AI & Technology

Slack tells teams to treat private channels as an AI agent blind spot

Written by
Full Name
August 25, 2026
Slack’s chief product officer, Jaime DeLanghe, has told organisations to default their channels to public because AI agents cannot read direct messages, putting the candid part of marketing work on the wrong side of the line vendors now want drawn.

Slack has put a name to the thing its agents cannot see. On 19 August, chief product officer Jaime DeLanghe set out a set of working practices for teams that share their work with AI agents, and told organisations to keep channels public unless there is a specific reason to gate them. Her stated reason was blunt: “a private channel is a blind spot for every agent that reports on it”.

The advice arrives as agent deployment runs well ahead of the context those agents can reach. Slack said in March that the number of custom agents built on its platform had grown more than 300% since January, and counted 2,600 pre-configured apps and agents available at that point. None of them can read a direct message they are not party to. The remedy on offer is behavioural: move the conversation to where the agent can already reach it.

Executives have started acting on that logic. The Wall Street Journal reported on 25 August that they are urging staff to post in public channels rather than message colleagues privately, so that agents crawling a workspace can reach updates on products, earnings and strategic plans. The article is paywalled and The Marketing Helm was unable to verify independently the executives it cites.

What did Slack’s product chief actually tell organisations to do?

DeLanghe’s guidance is narrower than the instruction executives are reported to be issuing. Published as an interview on Anthropic’s Claude blog, the second in a series on human-agent teams, it sets out four working habits: treat conversation history as a knowledge base, default shared channels to public, pass work back and forth between agents and people in defined handoffs, and give each agent a role narrow enough that colleagues can say what it is for.

The public-channel item comes with a condition attached. DeLanghe, who joined Slack in 2017 to work on search and machine learning and now runs product, argues that channels should stay public unless there is a specific reason to gate the context, and that genuinely sensitive material should be walled off first. Once that is done, she says, the main reason work retreats into direct messages is not secrecy but discomfort at being watched mid-process, and she puts psychological safety forward as the test for where the remaining line falls.

That is a materially different instruction from “stop using DMs”. It concedes that some categories of work belong in a small room, and it makes the size of that room a judgement for the team rather than a setting for the agent. Slack has published the reasoning; it has not published a list of which categories qualify.

Why do AI agents need public channels at all?

Permission is the constraint, not capability. Slack’s own position, set out in a March post on building an agent-first workspace, is that an agent is only as good as the data it can access, and that generic answers are what teams get when the model has no view of what was decided and why. The company’s Real-Time Search API and its Model Context Protocol support give agents scoped access to Slack conversations, subject to the permissions of whoever is asking.

Those permissions are the point. Third-party agents inherit them too, as they did when Anthropic put a shared Claude into Slack channels in June under administrator-scoped access. Slack’s published policy states that its AI features draw only on data a member already has access to when a request is made, and do not use private channels or direct messages the requester is not part of. Salesforce, which bought Slack in 2021, also says customer data is not used to train large language models, and that agents retrieve context rather than being trained on it. An agent, in other words, inherits the reach of the person running it. A direct message is invisible to it by membership, not by encryption.

The scale of deployment explains why the question is live now. Slack’s Workforce Index, fielded among 5,156 desk workers in Australia, France, Germany, Japan, the UK and the US between 9 April and 1 May 2025, found 52% of executives saying their companies had already implemented AI agents, with a further 38% planning to by the end of that year. Two in five desk workers had used an agent chatbot and 23% had directed one to complete work on their behalf. Gartner expects task-specific agents to feature in 40% of enterprise applications by the end of 2026, against under 5% a year earlier, a forecast Slack cites in its own material.

What does a public-by-default push cost a marketing team?

Marketing teams do a large share of their most useful work in the register that public channels discourage. Campaign post-mortems, honest assessments of an agency’s output, pricing discussed before it is announced, competitor positioning, and the first rough version of a message that has not survived contact with anyone yet: these conversations happen in direct messages because half-formed criticism is easier to give when three people can see it than when four hundred can. Moving them does not make an agent smarter about the campaign. It makes the criticism quieter.

The reluctance is not a refusal to work with AI. StackAdapt research published on 19 August found marketers’ comfort with the technology holding at 78% when it acts inside rules a human has set and falling to 50% when it acts alone, which describes a profession that will delegate readily and wants to keep hold of the terms. The documentation discipline behind the request is not new to marketers, and it is not where the difficulty sits. Teams already keep briefs, decision logs and campaign retrospectives, and a channel-first workspace makes those easier for a new starter or an agent to reconstruct. What is being asked for on top of that is a change in the room the work happens in, and the case for it rests on the agent’s convenience rather than on the marketer’s judgement. DeLanghe’s own framing, sensitive material walled off first and psychological safety deciding the rest, is the more defensible version, and it carries the weight of coming from the platform owner rather than from a productivity memo.

That distinction gives a marketing manager something concrete to hold in the meeting where an executive asks the team to abandon private messages. The platform’s guidance does not say everything should be visible. It says decisions and their reasoning should be recoverable, which is a different requirement and one a team can meet without narrating every doubt in the open. The alternative on offer is a workspace where the record is complete and the candour has moved to a channel the company cannot see at all.

Slack has not published guidance on which categories of work should remain private, and the WSJ report names no company policy setting that line in writing.

Subscribe to our newsletter

By subscribing you agree to with our Privacy Policy
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Share article

Recommended Reading