Tython

AISalesforceSecurityCompliance

Your Salesforce Data Is Training AI Models Right Now. Here's How to Stop It.

Scott Covert · 

In previous posts on the Tython blog, we’ve focused on threats from outside your Salesforce org–third-party access risk, deployment pipeline gaps, and permission misconfigurations. This week, the risk is coming from the platform itself.

A setting that surfaced in Salesforce’s Spring ’26 release has brought renewed attention to a practice that’s been in effect for years: Salesforce uses customer data from your org to train global predictive AI models. This isn’t a new capability. It’s been part of the Main Services Agreement (MSA) since at least 2018. What’s new is that Salesforce has finally made it visible–and disableable–through a toggle in Setup, rather than requiring a support case. The community reaction has been sharp, and it should be.

What’s Happening

If your org hasn’t explicitly opted out, Salesforce may be using your customer data to:

  • Train global predictive AI models (Einstein-related features)
  • Improve services and features you have access to
  • Conduct research and development for new features

This applies to predictive AI models only. Salesforce has stated that generative AI features, including Agentforce, do not use global models trained on customer data, and that their zero-data-retention policy with third-party LLMs remains in effect.

The key detail: this is enabled by default. Unless your org is on Government Cloud or previously submitted a support case to opt out, your data has been eligible for use in global model training.

How to Opt Out

As of Spring ’26, Salesforce has added a self-service toggle in Setup. Navigate to the Einstein data sharing settings and disable customer data sharing. The setting applies org-wide–it cannot be configured per user or per feature. Once disabled, no new data will be shared, and Salesforce states that previously collected data is deleted within 30 days.

Previously, opting out required logging a case with Salesforce Support. The toggle is an improvement in visibility, but the default-on posture remains the core issue.

The Slack Problem

This isn’t limited to Salesforce core. Slack–owned by Salesforce–uses customer data to train its machine learning models by default. These aren’t generative AI models, but they are trained on workspace data including messages and content from channels.

The opt-out process for Slack is worse. There is no toggle. Workspace Owners or Primary Owners must send an email to [email protected] with the subject line “Slack Global model opt-out request” and include the Workspace or Org URL. That’s the only mechanism. There is no in-app setting, no admin console option, and no notification that the training is occurring.

Opting out of Slack’s model training stops future data use but does not delete data Slack has already collected.

Why This Matters for Security Teams

The security concern isn’t that Salesforce or Slack are acting maliciously. It’s the default posture and the governance gap it creates.

  • If your organization is subject to GDPR, HIPAA, CCPA, or industry-specific data handling requirements, your customer data flowing into third-party model training pipelines may create compliance exposure you haven’t accounted for.
  • If your org contains sensitive business data–pricing, deal terms, customer PII, health records, financial data–that data has potentially been included in aggregate training datasets unless you explicitly opted out.
  • The opt-out model means the burden is on the customer to discover and disable a default they were never clearly notified about. Most orgs haven’t done this because most orgs didn’t know they needed to.

What to Do Now

  1. In Setup, search “Opt Out” or “Customer Data,” click “Opt Out of Customer Data Access,” and check the current state. If it’s enabled, decide whether your organization’s data governance policies permit it. If not, disable it.
  2. Determine whether your Slack workspace has opted out of global model training. If you don’t know, the answer is almost certainly no. Have your Workspace Owner email [email protected] to submit the opt-out request.
  3. Review your organization’s MSA with Salesforce. Understand what data use rights you’ve agreed to and whether those align with your internal data governance and regulatory obligations.
  4. Document the decision. Whether you opt out or consciously decide to leave it enabled, the decision should be recorded in your security governance documentation, not left to the default.

Deeper Dive

The practice of using customer data for model training isn’t a loophole. It’s explicitly authorized in Salesforce’s Main Services Agreement. The relevant language has been present since at least 2018, predating the current AI boom by several years. Under the MSA, Salesforce reserves the right to use customer data to train global predictive AI models, improve services and features, and conduct research and development.

This means every Salesforce customer who signed a standard MSA agreed to this. The issue isn’t legality–it’s visibility. Until Spring ’26, there was no self-service way to see whether your org was opted in, and no way to opt out without filing a support case. Most customers either didn’t know the clause existed or assumed it didn’t apply to their org.

Salesforce has emphasized that this data use is subject to their existing confidentiality and security commitments. Data is anonymized and de-identified before being aggregated into training datasets. But “anonymized and de-identified” is a spectrum, not a binary, and the sufficiency of de-identification depends on the nature of the data. An org with 50 records of a rare medical condition may not be meaningfully anonymized by stripping names and emails.

