What Atlassian is changing on August 17
Atlassian has told customers that beginning August 17, 2026, it will start collecting data from Jira, Confluence, and other cloud products to train its AI offerings, including the Rovo assistant and the Rovo Dev coding agent. The collection falls into two buckets. The first is metadata, described as de-identified operational signals such as story points, sprint dates, and SLA values. The second is in-app content, meaning the user-generated material inside those products: Confluence pages, along with Jira titles, descriptions, and comments. This is the substance of how teams plan and document their work, not a peripheral telemetry stream.
The reach is the part that makes this more than a routine terms update. The policy applies across Atlassian's cloud base, which the company serves at a scale of roughly 300,000 organizations. For a product that sits at the center of how engineering, product, and operations teams coordinate, a change to how that content is used propagates into a large share of the enterprise software market at once. What would normally be a legal-team footnote becomes a decision that data-governance owners and CIOs have to actively make before the deadline, because the default is participation.
The tier structure turns opt-out into a line item
The mechanics of the opt-out are what have drawn attention. Collection is mandatory on the Free, Standard, and Premium tiers, and only Enterprise customers can decline. In practice that means the ability to keep your own project content out of Atlassian's training pipeline is gated behind the most expensive subscription level. For a mid-market company on Premium, the choice is to accept the collection or to negotiate an upgrade whose primary new benefit, in this framing, is data control rather than additional features. That reframes a data-governance preference as a budget conversation.
This structure is likely to sit uneasily with buyers who assumed their private planning data was off-limits by default. GitLab captured the reframed question in its own commentary: "The question is no longer just 'do we move to Atlassian Cloud?' but 'do we move to Atlassian Cloud knowing our data will feed AI training unless we're on the most expensive tier?'" Whether or not one accepts a competitor's framing, the underlying point stands. The cost of keeping content out of training is now an explicit part of the total cost of ownership for teams below the Enterprise tier.
What data actually leaves your walls
The distinction between metadata and content deserves a close read. The metadata category is described as de-identified and operational, the kind of signal that reveals how teams work in aggregate without exposing specific text. The content category is different in kind. Confluence pages routinely hold architecture decisions, incident write-ups, security runbooks, and roadmap detail. Jira descriptions and comments capture the reasoning behind changes, references to systems and customers, and sometimes sensitive specifics that were never meant to leave the team. Feeding that material into model training raises questions that de-identification does not fully answer.
The concern extends well past any single leaked field to the aggregate itself. Even where individual entries are innocuous, the corpus of an organization's planning and documentation carries competitively meaningful structure: how it builds, what it prioritizes, where it struggles. Once that shapes a shared model, the boundary between one company's operating knowledge and a vendor's product becomes harder to draw. Leaders evaluating the change should look past the reassuring metadata language and reckon with the content category specifically, because that is where the genuinely sensitive material lives and where the governance exposure is real.
The competitive wedge GitLab is driving
GitLab has moved quickly to make Atlassian's policy a selling point, stating that it does not train on customer data at any tier, full stop, and that its own AI vendor contracts prohibit using customer inputs for the vendors' own purposes. The message is aimed straight at the buyers most exposed by the tier structure: teams that want AI features without surrendering their content, and who would otherwise have to buy up to Enterprise to keep control. By making the commitment unconditional across all subscription levels, GitLab is trying to convert a rival's monetization choice into a reason to switch platforms.
For engineering leaders, the competitive noise is less important than the principle it exposes. Data-use terms are becoming a first-class differentiator among developer platforms, on par with features and price. As every vendor races to train assistants and coding agents, the ones willing to commit contractually to not using customer data are carving out a distinct position, and the ones monetizing that data are betting customers will accept it for better AI. That divergence gives buyers real leverage, and it makes the fine print on data use something to negotiate deliberately rather than accept as boilerplate.
The questions CIOs should be asking now
The immediate task is scoping exposure. Data-governance owners need to know which Atlassian tier each business unit runs, what sensitive content sits in the affected Confluence spaces and Jira projects, and whether any of it falls under contractual or regulatory confidentiality obligations that the training collection would breach. That inventory is rarely centralized, so the work involves surveying teams that adopted Atlassian independently over the years. For regulated industries and for teams handling customer or partner data under NDAs, the default-on collection could conflict with commitments already made elsewhere, which turns a settings review into a compliance review with a hard date attached.
There is also a precedent worth weighing. Atlassian is a large, widely deployed vendor, and its move normalizes default-on training collection for a whole category of collaboration tools. If it holds without significant customer pushback, other vendors are likely to follow the same tiered playbook, since monetizing accumulated customer content is an obvious way to fund the AI features every platform now feels pressure to ship. Leaders should treat this as a signal to audit data-use terms across their entire SaaS estate, not just Atlassian, because the assumption that private workspace content stays out of vendor training is quietly eroding across the market.
What to do before the deadline
With August 17 fixed, the practical steps are concrete. Enterprise customers should confirm the opt-out is actually enabled rather than assume it, since the control exists but is not automatic. Teams below Enterprise face a genuine decision: accept the collection, upgrade for the opt-out, or begin moving the most sensitive content out of Atlassian ahead of the change. Each option carries a cost, and the right answer depends on how much confidential material lives in those systems and how the training collection interacts with existing data commitments. The one option that is not really available is inaction, because the default is participation.
The broader lesson for the roadmap is that AI data-use terms now belong in every procurement and renewal conversation for developer and collaboration tooling. What a vendor may do with your content is as material as uptime or price, and it deserves the same scrutiny. Leaders who build data-use review into their vendor process will avoid being surprised by the next default-on policy, and they will have a clearer basis for choosing platforms as the market splits between vendors that monetize customer data and vendors that contractually refuse to.



