Where Your AI Policy Stops Being True

A policy sentence about third-party AI training states an intention. Whether it is accurate may depend on documents the policy author did not write.

Most AI policies contain a version of this sentence. Company data will not be used to train or improve a third party's AI system without review and approval.

Whether that holds may depend on documents the company did not write. The policy itself is internal, and it can be rewritten in an afternoon. The vendor's contract is binding, and it can change without anyone at the company signing anything. Underneath the contract, there is usually a configuration screen, which can define terms the contract leaves undefined, and which arrives with its answers already set.

Atlassian's data contribution change, effective August 17, 2026, moved the contract and the settings. The customer's own policy stayed where it was.

The contract changed without a signature

The Customer Agreement, the AI Terms, the Data Processing Addendum (DPA), and the Privacy Policy all took effect that day.

None of them required a countersignature. The Customer Agreement is accepted by clicking a button when placing an order, or by using the products. The DPA applies automatically once the agreement is accepted.

Atlassian can modify the agreement by posting the changed portions on its website, with commercially reasonable efforts to post them thirty days ahead of the effective date. For a paid subscription, those changes normally wait for the next renewal. They can take effect mid-term when they reflect new product functionality, which appears to be what happened here. A customer that objects has thirty days from the notice to terminate the affected products and take a refund on the unused portion, and the agreement names that as the only remedy.

Notice goes to the billing or technical contact on file. Atlassian can also give notice by email, on its website, or inside the products.

The right to object ran for thirty days. Using it would have meant reading a vendor notice, recognizing it as a contract change rather than a product announcement, and knowing what the company's own AI policy promised. Contract review is usually triggered by an upcoming purchase. Nothing was being purchased here.

Metadata is not defined in the contract

Atlassian now uses customer metadata and in-app data to improve its apps and AI features for every customer. Before this change, it used them to improve one organization's own experience.

In-app data is what users write: Confluence page bodies, Jira work item descriptions, comments.

Metadata is the characteristics of that content. Content attributes are counts, statistical measures, and derivatives, such as the story points on a work item. Common patterns are phrases, keywords, and topics that appear frequently across many customers, pulled from search queries and their results, from custom configuration data, and from Rovo Chat conversations, prompts, and responses. Rovo is Atlassian's AI assistant, built into Jira and Confluence. Atlassian's examples are "vacation policy" and "recap team activity." Rare data that could be unique to one organization is omitted, and names and email addresses are stripped before use.

Metadata can therefore include material derived from what employees typed.

None of those agreements sets out what metadata means. The DPA authorizes Atlassian to de-identify and aggregate customer data and to use the result to improve its products generally, "in accordance with applicable data contribution Cloud Product functionalities." The contract points at the settings, and the settings are defined in support pages and in a Trust Center FAQ.

Your settings may be your data policy

The DPA states that the agreement, the orders, and the customer's use of the products, including its configurations and settings, together make up the customer's documented instructions for how Atlassian processes its data.

A default that no one selected can therefore stand as an instruction the company gave.

The Customer Agreement requires the customer to have obtained every disclosure, right, and consent needed for Atlassian to use the data as specified, and makes the customer responsible for deciding whether the products suit its regulatory obligations. The DPA puts the customer on the hook for ensuring its instructions comply with data protection law.

The metadata opt-out is Enterprise only

Any customer can turn off in-app data contribution, on any plan. Metadata is different. Free, Standard, and Premium have no opt-out. Only an organization with an active Enterprise plan can switch it off.

Defaults follow the highest active plan in each Atlassian cloud organization, trials included.

Data contribution defaults by highest active plan
Highest active plan Metadata In-app data
FreeOnOn
StandardOnOn
PremiumOnOff
EnterpriseOnOff

Source: Atlassian data contribution FAQs, read August 30, 2026


Which control is available appears to be set by the plan. A company on Premium can protect the pages and tickets its people wrote, and cannot decline what is drawn from what they typed into search and chat.

The table may understate the reach. A trial counts toward the highest active plan, so a trial can set the default for a whole organization. Settings are held per Atlassian cloud organization and determined independently, so a company running several would manage several. Activating or deactivating AI is a setting separate from data contribution, so switching Rovo off does not change what is contributed.

Exclusion turns on a compliance configuration rather than on the kind of business. Atlassian excludes organizations using customer-managed encryption keys, Atlassian Government Cloud, or Atlassian Isolated Cloud, organizations with HIPAA compliance configured, and government customers. Everyone else is in. A manufacturer, a consultancy, a bank, a retailer, or a healthcare company that has not configured HIPAA compliance is included on the ordinary defaults, and so are educational institutions, including government-run ones, on the same highest-active-plan rule.

What a policy needs behind it

An AI policy may be only a statement of intent until every vendor contract behind it carries the same terms. Ownership is what connects the policy, the contract, and the setting, which is the subject of Chapter 4 of The Governed Enterprise.

For any vendor that holds the company's work, it is worth knowing where a notice of changed terms lands and who acts on it. It is also worth knowing which promises in the AI policy are carried by a contract, and which rest on a settings page.


Sources

Every source below is published by Atlassian. All were read on August 30, 2026.

Contract documents, effective August 17, 2026

Atlassian Customer Agreement. Acceptance by use, Section 4.1 on customer data, Section 4.6 on AI offerings, Sections 6.1 and 6.2 on customer obligations, Section 20.5 on notices, Section 20.9 on changes to the agreement, and Section 21 on definitions. https://www.atlassian.com/legal/atlassian-customer-agreement

Atlassian Data Processing Addendum. Section 2.1 on documented instructions, and Schedule 1, Section 6.2 on de-identified and aggregated data. https://www.atlassian.com/legal/data-processing-addendum

Atlassian AI Terms. Section 5 on definitions. https://www.atlassian.com/legal/ai-terms

Atlassian Privacy Policy. https://www.atlassian.com/legal/privacy-policy

Vendor documentation

"Data practices built for responsible AI." Effective date and default settings. https://www.atlassian.com/trust/ai/data-contribution

"Data contribution FAQs." Definitions of metadata and in-app data, defaults by plan, opt-out availability, the highest-active-plan rule and its treatment of trials, per-organization scope, AI activation as a separate setting, compliance exclusions, educational institutions, and the list of updated legal documents. https://www.atlassian.com/trust/ai/data-contribution/faqs

"What types of data does my organization contribute?" https://support.atlassian.com/security-and-access-policies/docs/what-types-of-data-does-my-organization-contribute/

"Data contribution settings." https://support.atlassian.com/security-and-access-policies/docs/data-contribution-settings/