If your company runs Jira and Confluence Cloud with Rovo switched on, your tickets and pages already go to OpenAI and other model providers. Atlassian's expanded OpenAI deal adds more OpenAI models to that path without giving you a way to choose between providers. The one setting that keeps that data inside Atlassian's own infrastructure is the Atlassian-hosted-LLM option, which Atlassian offers only to Cloud Enterprise organizations, and only on request. Everyone else gets the router's choice.
OpenAI and Atlassian announced the expanded partnership on October 6, bringing GPT-6 family models into Rovo, the AI agent Atlassian sells alongside Jira, Confluence and Loom. According to AI Weekly's summary of VentureBeat's reporting, the deal covers GPT-6 Astra and the GPT-5.6 series, and an OpenAI representative called it "effectively a spend commitment," with Atlassian paying OpenAI. Neither company disclosed a dollar figure.
That matters to you for three practical reasons: where your data goes, what the new models cost in Rovo credits once overage billing starts on December 3, and whether your last AI vendor review still describes what Rovo actually does.
Who Decides Which Model Reads Your Jira Tickets?
Atlassian decides, per request, unless you are on Cloud Enterprise and have asked to opt out. Atlassian's trust page says Rovo's features "use dynamic routing to select the appropriate mix of models" for each scenario, drawn from open models it hosts (including the Gemma series) and third-party hosted LLMs from OpenAI's GPT series, Anthropic's Claude series and Google's Gemini series. It also states that by default, "data is transferred outside of the current site to third party LLM providers (e.g., OpenAI)."
Google is in the mix too. When Atlassian expanded its Google Cloud partnership in April, it said Gemini 3 Flash "will power certain Rovo capabilities" as part of "an open, multi-model and multi-cloud strategy." The new OpenAI models join the same router. AI Weekly reports that Rovo's internal gateway routes dynamically across OpenAI and other providers and that GPT-6 Astra is not the default.
The trust page describes no per-provider setting. The choice Atlassian offers is binary: "Eligible customers can elect to use only Atlassian-hosted LLMs," and that is "available by request for Cloud Enterprise organizations." Those customers trade some quality for it: Atlassian warns of "slight variations in performance and latency" because Rovo then relies solely on models inside the Atlassian Cloud boundary.
The strongest case for Atlassian's design is reasonable. A router that can move between OpenAI, Claude and Gemini protects you from one provider's outage, price change or model deprecation, and the AI Weekly editors argue that keeping the router in house makes sense while model leadership keeps shifting. The cost is that your data map changes whenever Atlassian's routing table does, and you find out from a sub-processor page rather than a setting.
There is one place where a person does pick a model. On a custom Rovo agent set to the "Think deeper" reasoning tier, the builder can choose a model, and Atlassian says the options "may change over time." That is a per-agent quality and cost choice made by whoever builds the agent, and it leaves the routing of every other Rovo request untouched.
Does Data Residency Keep Rovo Processing in Region?
The trust page commits to storage, not processing. With data residency on, "all of your in-scope app data will remain stored in the region you've selected," according to Atlassian. The page does not say the model calls stay in that region.
Atlassian's sub-processor list is more specific, and it is the document your privacy team should be reading this week. It lists three generative AI providers for "All Atlassian Cloud Products with enabled Atlassian Intelligence or Rovo":
| Sub-processor | Listed purpose | Listed locations |
|---|---|---|
| OpenAI, L.L.C. | Generative AI services provider for intelligence product features | USA |
| Google Vertex AI | Generative AI services provider for intelligence product features | USA, EEA (Belgium, Netherlands, Finland), Singapore, Taiwan |
| AWS Bedrock | Generative AI services provider for intelligence product features | USA, EEA (Germany, Sweden, Italy, Spain, Ireland, France), South Africa, Japan, and others |
OpenAI's only listed location is the USA. If you pinned your Jira site to the EU, any Rovo request the router sends to an OpenAI model is processed at a provider whose listed location is the United States. Anthropic does not appear on the list as its own entry, even though the trust page names Claude models; the list does not say which host serves them, so ask.
The protections Atlassian does commit to are real. The trust page says none of its LLM providers store submitted data or responses, that they operate under "strict zero data retention (ZDR) agreements," and that your Rovo data is not shared with third-party providers to train their models. For many companies that is enough. For a regulated team whose DPA promises EU processing, it is not, and we covered the wider pattern in our LLM data residency guide.
What Will GPT-6 Astra Cost You in Rovo Credits?
Atlassian has not published a credit rate for Astra, and from December 3 heavier model use starts costing money. Atlassian's Rovo credits page says extra usage billing takes effect on December 3, 2026, is enabled by default, and lists at $0.01 per credit ($10 per 1,000).
