Slack AI
low riskGenAI Assistantslack.comverified 2026-06-27
Data-handling profile
- Trains on input
- No — does not train on customer inputs
- Retention
- Slack does not use Customer Data (messages, files) to train generative AI/LLMs without affirmative opt-in consent; uses RAG so LLM providers never retain data; separately, legacy non-generative ML features (e.g., emoji/channel recommendations) analyze customer data by default with an opt-out available via support request.
- Data region
- US
- Certifications
- SOC 2 Type IIISO 27001
- DPA available
- Yes
- Breach history
- none known for Slack AI specifically (Slack faced 2015 credential breach of user profile data, unrelated to AI features)
- EU AI Act
- Embedded GenAI assistant inside core collaboration product; limited-risk transparency obligations apply; 2024 public controversy over ambiguous ToS language prompted clarified policy in April 2025.
Sources
- https://slack.com/trust/data-management/privacy-principles
- https://slack.com/help/articles/28310650165907-Security-for-AI-features-in-Slack
- https://slack.engineering/how-we-built-slack-ai-to-be-secure-and-private/
Every fact above is drawn from the vendor's public documentation, reviewed by a human, and version-stamped. Monitored daily for changes.
Change history
No material changes recorded since monitoring began.