Enterprise project and dev software staple Atlassian said Monday it is expanding a partnership with OpenAI that dates back to 2023, putting OpenAI's newest frontier models — including the recently released GPT-6 Astra and the GPT-5.6 series — into Atlassian's platform and its Rovo AI, and connecting Atlassian's enterprise context to OpenAI's ChatGPT and Codex.
For the enterprise technical buyers who live in Jira, Confluence and Bitbucket, the announcement means more capability, a clearer governance story, and a commercial tie to OpenAI that Atlassian has carefully stopped short of making exclusive.
What's new with OpenAI and Atlassian's partnership
Much of the described integration predates this week. Atlassian has used OpenAI models to power its AI since Atlassian Intelligence launched in April 2023, with the Teamwork Graph — Atlassian's map of how people, projects, documents and decisions connect — part of the pitch from the start. The company introduced its MCP integration for ChatGPT in December 2025. GPT-6 Astra shipped separately on September 3.
What the companies added this week is mostly connective: the state-of-the-art OpenAI models flowing into Rovo's model mix as they're released, a rebuilt Atlassian MCP server that exposes far more of the Atlassian estate to outside AI tools, and a commercial commitment.
Asked what "expanded access" means in contractual terms, an OpenAI representative declined to share specifics but described the arrangement, on background, as "effectively a spend commitment" — Atlassian committing dollars to OpenAI models and tech, not the reverse.
Atlassian is not betting the platform on one model
The most important thing for buyers to understand is what the deal is not.
Atlassian was explicit in correspondence with VentureBeat that GPT-6 Astra is not becoming Rovo's default model. Rovo runs an internal AI gateway that routes dynamically across OpenAI and other providers, balancing capability, speed and cost per task.
That multi-model reality is visible in Atlassian's own materials. Its MCP announcement — timed to its Team '26 Europe conference — leads with a quote from Anthropic's head of enterprise product, Scott White, who calls Atlassian's MCP "one of the most-used enterprise MCP integrations on Claude," and reports that the rebuilt server's token savings were measured on Claude models.
In other words, on roughly the same day OpenAI touts Atlassian as a showcase, Atlassian is showcasing Anthropic. Enterprises evaluating lock-in should read that as a feature: Atlassian is positioning the Teamwork Graph as the durable asset and treating the models as interchangeable.
The MCP layer is the real engine — and where the governance lives
The piece most relevant to developers and administrators is the rebuilt Atlassian MCP server, which the company says now handles more than 15 million calls a day. It exposes 220-plus tools across Jira, Confluence, Bitbucket, Loom, Goals and more, and Atlassian says it runs leaner than the prior version — up to 25% fewer tokens on comparable Jira and Confluence work in internal testing. Jira Service Management support is listed as coming soon.
The design lets an agent in ChatGPT, Codex, Cursor or Claude reach across the software lifecycle in a single request — inspecting a pull request, reading the linked Confluence spec, and drafting the follow-up work items — rather than stopping at a shallow keyword lookup.
For CISOs and platform owners, the governance model is spelled out more concretely than in either company's partnership post. Atlassian says the MCP server:
Is Atlassian-hosted and secured with OAuth 2.1 and PKCE by default, and enforces each user's existing permissions at query time, so an agent can never reach data the user couldn't already access.
Separates read, write and destructive actions into distinct risk tiers, letting clients require explicit confirmation on higher-risk steps.
Enforces Data Security Policies and Data Loss Prevention through Atlassian Guard across MCP connections.
Gives admins domain allowlists, IP allowlists, per-scope read/write/search controls and org-wide audit logging from the Admin Console — including the ability to disable writes entirely.
That addresses the thorniest objection to pointing an autonomous agent at a system of record.
It does not, on its own, fully resolve the prompt-injection risk — a malicious instruction planted in a ticket or page attempting to steer an agent with write access — but the combination of per-user permissions, separated write tiers, confirmation on risky steps and DLP is the mitigation Atlassian is offering, and it's a reasonable one to pressure-test in a proof of concept.
Astra in the loop: more capability, real cost, and safety checks that can interrupt work
GPT-6 Astra is the headline model, and it is genuinely capable — OpenAI reports state-of-the-art results on computer use, coding and cybersecurity benchmarks. Buyers should note two things. First, the comparisons are OpenAI's own and OpenAI-framed; on at least one independent measure OpenAI itself publishes, the Artificial Analysis Intelligence Index, Anthropic's Claude Fable 5.1 scores higher than Astra. Second, Astra is expensive — $10 per million input tokens and $50 per million output — and Atlassian notes that Rovo credit consumption scales with the models and compute a task uses, so heavier agentic reasoning will cost more credits. There is no flat price increase, but there is a variable one.
The operational caveats matter more for this audience than the benchmarks. Astra is OpenAI's first model to hit the "Critical" cybersecurity threshold under its Preparedness Framework; in testing it scored 100% on one exploit benchmark and surfaced two previously unknown zero-day vulnerabilities.
To contain that, OpenAI ships layered safeguards — Codex auto-review, production misalignment monitoring, and classifiers that can halt unauthorized actions. By OpenAI's own admission, those checks can "slow, pause, or stop legitimate work," defensive security tasks included; a paused task in ChatGPT or Codex may ask the user to review before continuing, and in the API it simply stops.
Teams building automated pipelines on Astra should design for interruption. Astra also currently refuses more advanced offensive tasks, such as writing proof-of-concept exploits — relevant for security teams hoping to use it for red-teaming, with OpenAI signaling it will loosen those limits for vetted defensive workflows over time.
One more item worth noting: OpenAI says Astra's written reasoning is harder to monitor than its predecessor's, a regression it calls serious and is still researching. For organizations that expect to audit why an agent did what it did, the model's own explanations may be a weaker trail than the system-level logs Atlassian and Codex capture.
What happens to your data
On the question enterprises ask first — does OpenAI get your data — the picture is clearer than the pitch materials suggested, though assembled from several sources. Atlassian says only the specific data returned by an invoked MCP tool is sent to OpenAI as context for that query, scoped to the requesting user's permissions.
On OpenAI's side, Astra supports Zero Data Retention for eligible API customers, and enterprise access to Astra is off by default until an administrator enables it. Atlassian's standing policy lists OpenAI as a subprocessor that does not train on customer inputs or outputs.
The remaining ambiguity is in the seams: what "eligible" covers for ZDR, and whether the Rovo-internal model path carries identical retention terms to the ChatGPT/Codex MCP connection. Those are worth confirming before a regulated workload goes near either path.
The bottom line
For Atlassian customers, this is an evolution, not a rupture. The newer models and the broader MCP surface make agents inside Atlassian meaningfully more useful, and the governance controls are the kind enterprises should demand.
The strategic signal is that Atlassian is deepening its OpenAI relationship — with real dollars behind it — while deliberately keeping its platform model-agnostic, with Anthropic and others very much in the mix.
The capabilities that remain "on the horizon," including autonomous agents that pick up work items and multi-agent orchestration with human checkpoints, are where the more consequential questions about control and accountability will actually get answered.
For now, the prudent move is to pilot the MCP connection against the governance claims, watch credit consumption on heavy reasoning, and design any Astra-based automation to tolerate a safety pause.
