Wrivio
Get Wrivio
4 min readBy Wrivio Team

Always-On AI Agents in Slack and Teams: What to Check Before One Joins Your Workspace

The newest wave of AI assistants does not wait for you to open a chat window. At its DevDay at the end of September 2026, OpenAI introduced Dots, persistent agents that keep working after you close the tab, run with their own cloud computer and browser, and reach users through ChatGPT, Slack, and Microsoft Teams, as reported by SiliconANGLE. Other vendors are moving the same direction.

An agent that lives in your team’s chat is a different kind of tool from a chatbot you paste text into. It can read conversations it was not explicitly given, act on information over time, and connect to other systems. Before someone on your team switches one on, it is worth asking a short list of questions.

What Can It Read?

Start with scope. An agent added to a workspace may be able to read:

  • Only messages sent directly to it.
  • Every message in channels it is added to, including history.
  • Files and links shared in those channels.
  • Connected apps such as email, calendars, documents, and ticketing tools.

Find out which applies, in writing, from the vendor’s documentation. “It only uses what it needs” is not an answer. Then check whether sensitive channels (HR, legal, deals, incidents) could be reached by accident through a shared channel or a broad permission.

What Can It Do Without Asking?

Reading is one risk. Acting is another. An agent that can send messages, update tickets, edit documents, or make purchases can also do those things wrongly, or be manipulated into doing them by text it reads. That second risk, prompt injection, is not solved; indirect prompt injection for non-engineers explains it in plain terms.

Ask which actions require human approval and whether you can change that. A sensible default for a new agent is that it drafts and a person sends. When to let an agent act and when to only draft covers how to decide.

Where Does The Data Go, And For How Long?

Persistent agents remember. That is the point. Ask:

  • Where conversation history and agent memory are stored.
  • How long they are retained, and whether you can delete them.
  • Whether workspace content is used to train models, and under what settings.
  • Which subprocessors handle the data.

If the answers are unclear, treat the agent like any other vendor with access to company data. Questions to ask an AI vendor about data is a ready-made list.

Who Is Accountable For What It Says?

When an agent posts in a channel or sends a message on someone’s behalf, colleagues and clients will read it as coming from that person or team. Decide in advance:

  • Whether agent-authored messages are labeled as such.
  • Who reviews them, and who answers for mistakes.
  • How someone outside the team can tell they are talking to an agent.

Disclosure expectations are tightening in several places; new AI disclosure laws in 2026 covers the main ones.

Start Small, Write It Down

If your team decides to try an always-on agent, start in one low-risk channel with a written note that says what it can read, what it can do, who owns it, and how to turn it off. Review after a month. A one-paragraph AI tool rollout announcement is enough to keep everyone informed.

For writing tasks specifically, there is a simpler option: a tool that only sees the text you choose to give it, when you choose to give it. Wrivio works that way. You press Ctrl+Shift+Space, paste the text you want rewritten, and nothing else is read. With the Local engine, the rewrite happens on your machine with no network call at all.

Common Questions

What are always-on AI agents?

They are AI assistants that keep running in the background, remember context over time, and can act across apps such as Slack, Teams, email, and documents without being prompted for each task.

Is it safe to add an AI agent to a Slack or Teams channel?

It can be, if you understand exactly what it can read and do, where its data is stored, and which actions require human approval. Start in a low-risk channel and keep sensitive channels out of scope.

Can an AI agent in a chat channel be manipulated?

Yes. Agents that read content from many sources can be influenced by instructions hidden in that content, a risk known as indirect prompt injection. Requiring human approval for actions reduces the impact.

Should agent messages be labeled in team channels?

Yes. Labeling agent-authored messages helps colleagues and clients understand who they are dealing with and keeps accountability clear.

Download Wrivio for Windows for AI rewriting that sees only the text you choose to give it.