Slack AI
slack.com
Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.
- No visibility into AI supply chain
- Data retention window not stated
- Underlying model providers not named
See Before you sign, with what to ask for ↓
Scanned Sep 1, 2026 · Public evidence · Point-in-time
Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.
Before you sign
Why it matters: The public sources scanned give no visibility at all into which providers or subprocessors are involved in AI processing.
What to ask for: Do not proceed until the vendor discloses which providers and subprocessors are involved in AI processing.
Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.
What to ask for: Get retention windows, in days, in writing.
“global retention policies, legal holds and support for e-discovery. The security programme at Slack”
Why it matters: AI is used but the public sources scanned do not name which foundation models or providers sit in the request path.
What to ask for: Require named providers and model versions, plus notice before any model change.
Buyer questionsanswered only from the public evidence scanned — click a row for the answer
✓Will they train on your data?Clear
Slack states as a stated AI principle that customer data is never used to train large language models, naming messages and files specifically.
“Your data is never used to train large language models. Your customer data in Slack (like messages and files) is not used to train LLMs.”
!How long do they keep your data?Ask the vendor
Slack documents global retention policies, legal holds and e-discovery support as customer-configurable controls over how long content is kept.
Requires written confirmation — see Before you sign ↓
“global retention policies, legal holds and support for e-discovery. The security programme at Slack”
!Who else can access your data?Ask the vendor
Not found in the public sources scanned — ask the vendor directly.
!Where is your data processed?Ask the vendor
Data residency appears in Slack's compliance resource set as a named control area, indicating regional storage options are offered rather than a single global location.
Confirm in writing: Ask the vendor to state this in writing before signing.
“Data residency Data processing addenda”
!What happens in a security incident?Ask the vendor
Slack publishes an RFC 9116 security.txt naming its HackerOne programme as the contact and policy for reporting vulnerabilities, with a public acknowledgements page.
Confirm in writing: Ask the vendor to state this in writing before signing.
“Contact: https://hackerone.com/slack/ Acknowledgements: https://hackerone.com/slack/thanks Policy: https://hackerone.com/slack/”
Key findingsclick a row for the evidence
✓A stated AI principle that customer data never trains LLMsStrong
Slack publishes three AI principles, the first of which is that customer data is never used to train large language models, naming messages and files specifically rather than referring vaguely to "your data".
Slack carries an unusual amount of an organisation's unstructured internal conversation, so this is the question that decides whether Slack AI is adoptable at all. Naming messages and files removes the ambiguity most vendors leave in place.
Question for vendor: Please restate the no-training commitment contractually, covering any AI feature added after signature.
“Your data is never used to train large language models. Your customer data in Slack (like messages and files) is not used to train LLMs.”
✓AI is admin-controlled and permission-boundStrong
Admins can turn AI features on or off at any time, and Slack AI operates only on content the requesting user already has permission to view.
Together these support a staged rollout and remove the most common AI failure in a collaboration tool — surfacing content to someone who could not otherwise reach it. The permission inheritance matters more here than in most products, because Slack's private channels and DMs are exactly where the sensitive material sits.
Question for vendor: Do the permission rules apply identically to private channels, DMs and connected external channels?
“Workspace and organisation admins can turn AI features on or off at any time, giving customers full control over how AI is used.”
“Slack AI only works with content that you already have permission to view. For example, AI search answers will only include results that you could also find in a standard”
!Machine learning is used beyond the features labelled AIGap
Slack states it also uses predictive machine learning models for experience features such as emoji suggestions and name autocomplete, described separately from its LLM features.
The no-training commitment is scoped to large language models. Predictive ML on customer signals sits outside that wording, and an organisation switching AI features off may still be within scope of these models. It is a scope question, not an allegation — but it is the kind of gap a governance review should close in writing.
Question for vendor: Does the "never used to train" commitment extend to your predictive ML models, and can those be disabled?
“Your data is never used to train large language models. Your customer data in Slack (like messages and files) is not used to train LLMs.”
