8 ms·
Atlassian enables default data collection to train AI
- titzer 5mo agoAI contributing to rising natural stupidity.
- kevcampb 5mo agoI really wish I could find a better source to link to for this. By default, all free and paid customers are being opted-in to their data being used for AI training. All your Confluence pages, Jira tickets, etc. https://support.atlassian.com/security-and-access-policies/docs/data-contribution-settings/ https://support.atlassian.com/security-and-access-policies/d... describes how to disable this, but it also appears that the setting to disable this doesn't exist (it's not visible on any of our instances).
- bradleyankrom 5mo agoHere's another link: https://www.theregister.com/2026/04/18/atlassians_new_data_collection_policy/ https://www.theregister.com/2026/04/18/atlassians_new_data_c...
- kevcampb 5mo agoUnfortunately that one has a subheading of "From August 17, the outfit will collect customer metadata by default unless you pay for the top tier" It's not just metadata, it's all "in-app data"
- Nathanba 5mo agothey sent out an email with this: https://dam-cdn.atl.orangelogic.com/CDNLink/AT12MW17.pdf https://dam-cdn.atl.orangelogic.com/CDNLink/AT12MW17.pdf
- kevcampb 5mo ago"Your available data contribution settings will be available no later than May 19, 2026." So let me guess, they're hoping that we forget about this by then, so that they can scoop up our data? I can't think any other reason for it.
- parkersweb 5mo agoThat email felt like the most weasel way of trying to sneak it past users - "data contribution", obfuscation, and the fact that they're not even making the opt out switch available quite yet...
- tgv 5mo agohttps://www.theregister.com/2026/04/18/atlassians_new_data_collection_policy/ https://www.theregister.com/2026/04/18/atlassians_new_data_c...
- kepano 5mo agoThis seems to be the official description of the changes: https://www.atlassian.com/trust/ai/data-contribution/faqs https://www.atlassian.com/trust/ai/data-contribution/faqs
- m4rtink 5mo agoWhat about really sensitive stuff like if possibly private tickets that have all kinds of stuff like customer data, embargoed CVE fixes or even sensitive health related data, are they just cobble that all into a model so it can leak out to random people ?
- carld 5mo agoI also do not see the setting to opt out. I'm at Atlassian Administration > Security, and I do not see Data contribution. I've looked at other, multiple setting pages and I do not see it. So, is this an automatic opt-in without the ability to opt-out?
- somewhatgoated 5mo agoOpt out features will be introduced at a later time
- pryanbeng 5mo agoThey said the opt out features will be rolled out to the Admin portal in May. I got this info from an email they sent out >To give you control over this change, we're introducing new in‑app settings that allow you to manage in‑app data contribution. Initially, these settings will apply to data in Jira, Confluence, and Jira Service Management, including data in your Atlassian Platform apps (Rovo, Home, Teams, Projects, Assets, Goals, Analytics, and Administration). We'll notify you when settings become available for additional apps you own, so you can review them in Atlassian Administration. Between today and May 19, 2026, we'll gradually roll out these settings in Atlassian Administration. We'll send you another email on May 19th as a reminder, so you have time to review and make any adjustments before August 17, 2026.
- deleted 5mo ago[deleted]
- itomato 5mo agoOpt-out at the Org level. To get value out of Rovo, it needs detail. Your over-subscribed Jira power user/admin can't effectively make it happen. No guarantees Atlassian (Rovo itself) can make it happen either, but the patterns are going to develop and evolve closer and closer to the Agents that make the features. They have a peculiar definition of Metadata, however. It's a proprietary data product derived from user content. It's a bit shit they way they sell it as metadata. It's a derivation. It's a product of Content, so it's Content - privacy safeguards cannot begin to cover the variation. \"Metadata includes two data types referred to as content attributes and common patterns. Content attributes are statistical characteristics, numeric fields, and derivatives of your in-app data. Examples of content attributes may include the number of story points assigned to a Jira work item or the complexity of a Confluence page. Common patterns are phrases, keywords, and topics we extract from search queries and results, Rovo Chat (conversations, prompts, and responses), and custom configuration data that are frequently seen across many customers, while omitting rare data that may be unique to your organization. Examples of common patterns may include common words, phrases, or Rovo Chat prompt topics that are frequently used by customers, such as “vacation policy” or “recap team activity.”\"
- MagicMoonlight 5mo agoThat's insane. Every single one of those things is highly sensitive and confidential information. How could you ever trust them after this? That information is priceless for shorting your company on the stock market. Not that they'd ever do that of course. Nobody with highly sensitive information about rival companies would ever do that.
