Atlassian will train on your data: Opt out with GitLab (opens in new tab)
Atlassian plans to use customer metadata and in-app content from Jira, Confluence, and other cloud products to train AI services beginning August 17, 2026. Collection will be enabled by default, with mandatory metadata collection for Free, Standard, and Premium customers; only Enterprise customers can opt out. The post argues this weakens data governance, particularly for regulated organizations, while presenting GitLab’s no-collection, no-training approach as a stronger privacy model.
What Atlassian’s Policy Change Covers
- Atlassian will collect:
- Metadata such as story points, sprint dates, SLA values, and signals from Teamwork Graph and connected apps.
- In-app content including Confluence pages, Jira issue titles, descriptions, and comments.
- Atlassian says data will be de-identified and aggregated before training.
- Data may be retained for up to seven years.
- After opting out, in-app data is reportedly removed within 30 days and models retrained within 90 days.
- Customers using customer-managed encryption keys, Government Cloud, Isolated Cloud, or HIPAA-related configurations are excluded.
- The change reverses Atlassian’s previous position that customer data would not be used to train or improve AI services.
Problems with Opt-Out-by-Default Governance
- Customers must notice the policy change, assess its legal and security impact, and act within the available timeframe.
- Free, Standard, and Premium customers cannot disable metadata collection.
- Enterprise is the only opt-out route, requiring at least 801 users and custom pricing.
- “De-identified” metadata can still reveal team performance, project structure, delivery cadence, and competitive operational intelligence.
- The policy turns data protection into a purchasing decision rather than a default customer right.
Why Atlassian Customers Face Greater Exposure
- Jira and Confluence often contain:
- Project plans and sprint data
- Security tickets and incident postmortems
- Internal documentation
- Bug, release, and portfolio management information
- Organizations using Bitbucket and Bamboo may also expose source-code metadata and CI/CD configuration signals.
- Teamwork Graph connectors can extend the data scope to tools such as Slack, Figma, Google Drive, Salesforce, and ServiceNow.
- Customers migrating from Data Center or Server editions to Atlassian Cloud must now evaluate not only cloud migration, but also the possibility of default AI training.
Compliance and Regulatory Implications
- Financial institutions may need to reassess vendor controls under frameworks such as SR 11-7 and DORA.
- Public-sector organizations must consider NIST 800-53 and FISMA requirements around sensitive-data flows.
- Healthcare organizations need to evaluate potential HIPAA implications.
- EU AI Act obligations may create additional concerns because European expectations often favor opt-in consent.
- Existing vendor-risk, model-risk, and data-processing assessments should be updated before August 17, 2026.
GitLab’s Contrasting Approach
- GitLab is presented as opposing opt-out-by-default collection.
- Its stated principles are:
- No collection of customer data
- No AI training on customer data
- The same privacy commitment regardless of subscription tier
- This approach avoids making stronger data protection dependent on Enterprise pricing and simplifies compliance reviews.
Organizations should inventory the data and integrations connected to Atlassian, review contractual and regulatory obligations, and determine whether they can opt out or need to reconsider their platform strategy.