Slack AI Vendor Risk Profile
Enterprise messaging and collaboration platform owned by Salesforce. Offers AI-powered features including Slack AI for channel summarization, thread digests, search answers, and workflow automation with LLM capabilities.
Risk overview
Risk score: 26/100
Risk tier: Moderate
Safety rating: 74/100 (higher is better)
Lower risk scores indicate lower assessed risk.
Last verified: Apr 19, 2026 Aging
Risk dimensions
| Dimension | Risk score |
|---|---|
| Data Handling | 28/100 |
| IP Exposure | 26/100 |
| Jurisdiction | 13/100 |
| Security | 30/100 |
| Regulatory Compliance | 40/100 |
| Transparency | 25/100 |
| Business Stability | 31/100 |
| Dependency Chain | 24/100 |
| Agent Governance | Not assessed |
Analyst summary
Rating: Acceptable
Slack AI (now part of the Salesforce family) runs on closed LLMs within Slack's own AWS VPC, avoiding the third-party data-sharing exposure that most AI features introduce. Salesforce's compliance inheritance (SOC 2, ISO 27001, FedRAMP Moderate via GovSlack, HIPAA BAA on Enterprise Grid) makes this one of the stronger enterprise AI postures available.
Bottom line: One of the cleaner enterprise AI implementations available; good fit for Slack-standardized organizations.
Strengths
- Slack AI runs on closed LLMs in Slack's own AWS VPC with no data sent to external providers
- No training on customer messages, files, or AI conversations
- Full compliance stack via Salesforce: SOC 2 Type II, ISO 27001/27017/27018, FedRAMP Moderate (GovSlack)
- HIPAA BAA available on Enterprise Grid
- Customer retains full ownership of all Customer Data and AI-generated summaries
Concerns
- Slack AI is a paid add-on on top of Enterprise Grid, driving up per-seat costs
- Closed LLM means less frontier-model capability than third-party-routed alternatives
- Salesforce ownership increases broader vendor concentration for customers already on the CRM
Best for
- Enterprises already on Slack Enterprise Grid adding AI inside their existing governance
- Regulated industries needing HIPAA-eligible or FedRAMP Moderate messaging AI
- Teams wanting AI message and thread summarization without exposing content to OpenAI or Anthropic
Avoid if
- You are not already on Slack (the AI alone does not justify switching)
- You need frontier-model capability over messaging-specific convenience
Citations
- Data Handling — Hipaa Baa Available
Slack offers HIPAA Business Associate Agreements for Enterprise Grid customers on eligible plans.
- Data Handling — Third Party Data Sharing
Slack AI runs on closed LLMs hosted within Slack's AWS VPC; customer data is not sent to third-party LLM providers.
- Data Handling — Trains On User Data
Slack does not train Slack AI or generative AI models on customer data. Customer data stays within the customer's Slack workspace.
- Ip Profiles — User Owns Outputs
As between Customer and Salesforce, Customer retains all ownership rights in Customer Data, including Slack AI generated summaries derived from Customer Data.
- Jurisdiction Profiles — Incorporation Country
Slack Technologies LLC is a subsidiary of Salesforce, Inc., a Delaware corporation headquartered in San Francisco, California.
- Security Compliance — Fedramp Authorized
Slack holds FedRAMP Moderate authorization for its GovSlack offering.
- Security Compliance — Iso 27001
Slack holds ISO/IEC 27001, 27017, and 27018 certifications.
- Security Compliance — Soc2 Type2
Slack maintains SOC 2 Type II attestations available via Salesforce's Compliance portal.