- freakynit 5mo ago"In-app data covers user-generated content: page titles and bodies in Confluence, Jira issue titles, descriptions, comments, custom emoji names, custom status names, and workflow names" ... damn!!
- martinald 5mo agoAtlassian just goes from misstep to misstep. I still use their products quite often. The amount of P0 bugs I experience is absolutely crazy: - Bitbucket workers are hopelessly out of date (self hosted). We've had to put so many random workarounds in especially for Docker, as they don't keep them up to date enough - I have had a bug in JIRA for years where I can't reorder a new ticket unless I refresh the page - Every new feature they introduce into JIRA/Bitbucket over the past couple of years just doesn't work. - I tried their AI stuff on the free trial, didn't work at all, tried to cancel, can't cancel the free trial online and had to write a load of support tickets (of which the support ticket contact form bugged out multiple times). Anyone have any insight into why things have got so so dysfunctional? Tech debt? Talent leaving? Both? Even 'bad' enterprise software tends to be able to keep the most basic features running, but Atlassian is a whole new category. If you check their 'community' it is just hundreds/thousands of bugs with workarounds.
- mhitza 5mo agoFeatureatis. Just keep pumping out features with no thought. Today, probably also AI-coded . Even in mid-sized projects if you keep pushing for only new features you'll get a similar system. At least my experience in 3 or so midsized projects that I've worked on where nothing else mattered than checking of features from a huge backlog.
- jamesfinlayson 5mo agoAh, been at a company like that once before. After a while a dedicated team was created to go in and fix broader issues and essentially stop the system from collapsing under its own weight.
- ezoe 5mo agoUmm? Is there single step Atlassian did it right? It's a cancer of software development the suits force us to swallow while real development and useful documents are outside of their service because it's so stressful to use.
- wsatb 5mo ago
- huwsername 5mo agoIf the rumours of an Anthropic acquisition are true, this makes a lot of sense. Anthropic are probably looking for a clean, high-signal dataset of metadata around business tasks that they can buy.
- ezoe 5mo agoI doubt data in Atlassian are anywhere close to clean or organic. It was designed by hell to swallow shit to real programmer who does real works outside of Atlassian.
- jerjerjer 5mo agoProgrammer adjacent data can already be consumed from git repos. Atlassian has PM data.
- deleted 5mo ago[deleted]
- m4rtink 5mo agoI'm thinking it would be ideal if Broadcom buys Attlassian instead and pulls another VMware. Problem solved - for ever. ;-)
- siva7 5mo agoOh what the.. i can't pay for a 2000$ max sub :/
- mrweasel 5mo agoI know of a company that's stuck on the datacenter edition, because they aren't allowed by some customers to store their data in the cloud. I can't imagine how much they must pay for that. Until they finish evaluating competitors, and eventually migrate to .... something, they are completely stuck. Jira is at the heart of all of their workflows and they cannot and will not move to cloud. This was an Atlassian partner, but they got screwed over on that part as well.
- oliver236 5mo agogenius move.
- tqwhite 5mo agoI don't see it as a misstep at all. The purpose of StackOVerflow is to share expertise. I am 100% supportive of it being used for training... AI, you, everyone.
- malfist 5mo agoWhat? Atlassian is not stack overflow.
- UqWBcuFx6NV4r 5mo agoDude, what?
