The prominent software conglomerate Atlassian has recently revised its data contribution policy, announcing that effective August 17, 2026, it will utilize customer metadata and application content from Jira, Confluence, and its peripheral cloud offerings to train its artificial intelligence models.
This policy shift is anticipated to impact approximately 300,000 clients. Atlassian is implementing a stratified approach to data governance: users on lower-tier subscriptions—specifically Free, Standard, and Premium—are precluded from opting out of certain data contribution programs. Conversely, Enterprise clientele retain the prerogative to manually withdraw, thereby ensuring their proprietary data remains excluded from the training corpora.
Atlassian delineates its data into distinct classifications. Metadata encompasses de-identified signals, including readability and complexity metrics, task taxonomies, semantic similarity indices, iteration completion timestamps, and Jira SLA values. These datasets are processed to minimize the presence of sensitive information.
In contrast, In-App Data comprises user-generated substance, such as Confluence page titles and body text, Jira issue headers, descriptions, commentaries, and bespoke nomenclature for emojis, statuses, and workflows.
The corporation asserts that prior to model ingestion, data will undergo de-identification, aggregation—a process of blending datasets to mitigate re-identification risks—and the application of robust protective measures. However, Atlassian intends to retain this harvested intelligence for a duration of up to seven years, a timeframe that has raised concerns regarding latent security vulnerabilities.
The governance of data contribution varies significantly across subscription tiers:
- Free and Standard Tiers: Metadata contribution is mandatory and active by default. In-app data contribution is enabled by default but may be manually deactivated through configuration.
- Premium Tier: Metadata contribution is enabled by default but offers an opt-out mechanism. In-app data contribution is disabled by default.
- Enterprise Tier: Both metadata and in-app data contributions are disabled by default.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.