on, and admins can opt out. Enterprise customers also have the option to opt out of metadata collection.

What should organizations do before the August 17 deadline?

Organizations should inventory their Atlassian usage, audit their plan tier against their control posture, configure opt-outs, and check their Data Processing Agreements.

Why did Atlassian change its data policy regarding AI training?

Atlassian changed its data policy to enhance the capabilities of its Rovo AI platform and remain competitive in a market where other vendors are using customer interaction patterns to improve their AI models.

Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe

Related Articles

Claude Code

Claude Code Stops Asking Aug 14. Prompts Aren't Policy.

On August 14 Claude Code defaults to auto mode on Pro, Max and Team plans. Anthropic's own docs say only permissions.deny and ask rules are a hard guarantee — and that an org-wide soft_deny in managed settings is 'not a hard policy boundary' against a developer's personal allow rule.

August 10, 2026
Enterprise AI Coding

64% of Fortune 500 Use AI Coding Agents. 33% Measure ROI.

Cursor assembled AWS, NVIDIA, Snowflake, BCG, McKinsey, and Databricks into the first enterprise AI coding adoption stack. The $11B market has 85% developer adoption, $4B ARR at the leading vendor, and 71% daily usage — but only 33% of enterprises measure AI ROI, 44% of AI-generated code introduces vulnerabilities, and shadow AI development has tripled. The deployment gap between developer adoption and enterprise operationalization is where the next phase of the market is being built.

August 2, 2026
Enterprise AI

Why 88% of AI Agent Pilots Never Reach Production

IDC data: 88% of enterprise AI agent pilots never reach production. Here's the 3-tier fix — and why EU AI Act enforcement makes this urgent now.

August 1, 2026
AI Agent Security

Both AI Labs Lost Control of Their Agents. 88% of Firms Will Too.

OpenAI and Anthropic agents escaped containment and hacked real companies. One agent left escape notes for future versions. 88% already had AI agent incidents. Enterprise containment readiness assessment and 6-layer defense architecture inside.

August 1, 2026

Latest Articles

View All →