Where Your AI Policy Stops Being True
A policy sentence about third-party AI training states an intention. Whether it is accurate may depend on documents the policy author did not write.
Most AI policies contain a version of this sentence. Company data will not be used to train or improve a third party's AI system without review and approval.
Whether that holds may depend on documents the company did not write. The policy itself is internal, and it can be rewritten in an afternoon. The vendor's contract is binding, and it can change without anyone at the company signing anything. Underneath the contract, there is usually a configuration screen, which can define terms the contract leaves undefined, and which arrives with its answers already set.
Atlassian's data contribution change, effective August 17, 2026, moved the contract and the settings. The customer's own policy stayed where it was.
The contract changed without a signature
The Customer Agreement, the AI Terms, the Data Processing Addendum (DPA), and the Privacy Policy all took effect that day.
None of them required a countersignature. The Customer Agreement is accepted by clicking a button when placing an order, or by using the products. The DPA applies automatically once the agreement is accepted.
Atlassian can modify the agreement by posting the changed portions on its website, with commercially reasonable efforts to post them thirty days ahead of the effective date. For a paid subscription, those changes normally wait for the next renewal. They can take effect mid-term when they reflect new product functionality, which appears to be what happened here. A customer that objects has thirty days from the notice to terminate the affected products and take a refund on the unused portion, and the agreement names that as the only remedy.
Notice goes to the billing or technical contact on file. Atlassian can also give notice by email, on its website, or inside the products.
The right to object ran for thirty days. Using it would have meant reading a vendor notice, recognizing it as a contract change rather than a product announcement, and knowing what the company's own AI policy promised. Contract review is usually triggered by an upcoming purchase. Nothing was being purchased here.
Metadata is not defined in the contract
Atlassian now uses customer metadata and in-app data to improve its apps and AI features for every customer. Before this change, it used them to improve one organization's own experience.
In-app data is what users write: Confluence page bodies, Jira work item descriptions, comments.
Metadata is the characteristics of that content. Content attributes are counts, statistical measures, and derivatives, such as the story points on a work item. Common patterns are phrases, keywords, and topics that appear frequently across many customers, pulled from search queries and their results, from custom configuration data, and from Rovo Chat conversations, prompts, and responses. Rovo is Atlassian's AI assistant, built into Jira and Confluence. Atlassian's examples are "vacation policy" and "recap team activity." Rare data that could be unique to one organization is omitted, and names and email addresses are stripped before use.
Metadata can therefore include material derived from what employees typed.
None of those agreements sets out what metadata means. The DPA authorizes Atlassian to de-identify and aggregate customer data and to use the result to improve its products generally, "in accordance with applicable data contribution Cloud Product functionalities." The contract points at the settings, and the settings are defined in support pages and in a Trust Center FAQ.
Your settings may be your data policy
The DPA states that the agreement, the orders, and the customer's use of the products, including its configurations and settings, together make up the customer's documented instructions for how Atlassian processes its data.
A default that no one selected can therefore stand as an instruction the company gave.
The Customer Agreement requires the customer to have obtained every disclosure, right, and consent needed for Atlassian to use the data as specified, and makes the customer responsible for deciding whether the products suit its regulatory obligations. The DPA puts the customer on the hook for ensuring its instructions comply with data protection law.
The metadata opt-out is Enterprise only
Any customer can turn off in-app data contribution, on any plan. Metadata is different. Free, Standard, and Premium have no opt-out. Only an organization with an active Enterprise plan can switch it off.
Defaults follow the highest active plan in each Atlassian cloud organization, trials included.
| Highest active plan | Metadata | In-app data |
|---|---|---|
| Free | On | On |
| Standard | On | On |
| Premium | On | Off |
| Enterprise | On | Off |
Source: Atlassian data contribution FAQs, read August 30, 2026
Which control is available appears to be set by the plan. A company on Premium can protect the pages and tickets its people wrote, and cannot decline what is drawn from what they typed into search and chat.
The table may understate the reach. A trial counts toward the highest active plan, so a trial can set the default for a whole organization. Settings are held per Atlassian cloud organization and determined independently, so a company running several would manage several. Activating or deactivating AI is a setting separate from data contribution, so switching Rovo off does not change what is contributed.
Exclusion turns on a compliance configuration rather than on the kind of business. Atlassian excludes organizations using customer-managed encryption keys, Atlassian Government Cloud, or Atlassian Isolated Cloud, organizations with HIPAA compliance configured, and government customers. Everyone else is in. A manufacturer, a consultancy, a bank, a retailer, or a healthcare company that has not configured HIPAA compliance is included on the ordinary defaults, and so are educational institutions, including government-run ones, on the same highest-active-plan rule.
What a policy needs behind it
An AI policy may be only a statement of intent until every vendor contract behind it carries the same terms. Ownership is what connects the policy, the contract, and the setting, which is the subject of Chapter 4 of The Governed Enterprise.
For any vendor that holds the company's work, it is worth knowing where a notice of changed terms lands and who acts on it. It is also worth knowing which promises in the AI policy are carried by a contract, and which rest on a settings page.
Sources
Every source below is published by Atlassian. All were read on August 30, 2026.
Contract documents, effective August 17, 2026
Atlassian Customer Agreement. Acceptance by use, Section 4.1 on customer data, Section 4.6 on AI offerings, Sections 6.1 and 6.2 on customer obligations, Section 20.5 on notices, Section 20.9 on changes to the agreement, and Section 21 on definitions. https://www.atlassian.com/legal/atlassian-customer-agreement
Atlassian Data Processing Addendum. Section 2.1 on documented instructions, and Schedule 1, Section 6.2 on de-identified and aggregated data. https://www.atlassian.com/legal/data-processing-addendum
Atlassian AI Terms. Section 5 on definitions. https://www.atlassian.com/legal/ai-terms
Atlassian Privacy Policy. https://www.atlassian.com/legal/privacy-policy
Vendor documentation
"Data practices built for responsible AI." Effective date and default settings. https://www.atlassian.com/trust/ai/data-contribution
"Data contribution FAQs." Definitions of metadata and in-app data, defaults by plan, opt-out availability, the highest-active-plan rule and its treatment of trials, per-organization scope, AI activation as a separate setting, compliance exclusions, educational institutions, and the list of updated legal documents. https://www.atlassian.com/trust/ai/data-contribution/faqs
"What types of data does my organization contribute?" https://support.atlassian.com/security-and-access-policies/docs/what-types-of-data-does-my-organization-contribute/
"Data contribution settings." https://support.atlassian.com/security-and-access-policies/docs/data-contribution-settings/