Slack, workplace information and AI
Research date: 4 October 2026
Edition: First baseline report
Method: Review of Slack’s public documentation. No signed-in business workspace was inspected and no controls were tested in a live account.
Summary
Slack’s AI can help staff find information, catch up on conversations and reduce routine work. Its reach can extend beyond messages into connected business systems.
- By default: The report identifies background recommendations and autocomplete, but does not establish a universal default for the generative features. Availability depends on subscription and administrator settings.
- Beyond the default: Conversation and file summaries, search answers, daily recaps, translations, writing assistance, huddle notes, Slackbot and AI steps inside workflows.
- Outside Slack: Connected search can retrieve information from email, document storage, project systems and Salesforce. Slackbot can use web search where permitted. Workflow outputs can feed subsequent steps that distribute information or perform connected operations.
- Business exposure and learning: Native AI can process private channels and direct messages the requesting employee is permitted to access. Huddle notes create a shareable record that people who missed the meeting may still read. Slack says customer data is excluded from generative-model training unless customers opt in; global predictive-model development has a separate opt-out. Third-party apps have their own terms.
The main exposure: Information scattered across Slack and connected systems becomes easier to retrieve, combine and distribute through an employee’s existing access.
Business finding
Slack has documented controls for its built-in AI features, but switching them off is only one part of the assessment. A business should also review connected information sources, automated workflows, installed apps and use of its data for predictive models.
Slack’s commitment about generative AI training is different from its arrangements for global prediction models. Its future-feature setting also has an exception for Slackbot developments. These distinctions matter because a business can make a decision today and still need to check what becomes available later.
Where is AI operating?
Slack’s built-in tools include conversation summaries, huddle notes, search answers, daily recaps, file summaries, translations, message explanations and content generation. Slackbot is described as a personal AI agent. Availability depends on subscription, role and administrator choices; legacy subscriptions can differ. [1]
The information involved can extend beyond public channels. Slack says AI responses can include content a person can access in private channels and direct messages. Connected sources can also supply information. A private channel is therefore not automatically an AI-free channel. [1]
Huddle notes process the live conversation and its message thread, producing notes and a transcript in a canvas. That turns a spoken discussion into a record available after the conversation. [5]
Workflow Builder offers two distinct uses: AI can help design a workflow, or an AI step can operate within the workflow after publication. A generated workflow can also contain ordinary automated steps. [6]
Separately, Slack describes predictive models for functions such as recommendations and autocomplete. These are different from the generative tools that write summaries or answer questions. [7]
The benefits include faster retrieval, easier catch-up and less routine work. The business should identify which benefit it actually needs before enabling access to more information or automating a process.
Who controls it?
Owners and administrators manage built-in AI access, with subscription-dependent choices. Primary owners control automatic access to future AI features. [2]
Enterprise search also needs organisation-level configuration and individual account connections. Slack says some Google Drive or Microsoft connections can enable or connect relevant search sources automatically. Do not assume every connection started with a fresh AI-specific approval. [3][4]
Anyone participating in a supported huddle can stop or cancel its AI notes. Channel members may also configure automatic notes where administrators permit this. [5]
The business should identify its primary owner, administrator, workflow managers and app owners. An employee using a customer’s or supplier’s workspace cannot assume their own employer controls that workspace’s settings. Obtain the relevant choices from the workspace owner before sharing information that requires particular restrictions.
What can the business switch off?
Built-in AI features
Open Admin → Workspace settings → Roles & permissions → Feature access → AI, edit each feature, select No one and save. Enterprise organisations instead enter through Tools & settings → Organisation settings, then the same permissions area. [2]
Future AI features
The primary owner can edit Future AI feature releases and clear Always allow access to new AI features. Enabled Slackbot receives new functionality automatically despite this choice, with separate controls for some functions. [2]
Huddle notes
During a desktop huddle, use AI notes: On → Stop AI notes to pause. To cancel and delete the notes and transcription, use Delete AI notes & transcription → Delete and cancel. Stopping temporarily and deleting are separate choices. [5]
For channel automatic start, open channel name → Settings → AI huddle notes → Edit and clear the automatic-start option. Check administrator restrictions as well as channel choices. [5]
Enterprise search sources
Organisation administrators can open Tools & settings → Organisation settings → Settings → Enterprise search to disable enterprise search or adjust sources. Source controls can exclude information from AI answers while retaining traditional search, where configured. [3]
An individual can disconnect a source through search results → Manage Apps → source → Manage → Disconnect. This is a personal connection choice, rather than proof that the organisation has removed every use of that source. [4]
Workflows and installed apps
Inspect published workflows and installed applications separately. Turning off an AI drafting tool does not establish that an already published automation has stopped. Review triggers, steps and permissions, then disable or amend the actual process that the business wants to stop.
What information and actions can the business restrict?
Start with the underlying permissions. Slack says native AI uses information the requesting member can already access and does not expose private channels or direct messages they cannot access. [8]
That makes existing access important. If too many employees can read a sensitive channel or connected folder, permission-respecting AI can still make its contents easier to find and combine. Review memberships and source-system permissions before treating the AI permission boundary as sufficient.
