Slack AI
low riskGenAI Assistantslack.comverified 2026-06-27profile 93% complete
Data-handling profile
- Trains on input
- No — does not train on customer inputs
- Retention
- Slack does not use Customer Data (messages, files) to train generative AI/LLMs without affirmative opt-in consent; uses RAG so LLM providers never retain data; separately, legacy non-generative ML features (e.g., emoji/channel recommendations) analyze customer data by default with an opt-out available via support request.
- Data region
- US
- Certifications
- SOC 2 Type IIISO 27001
- DPA available
- Yes
- Breach history
- none known for Slack AI specifically (Slack faced 2015 credential breach of user profile data, unrelated to AI features)
- EU AI Act
- Embedded GenAI assistant inside core collaboration product; limited-risk transparency obligations apply; 2024 public controversy over ambiguous ToS language prompted clarified policy in April 2025.
By plan and surface
Vendor-level answers are often wrong for a specific tier. These are the precise claims, each with the verbatim sentence we relied on.
| Plan | Surface | Trains | Opt-out default |
|---|---|---|---|
| unknown | unknown | unknown | opted_in |
- unknown/unknown: “To opt out, please have your Org or Workspace Owners or Primary Owner contact our Customer Experience team at feedback@slack.com with your Workspace/Org URL and the subject line “Slack Global model opt-out request.” We will process your request and respond once the opt out has been completed.”
Sources
- https://slack.com/trust/data-management/privacy-principles
- https://slack.com/help/articles/28310650165907-Security-for-AI-features-in-Slack
- https://slack.engineering/how-we-built-slack-ai-to-be-secure-and-private/
Every fact above is drawn from the vendor's public documentation, reviewed by a human, and version-stamped. Monitored daily for changes.
Control mapping
Obligations this vendor triggers, each attributable to the fact it rests on — for your supplier register, not a compliance determination.
- EU AI Act Art. 50 — Transparency obligations for AI systemsok
trains_on_input = no. Vendor states inputs are not used for training.
- EU AI Act Art. 26 — Obligations of deployers of high-risk AI systemsapplies
Applies to your organisation as deployer, independent of vendor. Assign human oversight, keep logs, and monitor operation where this tool is used in a high-risk context (Annex III duties apply from 2 Dec 2027).
- ISO/IEC 27001 A.5.19 — Information security in supplier relationshipsapplies
Slack AI processes organisational data as a supplier. Include this vendor in the supplier register and risk assessment.
- ISO/IEC 27001 A.5.20 — Addressing information security within supplier agreementsok
dpa_available = true. A data processing agreement is available and should be executed.
- ISO/IEC 27001 A.5.23 — Information security for use of cloud servicesapplies
Cloud AI service; trains_on_input = no. Define acceptable-use and configuration rules for this cloud service.
- ISO/IEC 42001 A.10.3 — Suppliers of AI systems and servicesapplies
certifications: SOC 2 Type II, ISO 27001 No AI-management certification identified; assurance must come from your own supplier assessment.
- GDPR Art. 44–49 — International transfers of personal dataattention
data_region = US. Processing occurs outside the EU/EEA — a transfer mechanism (SCCs or adequacy) must be in place.
- NIS2 Art. 21(2)(d) — Supply chain securityapplies
AI vendor forms part of your ICT supply chain. In scope for entities covered by NIS2; include in supply-chain risk measures.
- DORA Art. 28 — General principles for ICT third-party riskapplies
AI vendor is an ICT third-party service provider. For financial entities: register of information and contractual requirements apply.
Change history
No material changes recorded since monitoring began.