What “Predictive AI” Means in This Context

Salesforce draws a clear distinction between predictive and generative AI, and that distinction matters here.

Predictive AI in Salesforce refers to Einstein features that make predictions based on patterns in data: lead scoring, opportunity insights, case classification, send time optimization in Marketing Cloud. These features use machine learning models–some trained on individual org data (local models), some trained on aggregated data from multiple orgs (global models).

Global models are the ones relevant to this discussion. When Salesforce trains a global model, it aggregates anonymized data from participating orgs to build a model that can make predictions across the entire customer base. The premise is that patterns in one org’s data can improve predictions for another org. The tradeoff is that your data contributes to a model you don’t control and can’t inspect.

Generative AI features–including Agentforce, Einstein Copilot, and any feature powered by third-party LLMs–are explicitly excluded from this data sharing. Salesforce maintains a zero-data-retention policy with third-party LLM providers (OpenAI, Anthropic, etc.), and these features do not use global models trained on customer data. This distinction is important because it means the opt-out decision applies specifically to Einstein’s predictive capabilities, not to the entire AI stack.

Finding the Toggle in Setup

The Spring ’26 release added a self-service toggle for managing Einstein data sharing. To locate it:

  1. Navigate to Setup in your Salesforce org.
  2. Search for “Opt Out” or “Customer Data” in the Quick Find box.
  3. Click “Opt Out of Customer Data Access.”
  4. The toggle controls whether your org’s customer data is shared with Salesforce for global model training.

The setting is org-wide. When disabled, it applies to all users and all Einstein predictive features uniformly. There is no per-user or per-feature granularity.

When you disable the toggle:

  • No new data will be shared with Salesforce for model training purposes.
  • Data that has already been collected is retained for up to 30 days before deletion.
  • Your org can still use Einstein predictive features, but they will rely on org-specific models trained solely on your data rather than global models.
  • The opt-out does not affect generative AI features or Agentforce.

If your org had previously opted out via a support case, the toggle should already reflect that. If it doesn’t, verify with Salesforce Support.

The Slack Data Training Problem in Detail

Slack’s use of customer data for machine learning model training has been known since at least May 2024, when security researchers flagged the practice and it became a public controversy. Despite the backlash, the fundamental mechanics haven’t changed.

What Slack Uses

Slack trains machine learning models that power platform features like channel recommendations, search result ranking, emoji suggestions, and autocomplete. These are traditional ML models, not generative AI. Slack has stated explicitly that customer data is not used to train LLMs or generative models, and that its add-on Slack AI product uses third-party LLMs with no customer data used for training.

The training data comes from workspace activity. Slack states it uses “de-identified, aggregate data” and does not access message content in DMs, private channels, or public channels for global model training. However, metadata about usage patterns, channel activity, and interaction behaviors is included.

Why the Opt-Out Process Is a Problem

The only way to opt out of Slack’s global model training is to have a Workspace Owner or Primary Owner send an email to [email protected] with:

  • Subject line: “Slack Global model opt-out request”
  • The Workspace or Organization URL

There is no toggle in admin settings. There is no API endpoint. There is no notification to workspace administrators that training is occurring. The opt-out request is processed manually by Slack’s team.

This process creates several governance problems:

  • Discovery: administrators have to know the policy exists to opt out. There is no in-product notification.
  • Authority: only Workspace Owners or Primary Owners can submit the request. In large organizations, identifying who holds this role–and getting them to send an email–introduces friction.
  • Verification: there is no way to confirm the opt-out has been processed other than waiting for Slack’s confirmation email.
  • Scope: opting out stops future model training but does not delete data already collected.
  • Consistency: an organization using both Salesforce and Slack must manage opt-outs through two completely different mechanisms with different processes and different administrators.

The Broader Salesforce Ecosystem Exposure

If your organization uses Salesforce and Slack, you have two separate data-sharing defaults to manage through two different opt-out mechanisms. If you also use Marketing Cloud, Commerce Cloud, or other Salesforce products, the data sharing policies and opt-out processes may differ further. The lack of a unified data governance surface across the Salesforce ecosystem means that each product’s data sharing posture has to be investigated and managed independently.

Compliance Implications

GDPR

Under GDPR, using personal data for a purpose beyond what was originally collected requires a lawful basis. Salesforce argues that model training is covered by the MSA (contractual basis). Whether your Data Protection Officer agrees depends on whether your DPA with Salesforce explicitly contemplates this use, whether the anonymization is sufficient under GDPR’s standards, and whether your data subjects were informed. If you process EU personal data in Salesforce and haven’t evaluated this, it’s worth a conversation with your legal team.