The included allowance is modest. Jira and Confluence each grant 25 credits per user per month on Standard, 70 on Premium and 150 on Enterprise; the Teamwork and Service Collections grant 250, 700 and 1,500. Credits pool across the organization and do not roll over. Basic intelligence features cost 10 credits per billable event, premium features cost a variable amount, and for Think deeper Atlassian names "the specific models applied at each stage of the reasoning process" as a factor in what you burn.
Astra is the expensive end of OpenAI's lineup. VentureBeat lists it at $10 per million input tokens and $50 per million output, and we found OpenAI's own Ultrafast tier bills Astra at 6x. Inside Rovo, the agent settings show a model multiplier that Atlassian calls "indicative and intended as comparative guidance rather than exact figures." An autonomous agent pinned to the priciest model on a busy Jira project is exactly the case Atlassian's own page warns "can quickly consume credits."
The controls exist, and you have to turn them on. Admins can see usage under Insights, then Platform usage, then Rovo credits; export up to three months of events as CSV; disable extra usage; and set spending limits. Atlassian says per-user credit allocation is "coming soon." Until then one team's agent can drain the shared pool for everyone.
Is Astra Safe to Switch On for Agents?
Astra is off until an administrator enables it, per AI Weekly, which gives you a decision point most model launches skip. The same report notes Astra is OpenAI's first model to reach the "Critical" cybersecurity threshold under its Preparedness Framework, and that its safety checks can "slow, pause, or stop legitimate work," including defensive security tasks.
That second point bites inside Jira. A security team that tracks vulnerability work in Jira and asks a Rovo agent to summarise exploit details may hit those checks. We also reported that OpenAI pulled GPT-6.1 Astra over a scope-control flaw that GPT-6 Astra still has. An agent that acts across 220-plus tools is where scope control matters most.
AI Weekly reports Atlassian's rebuilt MCP server exposes 220-plus tools across Jira, Confluence, Bitbucket, Loom and Goals and handles 15 million calls a day, with Atlassian claiming up to 25% fewer tokens on comparable work. When the server reached general availability in February, Atlassian said admins can decide which MCP-compatible clients may connect, with usage logs for audit. If ChatGPT or Codex is on your approved list, the partnership makes that path easier to use, and the client allowlist is where you govern it. Our MCP governance guide covers enforcing that at the client.
Channel Insider notes Atlassian says agents act within each user's access and permission settings, and that autonomous work-item pickup and multi-agent orchestration are still in design. One analysis of the announcement points out it includes no new API pricing or contractual terms. Crypto Briefing's warning applies to every connector here: "Seamless data sharing is a feature right up until it shares something it should not."
What Should Atlassian Admins Do Before December 3?
This Week:
- Pull Atlassian's sub-processor list and put it next to your last AI vendor review. If the review predates the OpenAI, Vertex AI and Bedrock entries, or assumed in-region processing, reopen it. Our six questions for an AI vendor security review are a usable template.
- If you are on Cloud Enterprise and your DPA promises in-region processing or no third-party model access, file the request for Atlassian-hosted LLMs now, and test Rovo answer quality on your own Confluence content before you commit. That option keeps data inside Atlassian's cloud boundary, but Atlassian's setup page says the hosted models run "across multiple global regions," so get in-region processing confirmed in writing.
- Open Insights, then Platform usage, then Rovo credits, and export the CSV. Find which agents and teams drive usage today.
Before December 3:
- Decide whether extra usage stays on. If it does, set a spending limit; it is enabled by default.
- Leave Astra off until a named owner approves it for named agents. Ask your Atlassian account team in writing for Astra's credit multiplier against the Think deeper default.
- Audit every custom agent set to Think deeper and note its model. Atlassian promises at least 30 days' notice before a deprecated model is swapped for the nearest equivalent, so assign someone to watch for it.
Before Renewal:
- Ask Atlassian to contract for notice when a new LLM sub-processor is added to Rovo routing, and for a per-provider setting below the all-or-nothing hosted option.
- Price the Teamwork Collection's larger allowance against what overage would cost you at $0.01 per credit, using your December numbers.
The Bottom Line
Atlassian now buys frontier model access, routes across providers and meters the result in credits. We saw the same split in Microsoft's Copilot billing, where the seat stays flat and agent work bills separately. The router protects Atlassian's margin and your uptime. It also means that the list of companies processing your tickets is set by Atlassian, and your control over it is a support request that only Cloud Enterprise customers can file.
If you are not on Enterprise, your levers are the credit cap, the Astra switch and the MCP client allowlist. Set all three before December 3.
Continue Reading
- LLM Data Residency: Which Providers Actually Keep Data In Region
- OpenAI's Ultrafast Bills Astra at 6x and Skips EU Residency
- OpenAI Pulled GPT-6.1 Astra Over a Flaw GPT-6 Astra Still Has
- Model Router Buyer's Guide: Buy Failover, Not Judgment
- MCP Server Governance: Enforce at the Client, Not the Registry
- AI Vendor Security Review: 6 Questions That Change the Answer