“We also use predictive machine learning models to help to make the Slack experience even better. When you see an emoji that you and your teammates have used recently in the emoji picker or an autocomplete suggestion to help to find the right person at your company with a common name, our ML models are responsible for the relevancy”
✓Certificates are offered for download, not merely listedStrong
ISO/IEC 27001, 27017 and 27018 each carry a download link, and SOC 2 and SOC 3 are stated alongside them.
Most vendors in this directory list certifications without publishing the certificate, which leaves scope unverifiable from outside. Offering the documents is the difference between a claim and something a buyer can check — though this collection captured the index rather than the certificates, so the scope statements are still unread.
Question for vendor: Do the ISO/IEC 27001 and 27701 scope statements name Slack AI?
“ISO/IEC 27001 Information Security Management System (ISMS) Download certificate ISO/IEC 27017 Security Controls for the Provision and Use of Cloud Services Download certificate ISO/IEC 27018 Protection of Personally Identifiable Information (PII)”
“We’ve received several security certifications from the American Institute of Certified Public Accountants such as SOC 2 and SOC 3”
!No model provider is named anywhere in the collected materialGap
Nothing in the sources scanned names which large language models or providers sit behind Slack AI, and no subprocessor register was retrievable in this collection.
The no-training commitment binds Slack, but a buyer cannot see whose models process their content, in which jurisdiction, or what changes when Slack swaps one. Slack has published elsewhere that its LLMs run inside its own AWS VPC, which would materially reduce this exposure — that page did not survive collection here, so it is unresolved rather than absent.
Question for vendor: Which model providers serve Slack AI, are the models hosted within your own infrastructure, and where is the subprocessor list?
“Your data is never used to train large language models. Your customer data in Slack (like messages and files) is not used to train LLMs.”
!Incident handling and change management are not addressed publiclyGap
Slack publishes a coordinated vulnerability disclosure route through HackerOne, but nothing in the collected sources covers breach notification timeframes or how customers are told when AI features or underlying models change.
These are ordinary contract schedule items rather than exotic asks. Their absence from the public material does not imply absence from a negotiated agreement, but they cannot be assessed from outside and should be requested directly.
Question for vendor: What are your breach notification timeframes, and how are customers notified of changes to AI features or models?
“GDPR CCPA Data residency Data processing addenda Global trade compliance FedRAMP”
“Read our white paper on compliance Read our transfer impact assessment”
“Contact: https://hackerone.com/slack/ Acknowledgements: https://hackerone.com/slack/thanks Policy: https://hackerone.com/slack/”
Assurance dimensionsweighted components of one score — not eight separate ratings
Organisation & AI governance15% of the score80
Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.
Assessed against ISO 42001 · NIST AI RMF · AIUC-1
“Workspace and organisation admins can turn AI features on or off at any time, giving customers full control over how AI is used.”
“we’ve set high standards for security. We’ve received several security certifications from the American Institute of Certified Public Accountants such as SOC 2 and SOC 3”
Governance & accountability: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.
AI system15% of the score13
What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.
Assessed against ISO 42001 · NIST AI RMF
“Slack AI only works with content that you already have permission to view. For example, AI search answers will only include results that you could also find in a standard”
“We also use predictive machine learning models to help to make the Slack experience even better. When you see an emoji that you and your teammates have used recently in the emoji picker or an autocomplete suggestion to help to find the right person at your company with a common name, our ML models are responsible for the relevancy”
How AI features are evaluated before and after release — evals, red-teaming, monitoring.
Assessed against NIST GenAI · NIST AI RMF · ISO 42001
How changes to models and AI features are controlled and communicated — versioning, notice, rollback.
Assessed against ISO 27001 · ISO 42001
Testing & evaluation: not publicly evidenced.
Change management: not publicly evidenced.
Model10% of the scoreorganisation-level evidence0
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
Which model providers and versions process customer data, and how changes to them are disclosed.
Assessed against NIST GenAI · ISO 42001
Model provider transparency: not publicly evidenced.
Customer data15% of the score80
Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.