AI feature settings include choices concerning files, response sharing, workflow connectors, Slackbot web search and canvas changes. Search answers and Slackbot share a file-access setting. [2]
For enterprise search, review each source and who may use it. Slack lists sources including email, document storage, project systems and Salesforce. A configured Salesforce connection can make Salesforce available as a search source automatically. [3]
For workflows, distinguish information used to produce an answer from the steps that distribute or act on it. Slack documents AI steps using selected files or channels and passing outputs into subsequent workflow steps. Review the entire workflow, including its audience, rather than only the AI prompt. [6]
Huddle notes need an audience check too. Slack says people in the channel or direct message can view the resulting canvas, which can be shared. They need not all have attended the huddle. [5]
Finally, distinguish temporary answers from saved records. Slack describes conversation summaries and search answers as temporary, recaps as retained for 90 days, and workflow summaries posted to messages or canvases as subject to normal retention settings. [8]
Can the business refuse use of its information for AI training?
Slack’s privacy principles say customer data is not used to train generative AI models unless the customer affirmatively opts in. Its native-AI security guidance also says customer data is not used to train third-party language models. [7][8]
Global predictive-model development has a separate opt-out. Slack instructs an organisation or workspace owner to email [email protected], include the workspace or organisation URL, and use the subject Slack global model opt-out request. Slack says it responds when the opt-out is complete. This report provides the procedure; no email was sent. [7]
Slack says opting out still permits improvement within the customer’s own workspace and access to the benefits of its globally trained models. This is not a promise that all analysis of workspace information stops. [7]
Third-party AI apps require their own terms. Do not extend Slack’s native-AI training commitment to every application installed in Slack or every external service employees connect. Record which provider handles the information and which contract covers that route.
The business should therefore keep feature restrictions, the global-model opt-out and external-provider terms as separate evidence. A favourable answer about training does not settle access, inference, retention or automated actions.
How can the business check that its choices worked?
These are proposed business checks, not tests performed for this report:
- Record the actual subscription, legacy arrangements, workspaces, primary owner, administrator and employees covered by the decision.
- Save AI feature restrictions, reopen them and check an ordinary employee account. Verify the future-feature choice and Slackbot separately.
- Use harmless messages and files to test the specific restrictions: summaries, file answers, connected searches and workflow steps. Record the results rather than relying on an absent button.
- Run a fictional huddle. Check the activation notification, stopping and deletion controls, automatic-start behaviour and who can view the resulting canvas.
- Test retrieval permissions with one account permitted to access fictional source material and another without permission. Check connected systems as well as Slack channels.
- Inspect installed apps and published workflows for continuing data access or activity. Check what happens after a source or application is disconnected, including historical outputs.
- If requesting the global-model opt-out, retain Slack’s completion response. A sent email is evidence of the request, not completion.
- Check retained recaps, messages and canvases against the business’s chosen record requirements. Identify what can be deleted, exported or kept as evidence.
These checks establish saved settings and observable behaviour. They do not independently verify internal model training or every provider processing operation. Ask Slack or the external provider for clarification where a required result cannot be demonstrated.
What does the business lose, retain or need to replace?
Restricting optional built-in AI removes the relevant summaries, answers, assistance or automated AI steps. It does not itself amount to cancelling Slack. Confirm the remaining messaging, search and workflow functions in the actual subscription before changing an essential process.
Replace automated catch-up with a maintained decision log and clear action owners. Replace AI huddle notes with an assigned minute-taker where a record is necessary. If a workflow is stopped, assign somebody to the underlying task so it does not disappear along with the automation.
Where AI remains enabled, check important answers against the original messages or documents. Slack’s responses can include source citations. [8] A summary can still omit a condition, confuse a suggestion with an agreement or report an old decision as current. Human review should establish what was actually agreed before the answer directs work or reaches a customer.
The practical benefit of these controls is selective use: the business can retain useful assistance while limiting the information and activities involved. It should judge success by accurate decisions, useful time savings and dependable completion of work, rather than the volume of summaries produced.
Control assessment
| Business requirement | What this review establishes | Remaining limit |
|---|---|---|
| Restrict built-in AI access | Administrator controls exist. [2] | Subscription, groups and actual saved settings need verification. |
| Prevent automatic future access | A future-release preference exists. [2] | Slackbot developments have an explicit exception. |
| Control spoken-meeting records | Participants can stop or cancel supported huddle notes. [5] | Check automatic start, sharing and saved canvases. |
| Restrict connected information | Enterprise source and individual connection controls exist. [3][4] | Source permissions and automatic connections need review. |
| Stop AI-driven processes | AI steps are identifiable within workflows. [6] | Inspect published processes and downstream steps separately. |
| Refuse global predictive-model contribution | An owner-requested opt-out is documented. [7] | Obtain completion confirmation; local improvement remains. |
| Exclude external AI apps from training | Not established by Slack’s native commitments. | Assess each installed provider and connection. |
Official sources
[1] Guide to AI features in Slack.
[2] Manage access to AI features in Slack.
[3] Set up and manage Slack enterprise search.
[4] Search across your applications with enterprise search.
[5] Use AI to take huddle notes in Slack.
[6] Use AI to build Slack workflows.
[7] Privacy principles: search, learning and artificial intelligence.
[8] Security for AI features in Slack.
Scope and continuing research
This baseline covers native AI, predictive-model choices, enterprise search and selected workflow behaviour. It does not certify a workspace or assess every external app, agent, Slack Connect arrangement or connector permission.
The next update should prioritise subscription changes, Slackbot functionality, future-feature exceptions, source access, retained AI records and global-model opt-out terms. A provider’s published permission boundary does not establish that the business’s own permissions are appropriate or that its controls have been tested.