← All case files
pending deployment tech · US · marketing

After a user backlash, Slack updated its AI 'privacy principles' over training ML models on customer data (May 2024)

In May 2024 a Hacker News thread surfaced Slack's published 'privacy principles', which disclosed that Slack analyzes customer messages, content and files to develop AI/ML models on an opt-out-by-default basis, escapable only by email. After a privacy backlash (TechCrunch and SecurityWeek, 17 May 2024), Slack publicly updated the principles' language on 17 May 2024 and stated that it does not develop the large language models or other generative models behind its Slack AI product using customer data. This is an AI-data/terms walk-back — a language clarification, not a confirmed reversal of the opt-out-by-default ML-training practice — carried first-party by Slack's blog plus four independent newsrooms.

What happened

In mid-May 2024 a Hacker News thread surfaced the wording of Slack’s published “privacy principles” (overhauled in 2023). The Register quoted the clause that set off the backlash verbatim: “To develop AI/ML models, our systems analyze Customer Data (e.g. messages, content and files) submitted to Slack” (source). The escape hatch was opt-out-by-default and buried. TechCrunch reported that “Slack opts users in by default to its AI training, and that you need to email a specific address to opt out” (source). SecurityWeek’s summary was blunter: Slack “reveals it has been training AI/ML models on customer data, including messages, files and usage information. It’s opt-in by default” (source).

The walk-back

Slack responded on 17 May 2024 by publicly updating the principles’ language. On its own blog it wrote: “Today, we updated those principles to more clearly explain how Slack protects customer data while providing both ML and generative AI experiences in Slack” (source). Slack drew a distinction between two classes of model. For the large language models in its add-on Slack AI product it stated: “we do not develop LLMs or other generative models using customer data” (source). For its traditional (non-generative) machine-learning “global models” — channel and emoji recommendations, search — de-identified customer data is used on an opt-out basis, and “Customers can email Slack to opt out of training non-generative ML models” (source).

Independent press confirmed the update. The Register reported that Slack “has now updated the principles” to “better explain the relationship between customer data and generative AI in Slack” (source). Computerworld reported the change came “in response to concerns about the use of customer data to train its generative AI (genAI) models,” and that “To opt out, the Slack admin at a customer organization must email the company to request their data is no longer accessed” (source).

What this is — and isn’t

This is a language / policy-communication walk-back, not a confirmed reversal of the underlying practice. The reporting consensus is that Slack clarified how it describes its use of customer data and reaffirmed that its generative-AI product is not trained on customer content — but on this record it did not stop using de-identified customer data to train its non-generative ML “global models,” and the opt-out remained email-only (source). The account above restates only what Slack and the cited newsrooms put on the record.

Weakest load-bearing source. The only Tier-1 source here is Slack’s own blog — the first-party ORIGIN, and also the subject of the story — which carries the walk-back statements but cannot independently corroborate itself. Every independent confirmation of both the triggering clause and the update rests on Tier-2 newsrooms (The Register, Computerworld, TechCrunch, SecurityWeek); there is no independent primary or regulatory record. And no cited source states that the opt-out-by-default non-generative ML training actually stopped — only that the wording was clarified — so the page claims a language change, not a practice reversal.

How this was verified

  • Method: Every quoted clause was bound verbatim to a Wayback capture of the cited source. Slack’s first-party blog (capture 20240519170508), The Register (20240520112428), Computerworld (20240520210137), TechCrunch (20240517151053) and SecurityWeek (20240517191326) were each decoded and searched for the exact quoted strings this session; all bind (the Slack blog’s “updated those principles” sentence is interrupted only by an in-line <a> link on the word “principles”). First-party origin (Slack) is not counted toward independent corroboration — the four Tier-2 newsrooms are.
  • Date verified: 2026-08-18.
  • Ceiling / what green needs: This page is held at amber pending. Green would require an on-the-record Slack/Salesforce confirmation (Corporate Communications / Legal) of the exact before/after wording, whether any substantive practice — not just the language — changed, and whether opt-out stayed email-only. Green never depends on Slack confirming its own account as testimonial; it depends on the public record. No numeric outcome is claimed.

Sources

  1. Slack · “How Slack protects your data when using machine learning and AI” · 2024-05-17 · Tier 1 (first-party primary; capture 20240519170508) · https://slack.com/blog/news/how-slack-protects-your-data-when-using-machine-learning-and-ai
  2. The Register (Thomas Claburn) · “Users upset by Slack using customer data in model training” · 2024-05-20 · Tier 2 (independent newsroom) · https://www.theregister.com/2024/05/20/slack_ts_and_cs_update/
  3. Computerworld · “Slack updates AI ‘privacy principles’ after user backlash” · 2024-05-20 · Tier 2 (independent newsroom) · https://www.computerworld.com/article/2114741/slack-updates-ai-privacy-principles-after-user-backlash.html
  4. TechCrunch (Ingrid Lunden) · “Slack under attack over sneaky AI training policy” · 2024-05-17 · Tier 2 (independent newsroom) · https://techcrunch.com/2024/05/17/slack-under-attack-over-sneaky-ai-training-policy/
  5. SecurityWeek (Kevin Townsend) · “User Outcry as Slack Scrapes Customer Data for AI Model Training” · 2024-05-17 · Tier 2 (independent newsroom) · https://www.securityweek.com/user-outcry-as-slack-scrapes-customer-data-for-ai-model-training/

Slack 'privacy principles' — Search, Learning and Artificial IntelligenceTraditional (non-generative) ML 'global models' (channel/emoji recommendations, search)Slack AI add-on product (third-party large language models)

Verification record
Status
pending
Method
Byte-tied Wayback captures of Slack's first-party blog (2024-05-19) plus four independent newsrooms — The Register (2024-05-20), Computerworld (2024-05-20), TechCrunch (2024-05-17) and SecurityWeek (2024-05-17). Every load-bearing quote was decoded and bound verbatim in the specific capture it is attributed to this session.
Provider
Slack Technologies (Salesforce)
Client
Slack Technologies (Salesforce) · Enterprise workplace collaboration software; AI/data privacy principles
Disclosure
named