Assessed against ISO 27018 · OAIC APPs · EU AI Act
“Your data is never used to train large language models. Your customer data in Slack (like messages and files) is not used to train LLMs.”
“Data residency Data processing addenda”
“global retention policies, legal holds and support for e-discovery. The security programme at Slack”
Customer data treatment: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.
AI supply chain10% of the scoreorganisation-level evidence0
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
The named chain of AI and infrastructure providers behind the product, and how it is disclosed.
Assessed against ISO 27001 · ISO 27017
Subprocessors & supply chain: not publicly evidenced.
Security foundation15% of the scoreorganisation-level evidence65
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.
Assessed against ISO 27001 · NIST AI RMF
“Contact: https://hackerone.com/slack/ Acknowledgements: https://hackerone.com/slack/thanks Policy: https://hackerone.com/slack/”
Independent assurance evidence10% of the scoreorganisation-level evidence100
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.
Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008
“ISO/IEC 27001 Information Security Management System (ISMS) Download certificate ISO/IEC 27017 Security Controls for the Provision and Use of Cloud Services Download certificate ISO/IEC 27018 Protection of Personally Identifiable Information (PII)”
“We’ve received several security certifications from the American Institute of Certified Public Accountants such as SOC 2 and SOC 3”
Read from the registry record above — cited, not reproduced.
Document held and reviewed by TrustyCyber — cited, not reproduced.
Document held and reviewed by TrustyCyber — cited, not reproduced.
Document held and reviewed by TrustyCyber — cited, not reproduced.
Document held and reviewed by TrustyCyber — cited, not reproduced.
Legal & contractual10% of the scoreorganisation-level evidence60
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.
Assessed against EU AI Act · OAIC APPs
“GDPR CCPA Data residency Data processing addenda Global trade compliance FedRAMP”
“Read our white paper on compliance Read our transfer impact assessment”
Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.
Not graded: Agent — not applicable to this scan.
What would strengthen assuranceeach figure is from today's score — resolving one changes the others
Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 65 → up to 81 with every identified gap resolved.
AI supply chainclick a node to focus it · drag to pan · zoom with the controls
View as list
What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0
This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.
Map your inherited responsibilitiesAssurance evidence: certifications 9 — registry checks and verification ladders, click to view
Scope covers the ISMS supporting Slack Technologies, LLC and its Team Collaboration Platform. It does NOT name Slack AI specifically, so this is platform-level coverage rather than product-scoped. Certified by Schellman Compliance, LLC; original registration 10 Nov 2017, issue date 8 Jan 2026.
Checked against ISO/IEC 27001:2022 certificate of registration published by Slack (Schellman Compliance, LLC, version 11), Sep 1, 2026: Verified on the registry
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Stated on the GDPR commitment page alongside SOC 3. No report or scope statement was available.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
The certificate's scope names Slack AI explicitly, so the AI management system certification covers the assessed product rather than only its parent. Issued by MSECB, certificate CERT-001117, certified since 2025-09-30.
Checked against ISO/IEC 42001:2023 certificate published by Salesforce/Slack (MSECB, certificate CERT-001117), Sep 1, 2026: Verified on the registry
Checked against FedRAMP Marketplace (fedramp.gov), Sep 1, 2026: Verified on the registry
27701 is carried as an extension of the same ISO/IEC 27001 certificate, in the role of a personally identifiable information processor. Platform-level, not scoped to Slack AI.
Checked against ISO/IEC 27701:2019 extension recorded on Slack's ISO/IEC 27001:2022 certificate (Schellman Compliance, LLC), Sep 1, 2026: Verified on the registry
Australian instance of the Slack Cloud platform, assessed at PROTECTED against the ISM (December 2025) under the ACSC framework Phase 1a. An IRAP assessment is not an authorisation - the letter states cloud consumers remain responsible for granting an Authority to Operate in their own environment.
Checked against IRAP Letter of Assessment published by Slack (CyberCX, 26 May 2026), Sep 1, 2026: Verified on the registry
Sources 21 — click to view
Appendix: standards landscape 8 — click to view
Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.
This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.
