Atlassian launches AMP to tackle AI code visibility, attribution

Atlassian today rolled out new offerings designed to make it easier for IT to differentiate coding by AIs from human coding. The problem is that such distinctions in the enterprise today are rarely binary, as much coding has lots of each.

The lack of meaningful visibility into code origin is a massive problem for most large businesses, said Jamil Valliani, head of AI products at Atlassian, in an interview. “For most enterprises, this is what is holding them back from further adopting AI.”

Atlassian’s new offering is dubbed Agentic Multiplayer Protocol (AMP), which the company described as its “foundation for how humans and agents collaborate across the Atlassian platform,” defining how agents “take part in multiplayer work with an identity, scoped authority, shared context and tasks, and results you can review.”

It includes Teamwork Graph, which Atlassian said indexes source code down to functions, symbols and classes, allowing coders to more easily search across Bitbucket and GitHub without cloning a repo. The vendor also said that Teamwork Graph provides full attribution and accountability, including version history that shows exactly what a human wrote versus what an agent did, across Claude, Codex, Figma, and Rovo.

As well, a new mode in Rovo Chat, Rovo Work, handles complex, multi-step tasks with human oversight to review and approve them. It executes across Jira, Confluence, and connected tools, and can run for hours in a secure sandbox to achieve the goal approved by the user. And a geographic feature called EU AI Inference restricts LLM processing exclusively to models hosted within the EU, the vendor claims.

Atlassian said that those capabilities are available immediately. 

The announcement also described some promised non-human identity (NHI) capabilities, including controls examining what is visible to AI, and providing restrictions on what access can be granted to agent accounts and other forms of NHI. Those capabilities, Atlassian said, will roll out “soon.”

Potential value substantial

Analysts and consultants generally said that the move toward greater code origin visibility is good, but that it’s unclear whether the Atlassian offering will deliver enough meaningful context to make it useful.

Adam Resnick, a research manager at IDC, noted, “the potential value is substantial, particularly as agents take on more autonomous work.”

But, he stressed, “the real value goes beyond knowing who typed a given line. Enterprises want visibility into where humans and agents exercised judgment on consequential decisions, such as which data store to adopt or how to handle authentication. The most useful provenance shows whether meaningful human review took place, rather than simply recording that someone clicked approve.”

That more sophisticated visibility, Resnick said, “gives organizations a basis for risk-based review, rather than a blanket rule for AI-generated code. A small, well-scoped agent change may warrant lighter review than a human-written change to a payments system. Origin is one input, alongside the degree of agent autonomy, the consequence of the change, and evidence of human oversight.”

One of the hardest problems

Indeed, he said, “separating AI and human contributions is one of the hardest problems in AI software engineering intelligence.” And it involves how most enterprises are using agentic development today.

Git, for example, records an author and a committer, “so when a developer runs an agent locally, the record names the developer. Attribution usually lives in commit message text, which developers can disable, edit, or lose when history is rewritten,” Resnick pointed out. “Conventions vary from one vendor to the next. And developers routinely edit agent output, so human and AI work ends up mixed together. And many organizations run several agents side by side.”

Mike Wilkes, enterprise CISO at Aikido Security, agreed.

“Git can tell you who committed a change, but that is increasingly different from who, or what, actually wrote the code,” he said. “A developer might accept Copilot suggestions, paste code from ChatGPT, delegate a task to Claude Code, or have an autonomous agent create a pull request. By the time that code reaches the repository, much of that provenance has been flattened into a human identity and a commit.”

Helps determine AI value

Wilkes and others said that unraveling the complexity of the code’s history will make a massive difference for a CIO trying to make funding and AI strategy decisions. 

“Reliable attribution lets CIOs finally measure agentic development rather than merely count AI licenses and token consumption,” Wilkes said. “We could compare human versus agent-assisted changes on cycle time, review effort, rework, defects, rollbacks and ultimately calculate cost per accepted change.”

Doing so, and organization might discover that agents produce 40% of its changes, but only

[…]
Content was trimmed to protect the source. Please visit the original article for the full text.

This article has been indexed from InfoWorld

Read the original article: