i
News
News · 2026-10-06

Atlassian deepens its OpenAI partnership without choosing one model

@neuronium_ai @neuronium_ai

Atlassian is deepening its OpenAI partnership with a spending commitment and plans to bring OpenAI’s latest models into Rovo as they become available. The change gives AI agents more ways to work across Jira, Confluence, Bitbucket and other Atlassian products, while an updated MCP server expands access for external tools. But GPT-6 Astra will not become Rovo’s default model: Atlassian says its platform will continue routing work among providers, making the partnership a bet on OpenAI without giving up model choice.

Cover: Atlassian deepens its OpenAI partnership without choosing one model

The partnership is about access, not exclusivity

Atlassian has used OpenAI models in its AI features since launching Atlassian Intelligence in April 2023. The company has also built around Teamwork Graph, its map of connections among people, projects, documents and decisions. It introduced MCP integration for ChatGPT in December 2025. GPT-6 Astra launched separately on September 3.

The latest announcement links these efforts more closely. OpenAI’s advanced models will join Rovo’s model lineup as they ship, while Atlassian’s updated MCP server will expose more platform data and functions to external AI tools. There is also a financial commitment: an OpenAI representative described the arrangement anonymously as a de facto spending commitment, with Atlassian directing funds toward OpenAI models and technology. The representative did not disclose the terms of the “expanded access.”

The commitment does not make Astra Rovo’s default. Atlassian told VentureBeat that Rovo’s internal gateway dynamically routes requests to OpenAI and other providers based on model capability, speed and the cost of completing a task.

That distinction matters. Atlassian’s MCP announcement for its Team '26 Europe conference also quoted Scott White, Anthropic’s head of enterprise products, calling Atlassian one of the most-used enterprise MCP integrations in Claude. Atlassian measured token savings in its updated server using Claude models.

OpenAIAnthropicother providers

What the MCP update adds

Atlassian says its MCP server handles more than 15 million calls a day and offers over 220 tools across Jira, Confluence, Bitbucket, Loom, Goals and other products. In internal tests, the updated version used up to 25% fewer tokens for comparable work in Jira and Confluence. Jira Service Management support is planned for later.

An agent in ChatGPT, Codex, Cursor or Claude can use a single request to check a pull request, read its related Confluence specification and prepare follow-up tasks. That is more than a keyword search: the value comes from connecting work across tools.

For administrators, Atlassian describes a set of controls for those connections:

The server is hosted by Atlassian and protected by OAuth 2.1 and PKCE by default. It checks the requesting user’s existing permissions, so an agent cannot access data that user cannot access.
Read, write and destructive actions are divided into risk levels. Administrators can require separate confirmation for higher-risk actions.
Atlassian Guard data security and loss prevention policies apply to all MCP connections.
Administrators can set allowlists for domains and IP addresses, manage read, write and search permissions for individual spaces, enable organization-wide action logging, or disable logging entirely.

Those controls address a central concern for companies connecting agents to systems that hold workplace data. They do not, by themselves, eliminate prompt-injection risk: an attacker could put instructions in a task or page that try to steer an agent with write access. Atlassian’s proposed mitigations include user permissions, separate write-access levels, confirmation for risky actions and data loss prevention. I think those controls need to be tested in a pilot, not treated as proof that the risk is settled.

Astra brings cost and safety trade-offs

OpenAI says Astra delivers leading results in benchmarks for computer use, coding and cybersecurity. Those comparisons were prepared and presented by OpenAI. In the independent Artificial Analysis Intelligence Index, published by OpenAI, Anthropic’s Claude Fable 5.1 scored higher than Astra.

Astra costs $10 per million input tokens and $50 per million output tokens. Atlassian says Rovo credit consumption depends on the models and computing resources used, so tasks that require deeper reasoning from an agent will cost more. There is no fixed price increase, but bills may rise with usage.

Astra is the first OpenAI model to reach the “Critical” level for cybersecurity under its Preparedness Framework. During testing, it scored 100% on one vulnerability-finding benchmark and found two previously unknown zero-day vulnerabilities.

OpenAI says it uses several safeguards, including automated checks in Codex, production monitoring for model failures and classifiers that can stop unauthorized actions. The company also acknowledges that these checks can slow, pause or stop legitimate work, including defensive security tasks. In ChatGPT or Codex, users may be asked to review a task before continuing; in the API, it simply stops.

Astra also refuses some more complex offensive security tasks, such as writing exploits to confirm a vulnerability. OpenAI says it plans to ease restrictions over time for verified defensive use cases. For teams building automated pipelines, interruptions are part of the operating conditions, not an edge case to ignore.

OpenAI has another caveat: Astra’s written account of its reasoning is harder to monitor than the previous model’s. The company calls this a serious regression and says it is still investigating. For organizations that need to explain why an agent took an action, system logs from Atlassian and Codex may be more useful than the model’s own account.

The unresolved data questions

Atlassian says OpenAI receives only the data returned by an MCP tool for a specific request, and that access is limited by the permissions of the user who submitted it. OpenAI says Astra supports zero data retention for eligible API customers. Enterprise access to Astra is off by default until an administrator enables it. Atlassian’s current policy lists OpenAI as a subprocessor that does not train models on customer prompts and responses.

The gap is in the details at the boundary between those policies: which API customers qualify for zero data retention, and whether retention periods for models used inside Rovo match the terms for connecting ChatGPT and Codex through MCP. Companies handling regulated data should get answers to both before putting that information through the system.

I think the more consequential bet here is not that OpenAI will become Atlassian’s sole model provider. Atlassian is making the platform, its permissions and its Teamwork Graph the durable layer, while models remain replaceable. That gives customers flexibility, but it also leaves them responsible for testing access controls, tracking the cost of harder tasks and designing workflows that can tolerate safety pauses.

The larger question of control remains open. Atlassian describes autonomous agents that take on tasks and multiple agents coordinating with human checkpoints as future possibilities. For now, the partnership expands what agents can reach; it does not settle who is accountable when they act.

Daily AI news

Every day we pick what actually matters in AI and explain it plainly — no hype, no filler. Subscribe if you want to follow where the industry is going.

Only what matters — every day

Follow on X