Atlassian is about to train its AI on your Jira and Confluence data. Here is what to change before 17 August.
Most conversations about AI data leakage start with the obvious culprit: someone on the team pasting a client list or a contract into a free chatbot. That is real. But some of the largest exposures now come from a quieter direction, tools you have already approved, already pay for, and already trust, quietly changing what they do with your data. Atlassian has just given the clearest example yet.
What is changing
From 17 August 2026, Atlassian will begin using customer data from its cloud products, Jira, Confluence, Jira Service Management and others, to train its own AI features, including Rovo and Rovo Dev. The change is switched on by default and reaches roughly 300,000 organisations. It reverses Atlassian’s earlier position that customer data would not be used to train its AI, and it arrives alongside an updated customer agreement that takes effect the same day.
Two kinds of data, two very different rules
Atlassian splits the data into two buckets, and the opt-out you get depends on which plan you pay for.
In-app data is the content your team actually writes: Jira issue titles, descriptions and comments; Confluence page titles and bodies; custom status, workflow and emoji names. This is the sensitive category, and the good news is that an administrator on any tier can switch it off. On Free and Standard it is on by default; on Premium and Enterprise it is off by default.
Metadata is the layer Atlassian describes as de-identified and aggregated: story points, task classifications, sprint dates, service-level values, readability and similarity scores. Here the deal is harder. Free, Standard and Premium customers cannot opt out of metadata collection at all, only Enterprise can. Atlassian’s argument is that aggregated metadata sits outside the data you “own”. Reasonable people will disagree, and it is worth knowing that is the position being taken.
Whatever you choose, the collection is not instantly reversible. Atlassian says it will retain contributed data for up to seven years. Opting out stops future collection and removes in-app data within about 30 days, with affected models retrained within 90 days, but it does not unwind data that has already been absorbed into a trained model.
Why this is an AI leakage problem, not a privacy footnote
This is exactly the pattern AI Leakage exists to track. Shadow AI, staff using tools nobody signed off on, is only half the risk. The other half is approved tools becoming a leakage channel when the vendor rewrites the terms underneath you. Nobody at your company decided to feed sprint boards, incident postmortems and internal documentation into a training pipeline. The default did it for you, and the burden to notice and act inside a fixed window falls on you.
The reach is wider than Jira and Confluence, too. Through Atlassian’s Teamwork Graph connectors, signals from linked tools such as Slack, Google Drive and Salesforce can be drawn in, so the data in scope is not limited to what lives inside Atlassian’s own products.
If you operate in New Zealand or Australia, there is a compliance edge. Under the New Zealand Privacy Act 2020 and the Australian Privacy Principles, you remain accountable for personal information held in those tickets and pages even once it has been repurposed for training. For regulated data, that is a conversation to have with your privacy officer before 17 August, not after.
What to do before 17 August
The settings are already live, so there is no need to wait.
- Open Atlassian Administration → Security → Data contribution.
- Turn off in-app data contribution. Every tier can do this, and it covers the content that matters most.
- If you are on Enterprise, also opt out of metadata collection.
- Check whether you are automatically excluded. Accounts with HIPAA requirements, customer-managed encryption keys (BYOK), Atlassian Government Cloud and Atlassian Isolated Cloud are carved out, as are some government and financial-services customers.
- If the toggle has not appeared in your admin panel yet, you are currently sitting in the default state, keep checking, because enforcement does not wait for you.
The bigger pattern
Atlassian is not an outlier. GitHub changed its Copilot data terms earlier in 2026, and “on by default, opt out if you happen to notice” is becoming the industry norm. The practical lesson for a small business is uncomfortable but simple: the tools you approved last year are not frozen in time, and “we don’t really use AI” is almost never true once you look. Keeping a current picture of which tools you use, on which tier, under which data terms, is now part of running a business, not an IT side project.
This is precisely the kind of change our free AI Tool Risk Directory tracks, and the kind of thing our alerts exist to flag: plain-English warnings when a tool you rely on changes its data policy. If that would save you from finding out too late, you can subscribe here.
How this was written: drafted with AI and reviewed by a person before publishing. The factual claims here are drawn from Atlassian’s own data-contribution documentation and contemporaneous reporting dated April-May 2026. Tool terms change, if you are reading this after 17 August 2026, check the current settings directly.
