I know the issues with the AT&T version are very similar to the Verizon version (which I have), but I'm not completely familiar with AT&T's. The Verizon version does have an "unroot" method, so I would assume the AT&T one does as well...but I'm honestly not sure if the factory images are available to allow it or not.
The bootloader issue has not been resolved for phones with the latest update (ME7)...root can be achieved, but no custom recovery, which means no ROMs (which, to relate to the original post of this thread, means no CM). There is some
new dual boot option worked on, but I'm not sure if that's ready for prime time just yet.
The actual process to root can be found here:
[STICKY] How to Root Your Verizon Galaxy S4 MDK or ME7 - xda-developers
Again, this will let you run apps that require root, like Titanium backup, and remove bloatware and such, but you won't be able to flash ROMs or anything like that.
If you ever needed to "unroot" you could just flash the ME7 factory image:
[LINK][ODIN][TAR][VZW] SCH-I545 VRUAME7 Factory Image - xda-developers