- Bnjoroge 5mo ago[flagged]
- reeseparker63 5mo agoWorth noting that Atlassian's data residency options don't exempt you from this—your data can still be used for training even if you've pinned it to a specific region.
- kepano 5mo agoThe official Atlassian FAQ on this change: https://www.atlassian.com/trust/ai/data-contribution/faqs https://www.atlassian.com/trust/ai/data-contribution/faqs
- boxingdog 5mo ago[dead]
- dreknows 5mo agoThe opt-out-by-default pattern has been gradually normalizing in enterprise SaaS, but what makes this particularly egregious is the combination of two things: the data scope (not just metadata, but all in-app content per kevcampb's link) and the broken opt-out (the disabling setting not rendering on any instance). One is a policy decision you can argue about. Both together suggest the friction is intentional. The data residency point is worth flagging separately - a lot of enterprise buyers treat region-pinning as a privacy guarantee for everything in their contract. It was never that. Residency tells you where data is stored at rest, not who can access it for what purpose.
- tgv 5mo agoWhat makes this extra scummy is this: “If customers were to right now terminate their contract, the new data contribution settings will not apply to them as these will not be enforced until August 17, 2026,” (from https://www.theregister.com/2026/04/18/atlassians_new_data_collection_policy/ https://www.theregister.com/2026/04/18/atlassians_new_data_c...) So you can't even take a bit of time to consider your options.
- deleted 5mo ago[deleted]
- deleted 5mo ago[deleted]
- sebakubisz 5mo ago[dead]
- pkilgore 5mo agoDoes this apply to Loom?
- itomato 5mo agoLoom isn't mentioned in the Partner materials I have read. That's about all I can say.
- willis936 5mo agoPresumably the government and HIPAA carveouts are for legal obligations. Trade secret theft is illegal so I wonder why they're not considering this.
- danny_codes 5mo agoMaybe if you put your data in Atlassian the you failed to adequately protect your trade secret? IIRC you need to make a reasonable effort to protect the secret.
- willis936 5mo agoEstablishing MNDAs is considered reasonable effort and this is a policy update that basically says "we are ignoring all MNDAs".
- dylan604 5mo agoBecause nobody will prosecute them for violations
- firesteelrain 5mo agoNo wonder they wanted to stop supporting the Data Center versions for on prem.
- jerhewet 5mo agoWill Atlassian be harvesting code and content from private Bitbucket repositories? The wording in their policies and FAQ's is vague, so I'd like to get a definitive (Yes / No) answer.
- zelphirkalt 5mo agoIf it is vague, then that probably is a very clear answer to your question.
- ororoo 5mo agoI think I looked for this months ago, and my interpretation was that no, they were not doing AI training with it.. but with this announcement, I will be moving all my stuff to my own servers. cloud repos are handy, but, having to constantly worry if some criminal comes "joinks, its my data now", is not worth it.
- microflash 5mo agoI read this as "Stop using this product" toggle every time a company does this without consent. It has done a good amount of mental and financial improvements to me.
- Bnjoroge 5mo agoPlenty of other companies enable this by default too, such as Github, Figma, Adobe, Vercel. I think it's fair to assume that if you ahve data stored within any company, they'll by default use it for training.
- tombert 5mo agoMaybe this will become The Year of the Self Hosted. For stuff that I don't particularly care about privacy I've kept on the cloud (e.g. my blog, which is public anyway and as such is probably training bots regardless), but for stuff that I don't want to be used to train their models and/or sell to advertisers I have moved to be self hosted on my own network.
- CodesInChaos 5mo agoDo you have any source for Github training on private repositories if you don't interact with copilot yourself?
- Bnjoroge 5mo agoI believe you have to disable the toggle, but not sure if it applies to folks who dont use copilot: https://github.com/orgs/community/discussions/188488 https://github.com/orgs/community/discussions/188488
- an0malous 5mo agoWe need to kill SaaS. Apps should be local-first and have peer-to-peer data sync. These companies won't stop until they use your data to replace you and enrich their owners.
