The partnership is about access, not exclusivity
Atlassian has used OpenAI models in its AI features since launching Atlassian Intelligence in April 2023. The company has also built around Teamwork Graph, its map of connections among people, projects, documents and decisions. It introduced MCP integration for ChatGPT in December 2025. GPT-6 Astra launched separately on September 3.
The latest announcement links these efforts more closely. OpenAI’s advanced models will join Rovo’s model lineup as they ship, while Atlassian’s updated MCP server will expose more platform data and functions to external AI tools. There is also a financial commitment: an OpenAI representative described the arrangement anonymously as a de facto spending commitment, with Atlassian directing funds toward OpenAI models and technology. The representative did not disclose the terms of the “expanded access.”
The commitment does not make Astra Rovo’s default. Atlassian told VentureBeat that Rovo’s internal gateway dynamically routes requests to OpenAI and other providers based on model capability, speed and the cost of completing a task.
That distinction matters. Atlassian’s MCP announcement for its Team '26 Europe conference also quoted Scott White, Anthropic’s head of enterprise products, calling Atlassian one of the most-used enterprise MCP integrations in Claude. Atlassian measured token savings in its updated server using Claude models.
What the MCP update adds
Atlassian says its MCP server handles more than 15 million calls a day and offers over 220 tools across Jira, Confluence, Bitbucket, Loom, Goals and other products. In internal tests, the updated version used up to 25% fewer tokens for comparable work in Jira and Confluence. Jira Service Management support is planned for later.
An agent in ChatGPT, Codex, Cursor or Claude can use a single request to check a pull request, read its related Confluence specification and prepare follow-up tasks. That is more than a keyword search: the value comes from connecting work across tools.
For administrators, Atlassian describes a set of controls for those connections:
Those controls address a central concern for companies connecting agents to systems that hold workplace data. They do not, by themselves, eliminate prompt-injection risk: an attacker could put instructions in a task or page that try to steer an agent with write access. Atlassian’s proposed mitigations include user permissions, separate write-access levels, confirmation for risky actions and data loss prevention. I think those controls need to be tested in a pilot, not treated as proof that the risk is settled.
Astra brings cost and safety trade-offs
OpenAI says Astra delivers leading results in benchmarks for computer use, coding and cybersecurity. Those comparisons were prepared and presented by OpenAI. In the independent Artificial Analysis Intelligence Index, published by OpenAI, Anthropic’s Claude Fable 5.1 scored higher than Astra.
Astra costs $10 per million input tokens and $50 per million output tokens. Atlassian says Rovo credit consumption depends on the models and computing resources used, so tasks that require deeper reasoning from an agent will cost more. There is no fixed price increase, but bills may rise with usage.
Astra is the first OpenAI model to reach the “Critical” level for cybersecurity under its Preparedness Framework. During testing, it scored 100% on one vulnerability-finding benchmark and found two previously unknown zero-day vulnerabilities.
OpenAI says it uses several safeguards, including automated checks in Codex, production monitoring for model failures and classifiers that can stop unauthorized actions. The company also acknowledges that these checks can slow, pause or stop legitimate work, including defensive security tasks. In ChatGPT or Codex, users may be asked to review a task before continuing; in the API, it simply stops.
Astra also refuses some more complex offensive security tasks, such as writing exploits to confirm a vulnerability. OpenAI says it plans to ease restrictions over time for verified defensive use cases. For teams building automated pipelines, interruptions are part of the operating conditions, not an edge case to ignore.
OpenAI has another caveat: Astra’s written account of its reasoning is harder to monitor than the previous model’s. The company calls this a serious regression and says it is still investigating. For organizations that need to explain why an agent took an action, system logs from Atlassian and Codex may be more useful than the model’s own account.
The unresolved data questions
Atlassian says OpenAI receives only the data returned by an MCP tool for a specific request, and that access is limited by the permissions of the user who submitted it. OpenAI says Astra supports zero data retention for eligible API customers. Enterprise access to Astra is off by default until an administrator enables it. Atlassian’s current policy lists OpenAI as a subprocessor that does not train models on customer prompts and responses.
The gap is in the details at the boundary between those policies: which API customers qualify for zero data retention, and whether retention periods for models used inside Rovo match the terms for connecting ChatGPT and Codex through MCP. Companies handling regulated data should get answers to both before putting that information through the system.
I think the more consequential bet here is not that OpenAI will become Atlassian’s sole model provider. Atlassian is making the platform, its permissions and its Teamwork Graph the durable layer, while models remain replaceable. That gives customers flexibility, but it also leaves them responsible for testing access controls, tracking the cost of harder tasks and designing workflows that can tolerate safety pauses.
The larger question of control remains open. Atlassian describes autonomous agents that take on tasks and multiple agents coordinating with human checkpoints as future possibilities. For now, the partnership expands what agents can reach; it does not settle who is accountable when they act.
Daily AI news
Every day we pick what actually matters in AI and explain it plainly — no hype, no filler. Subscribe if you want to follow where the industry is going.
Only what matters — every day
Follow on X