AI You're Actually Allowed to Use

Maria ReisingerMaria Reisinger·2026-07-28·5 min read
Enterprise AIData PrivacyGDPRAI GovernanceSecure AI

Der Schalter.png

The industry now switches AI on by default for everyone. For a large share of organisations, that isn't a convenience; it's a problem they have to defend against.

The clearest signal of where enterprise software is heading came, quietly, in an admin settings panel. Atlassian's AI assistant, Rovo, began life as an opt-in add-on you chose to buy. Within two years it became a platform default: bundled into every paid plan, switched on automatically, and, as of 2026, set to contribute customer data to train Atlassian's models unless an administrator actively opts out. There is no global off switch, new apps inherit the setting automatically, and data already collected can be retained for years.

This is the new normal: AI adoption as something that happens to you, that you switch off, rather than something you consciously choose. And it quietly assumes a world in which everyone can, and wants to, flip that switch to on. Many can't. Many won't.

Atlassian isn't alone

Atlassian is just the most recent and most candid case. The same move, training on customer data, switched on by default, with opting out left to the customer, runs right across the industry:

Slack turned on training of its models on customer messages and content by default in 2024; opting out meant emailing Slack to ask. Only after a public backlash did it revise its privacy principles.

LinkedIn began quietly using member data to train AI in 2024, behind a buried opt-out toggle. In the UK and EU, it took the data-protection regulator to halt the practice.

Meta has, since 2025, used the public posts of adult EU users to train its AI, relying on "legitimate interest" under the GDPR, with objection possible only via a form, and anyone who had already objected in 2024 having to do it again.

Zoom gave itself the right to use customer content for AI training through a 2023 terms update, then reversed course after fierce protest.

Salesforce, finally, set off a debate in 2025 with a new default AI-data setting and the question of what customers had actually agreed to.

Five names, one pattern: opt-out instead of opt-in, the burden on the customer, and regulators or public pressure as the only brake.

The organisations the default leaves behind

Talk to teams in healthcare, law, finance, insurance or the public sector and a pattern emerges fast. It isn't that they don't see the value of AI; it's that they aren't free to hand their data to a system they don't control. Three situations come up again and again.

Regulation draws a hard line. Patient records, case files, financial data and citizen information sit under rules such as the GDPR, sector law and professional confidentiality, all of which dictate where data may be processed and forbid it being fed into opaque training pipelines. An "on by default" model turns a productivity feature into a compliance incident.

The customer says no. Increasingly it isn't even the company's own choice. Their clients now write it into contracts: our data must not touch third-party AI, must not leave the EU, must never be used for training. A single default toggle in the wrong position can breach a customer agreement the business depends on.

It's a matter of principle. And plenty of organisations simply don't want the content their people create, strategy, code, client work, quietly improving someone else's model. Declining shouldn't require a project plan, a deadline and permanent vigilance. Yet today, opting out is the work; opting in is the default.

"For a great many teams, the question isn't 'which AI is smartest?' It's 'which AI am I actually allowed to use?'"

Metafrazo: AI you're allowed to use

Metafrazo is built for exactly those teams: a secure AI platform that starts from the opposite premise. Not "AI for everyone, off if you must," but AI on your terms, by design. The difference isn't a marketing line; it's in where the data lives, what happens to it, and who decides. Two commitments sit underneath everything we build.

Hosted and processed in the EU

Your data is processed within the European Union, under European data-protection law. The GDPR is the foundation, not a checkbox. You always know the jurisdiction your data sits in, and you can give your own customers exactly the same assurance.

Never trained on your data

Your content is never used to train models. What your teams create stays yours, full stop. There is no data-contribution toggle to police, because contribution was never the default.

Those two principles do something the industry's default model can't: they let an organisation say yes to AI without breaking a promise to its regulator, its client, or itself. Control isn't a setting buried three menus deep that you re-audit after every release; it's the starting point. You decide what the AI can see and what it can do, and nothing is switched on behind your back.

That is the real unlock. The teams held back from AI aren't held back by capability; the models are extraordinary and getting better. They're held back by trust, by the gap between what the technology can do and what they are permitted to let it touch. Close that gap, and the people who were locked out, whether by law, by contract, or by conviction, finally get a way in.

Metafrazo: secure AI, hosted in the EU, never trained on your data.

Sources

  1. TechCrunch, "Slack under attack over sneaky AI training policy," May 2024.

  2. Legal IT Insider, "LinkedIn suspends opt-out AI model training for UK following ICO concerns," September 2024.

  3. Goodwin, "Training of Meta's AI Systems and the Use of the European Users' Data," May 2025.

  4. Variety, "Zoom Now Says It Won't Use Any Customer Content to Train AI," August 2023.

  5. Salesforce Ben, "Salesforce's New AI Data Setting Sparks Debate Over What Customers Agreed To," 2025.

Copy

Rate this post

No ratings yet