- rogerthis 5mo agoBeautiful on paper. But it does not scale outside a certain type of tech people.
- an0malous 5mo agoWhat’s the scaling bottleneck? If you made a local-first, P2P version of Figma what would break first? For a company of like 50 people, I doubt you’d have more than 100GB of data so it should fit on everyone’s computers. The P2P syncing part seems solvable, even if you need a centralized handshake server somewhere. And from the user perspective I don’t see why the UX couldn’t be identical, so it’s all the same to them. It seems like the real bottleneck is something else.
- moring 5mo ago> If you made a local-first, P2P version of Figma what would break first? The guy who has to keep it running day by day, next to the other 30 local-first systems.
- an0malous 5mo agoWhat is there to run? There are millions of apps that don’t require maintenance, this was the default before SaaS.
- stackskipton 5mo agoEvery app need maintenance if it's connected to the internet. Security updates at minimum.
- rsynnott 5mo agoImagine an AI based on jira tickets. _That's_ the torment nexus.
- qsera 5mo agoI am wondering why not just rsyncrypt the source code before pushing to the repo? >rsyncrypto is a utility that encrypts a file (or a directory structure) in a way that ensures that local changes to the plain text file will result in local changes to the cipher text file. This, in turn, ensures that doing rsync to synchronize the encrypted files to another machine will have only a small impact on rsync's wire efficiency. https://manpages.ubuntu.com/manpages/focal/man1/rsyncrypto.1.html https://manpages.ubuntu.com/manpages/focal/man1/rsyncrypto.1...
- jason_s 5mo agoI'm really tired of JIRA, to the point where I have expressed it publicly: https://www.embeddedrelated.com/showarticle/1772.php https://www.embeddedrelated.com/showarticle/1772.php
- shadowgovt 5mo agoThe only silver lining I can see in this is that if they replace their existing tooling with AI integration, we might actually get search and confluence that works. I've lost count of how many times I search for a keyword and get no relevant results, but the document I'm looking for, which contains the keyword, is in my automatic pop-up of recent documents visited.
- rvz 5mo agoNo surprise here. It's by design.
- yalok 5mo agoDoes this include repos content in BitBucket?
- arjunthazhath 5mo agoOmg
- maxloh 5mo agoThe adage was "If you're not paying for the product, you are the product." Now enterprises are paying to become the product. That's ridiculous.
- wingmanjd 5mo agoI made this a while back to move us off our on-prem Atlassian to Gitlab [1]. Maybe it'll help someone if they want something similar. Fair warning: I haven't tried this recently, so YMMV. [1] https://gitlab.com/jeremygonyea/jira-to-gitlab-migration-tool https://gitlab.com/jeremygonyea/jira-to-gitlab-migration-too...
- RomanPushkin 5mo agoThey're so desperate because their stock went down ~10 times in last 5 years or so
- fred_is_fred 5mo agoTo anyone using a model trained on my company's Jira tickets, I apologize for the regression.
- atomic128 5mo agoRumors that Anthropic is in talks to buy Atlassian, presumably for the training data. Data poisoning efforts are underway: https://www.reddit.com/r/PoisonFountain/comments/1sqrq24/atlassian_enables_default_data_collection_to/ https://www.reddit.com/r/PoisonFountain/comments/1sqrq24/atl...
- mrweasel 5mo agoI know at least two companies that won't be able to use Atlassian products anymore if that's the case. They really don't give a shit about privacy and regulatory requirements.
- svilen_dobrev 5mo agogithub etc hold source code -> scraped -> so AI may generate any of that. And the specs become the new source (code). fast forward.. Atlassian etc hold source specs -> scraped -> so AI may generate any of that.. then any of above.. the new source would be (?what? company missions? get-rich-quick-schemes?) fast forward..
- zurfer 5mo agoHmm, if the stock keeps falling that might really happen.
