AI You're Actually Allowed to Use


The industry now switches AI on by default for everyone. For a large share of organisations, that isn't a convenience; it's a problem they have to defend against.
The clearest signal of where enterprise software is heading came, quietly, in an admin settings panel. Atlassian's AI assistant, Rovo, began life as an opt-in add-on you chose to buy. Within two years it became a platform default: bundled into every paid plan, switched on automatically, and, as of 2026, set to contribute customer data to train Atlassian's models unless an administrator actively opts out. There is no global off switch, new apps inherit the setting automatically, and data already collected can be retained for years.
This is the new normal: AI adoption as something that happens to you, that you switch off, rather than something you consciously choose. And it quietly assumes a world in which everyone can, and wants to, flip that switch to on. Many can't. Many won't.
Atlassian isn't alone
Atlassian is just the most recent and most candid case. The same move, training on customer data, switched on by default, with opting out left to the customer, runs right across the industry:
Slack turned on training of its models on customer messages and content by default in 2024; opting out meant emailing Slack to ask. Only after a public backlash did it revise its privacy principles.
LinkedIn began quietly using member data to train AI in 2024, behind a buried opt-out toggle. In the UK and EU, it took the data-protection regulator to halt the practice.
Meta has, since 2025, used the public posts of adult EU users to train its AI, relying on "legitimate interest" under the GDPR, with objection possible only via a form, and anyone who had already objected in 2024 having to do it again.
Zoom gave itself the right to use customer content for AI training through a 2023 terms update, then reversed course after fierce protest.
Salesforce, finally, set off a debate in 2025 with a new default AI-data setting and the question of what customers had actually agreed to.
Five names, one pattern: opt-out instead of opt-in, the burden on the customer, and regulators or public pressure as the only brake.
The organisations the default leaves behind
Talk to teams in healthcare, law, finance, insurance or the public sector and a pattern emerges fast. It isn't that they don't see the value of AI; it's that they aren't free to hand their data to a system they don't control. Three situations come up again and again.
Regulation draws a hard line. Patient records, case files, financial data and citizen information sit under rules such as the GDPR, sector law and professional confidentiality, all of which dictate where data may be processed and forbid it being fed into opaque training pipelines. An "on by default" model turns a productivity feature into a compliance incident.
The customer says no. Increasingly it isn't even the company's own choice. Their clients now write it into contracts: our data must not touch third-party AI, must not leave the EU, must never be used for training. A single default toggle in the wrong position can breach a customer agreement the business depends on.
It's a matter of principle. And plenty of organisations simply don't want the content their people create, strategy, code, client work, quietly improving someone else's model. Declining shouldn't require a project plan, a deadline and permanent vigilance. Yet today, opting out is the work; opting in is the default.
"For a great many teams, the question isn't 'which AI is smartest?' It's 'which AI am I actually allowed to use?'"
Metafrazo: AI you're allowed to use
Metafrazo is built for exactly those teams: a secure AI platform that starts from the opposite premise. Not "AI for everyone, off if you must," but AI on your terms, by design. The difference isn't a marketing line; it's in where the data lives, what happens to it, and who decides. Two commitments sit underneath everything we build.
Hosted and processed in the EU
Your data is processed within the European Union, under European data-protection law. The GDPR is the foundation, not a checkbox. You always know the jurisdiction your data sits in, and you can give your own customers exactly the same assurance.
Never trained on your data
Your content is never used to train models. What your teams create stays yours, full stop. There is no data-contribution toggle to police, because contribution was never the default.
Those two principles do something the industry's default model can't: they let an organisation say yes to AI without breaking a promise to its regulator, its client, or itself. Control isn't a setting buried three menus deep that you re-audit after every release; it's the starting point. You decide what the AI can see and what it can do, and nothing is switched on behind your back.
That is the real unlock. The teams held back from AI aren't held back by capability; the models are extraordinary and getting better. They're held back by trust, by the gap between what the technology can do and what they are permitted to let it touch. Close that gap, and the people who were locked out, whether by law, by contract, or by conviction, finally get a way in.
Metafrazo: secure AI, hosted in the EU, never trained on your data.
Sources
-
TechCrunch, "Slack under attack over sneaky AI training policy," May 2024.
-
Legal IT Insider, "LinkedIn suspends opt-out AI model training for UK following ICO concerns," September 2024.
-
Goodwin, "Training of Meta's AI Systems and the Use of the European Users' Data," May 2025.
-
Variety, "Zoom Now Says It Won't Use Any Customer Content to Train AI," August 2023.
-
Salesforce Ben, "Salesforce's New AI Data Setting Sparks Debate Over What Customers Agreed To," 2025.
Rate this post
Related articles

What DORA Really Asks of Your Approvals
DORA no longer asks whether an approval control exists, but whether it still works across your whole Jira over time. That drift never shows in a single ticket. Here is where Article 9 fits, and why the evidence you need is already in your Jira history.
2026-08-19

The color decides, not the number
Four teams estimate in four different units, and one dashboard turns them into a single colour. When the bar is green, nobody asks what the number underneath actually means. The gap this opens up only matters when someone asks what a decision was based on. And that is where the configuration and the event history start to disagree.
2026-08-17

Why workflow bypass is one of the most invisible governance risks in a large Jira estate
Your Jira dashboards reward speed. A skipped review can look exactly like speed. Workflow bypass rarely appears as an obvious governance failure. It starts with small, defensible decisions: a review skipped, a workflow step routed around, a ticket reopened, or an issue left stuck in a status. Individually, none looks alarming. Over time, they form patterns that traditional velocity and project dashboards can completely miss. The data is already there in Jira. The real challenge is seeing the pattern early enough to act. The Bypass Risk Score turns those workflow events into a continuously updated signal, helping admins identify where governance attention is needed before a small bypass becomes a structural problem.
2026-08-14