HIPAA

If your Salesforce org contains Protected Health Information (PHI) and you have a BAA with Salesforce, the use of PHI for model training outside the purposes specified in the BAA could be a compliance issue. Salesforce’s Government Cloud orgs are excluded from data sharing by default, but standard commercial orgs with healthcare data are not.

CCPA/CPRA

The California Privacy Rights Act gives consumers the right to opt out of the “sale” or “sharing” of their personal information. Whether Salesforce’s data sharing for model training constitutes “sharing” under CPRA is a legal determination your privacy team should make.

SOC 2

SOC 2 Type II audits evaluate whether an organization’s controls operate effectively over time. If your organization committed to certain data handling practices in your SOC 2 controls and your Salesforce data is being shared for purposes not covered by those controls, you have a gap.

Governance Checklist for AI Data Sharing

Use this checklist to evaluate and document your organization’s posture across the Salesforce ecosystem:

Salesforce Core

  • [ ] In Setup, search “Opt Out” or “Customer Data” and click “Opt Out of Customer Data Access” to identify the current state.
  • [ ] Determine whether your org was previously opted out via support case.
  • [ ] Review your MSA and DPA with Salesforce for data use clauses.
  • [ ] Evaluate whether the data in your org (PII, PHI, financial data, proprietary business data) creates compliance risk if included in aggregate training datasets.
  • [ ] Make a documented decision: opt out or consciously accept.
  • [ ] If opting out, disable the toggle and verify after 30 days that data retention has been addressed.

Slack

  • [ ] Identify the Workspace Owner or Primary Owner for each Slack workspace in your organization.
  • [ ] Determine whether an opt-out request has previously been submitted.
  • [ ] If not, submit the opt-out request via email to [email protected].
  • [ ] Retain the confirmation email as documentation.
  • [ ] Add Slack data sharing review to your quarterly security governance cadence.

Other Salesforce Products

  • [ ] If using Marketing Cloud, review Einstein data sharing settings specific to that product.
  • [ ] If using Commerce Cloud or other Salesforce products, investigate product-specific data sharing policies.
  • [ ] Document the data sharing posture for each Salesforce product in use.

Ongoing

  • [ ] Add Salesforce and Slack AI data sharing to your annual MSA/DPA review.
  • [ ] Monitor Salesforce release notes for changes to data sharing defaults or opt-out mechanisms.
  • [ ] Include AI data sharing posture in your vendor risk assessment for Salesforce.

The Industry Context

The opt-out model that Salesforce and Slack use is increasingly out of step with industry norms for enterprise AI. OpenAI’s enterprise products (ChatGPT Enterprise, API) do not use customer data for model training by default. Anthropic’s Claude does not train on enterprise customer data. Google’s Cloud AI products operate on an opt-in basis for data contribution.

The SaaS industry broadly reserves the right to use customer data for product improvement in standard terms of service–this is not unique to Salesforce. But the AI-specific application of that right has drawn more scrutiny because the nature of model training means customer data is incorporated into a persistent artifact (the trained model) rather than being used transiently for analytics or debugging.

Salesforce’s addition of the Setup toggle in Spring ’26 is a step toward transparency. But the default-on posture, the years of data collection before the toggle existed, and the email-only opt-out for Slack suggest that the company’s data governance UX has not kept pace with the sensitivity of the underlying practice.

The Bottom Line

Your Salesforce org’s data has likely been contributing to AI model training since you signed your MSA, unless you specifically asked it not to. Your Slack workspace almost certainly has been, because the only way to stop it requires knowing about a policy buried in privacy documentation and sending a manual email.

Neither of these facts means your data has been mishandled. Salesforce’s confidentiality commitments and de-identification practices provide a baseline of protection. But “probably fine” is not a data governance posture. The responsible action is to evaluate the practice against your own data governance policies, make a conscious decision, and document it.

The toggle is there now. The email address is known. The only thing missing is the decision.

Book a 15-Minute Security Strategy Call

Reference(s):

https://www.salesforceben.com/salesforces-new-ai-data-setting-sparks-debate-over-what-customers-agreed-to/

https://help.salesforce.com/s/articleView?id=000384050&language=en_US&type=1

https://help.salesforce.com/s/articleView?id=sf.aac_manage_data_policies.htm&language=en_US&type=5

https://slack.com/trust/data-management/privacy-principles

https://www.salesforceben.com/whats-brewing-at-slack-controversy-over-ai-training-policy/

https://techcrunch.com/2024/05/17/slack-under-attack-over-sneaky-ai-training-policy/