- tesders 5mo ago[dead]
- deferredgrant 5mo ago[flagged]
- nyellin 5mo agoWhy does Atlassian need to train AI models?
- odie5533 5mo agoRumor is they're being bought by Anthropic.
- CobrastanJorji 5mo agoMicrosoft, Amazon, Google, everybody else with both having-business-customers and also data-collecting businesses: "We swear that we absolutely will not collect/train our stuff on business customer data." Atlassian: "Yolo!"
- zelphirkalt 5mo agoThey are lowering the threshold for this kind of shit for everyone else. We should kill it with fire, before this spreads even further. But I guess most businesses led by non-technical people will simply not care and give their customer data to the AI sharks at no additional cost.
- everdrive 5mo agoWho wouldn't these days. Just assume if a company has your data it's training AI on it. No company cares about your privacy more than they do their profits. Not a one.
- zelphirkalt 5mo agoOh another piece of the abysmal tools stack that should bite the dust. Maybe I will still see a software job without terrible tooling in the EU.
- RobRivera 5mo agoYet another opportunity to provide an alternative that keeps data private
- ai-tamer 5mo agoGenuine question: how many agent-hours to rebuild Jira from scratch and migrate 100% of the content out? Split the work, pool our agents, ship by August 17. ;-)
- josefritzishere 5mo agoThis is such an obvious conflict of interest. They know Confluence is full of proprietary information. They are violating their client's trust https://www.theregister.com/2026/04/18/atlassians_new_data_collection_policy/ https://www.theregister.com/2026/04/18/atlassians_new_data_c...
- fakedang 5mo agoBye bye Bitbucket, Jira, Confluence, etc. Seriously, if you're using any Atlassian product other than Statuspage, you deserve to get your data hoovered up for AI.
- az226 5mo agoYou can thank GitHub for setting this draconian precedent
- CodesInChaos 5mo agoI don't think GitHub even set a precedent for this. My understanding is that they don't train on private repositories per se, though if you access a private repository through copilot, the data flow through copilot can be trained on, which pulls in data from the repo. So a private repo should be safe, as long as you don't use copilot. While Atlassian wants to pull in data from private issue trackers/wikis.
- az226 5mo agoListen to yourself. Take a moment and try to unpack the mental gymnastics wrangling you just did. Ask yourself, why does the fact that you have a Copilot subscription make it okay to train on all your private repos? GitHub does not have any of its own models. It routes to partners like OpenAI. Just because some data is from private repos, doesn’t mean all data is flowing nor does it mean it should be trained on just because it’s being inferences on, and there is a difference on the data that was used vs. all the data from that repo, and difference between just that repo vs. all private repos. And they made it all opted in as default. Draconian. So yes, they did set a precedent and you’re here arguing why it’s okay.
- linsomniac 5mo agoJust a couple days ago my CTO was saying he was reluctant to clone all our git repos into github because of the AI training possibility. All our code is in bitbucket now, so not sure what our plan now is.
- bastawhiz 5mo agoLet's talk about The Browser Company being bought by Atlassian. If you haven't dropped Arc or Dia, now seems like the time.
- jononor 5mo agoTime to migrate off Atlassian, and ban it for any use in the company. You cannot just help yourself to customer data like that. The data is not yours, never was, and never will be. Pay for a service that blatantly rips of our company IP? Nope. Thanks for showing your colors so clearly Atlassian. Good riddance.
- AdminAccount 5mo agoA to my knowledge unconfirmed claim by the register states: "Tseytlin said that some Atlassian customers are completely excluded from metadata or in‑app "data contribution" entirely. This includes those who use customer-managed keys, or bring your own key, Atlassian Government Cloud, or Atlassian Isolated Cloud users. He said Atlassian will also not collect metadata or in-app data from customers with HIPAA compliance requirements or from some government and financial services customers." https://www.theregister.com/2026/04/18/atlassians_new_data_collection_policy/ https://www.theregister.com/2026/04/18/atlassians_new_data_c...