BAA requires Enterprise Grid, and Slack's HIPAA guidance does not mention Slack AI · No generative-model training on customer data, but customer data improves global non-generative models unless you opt out · Retention not stated
| Slack AI | |
|---|---|
| HIPAA BAA | YesEnterprise Grid only - a BAA must be executed, and Slack's guidance permits PHI only in messages, files, file names, and private channel or DM names. The HIPAA article does not mention Slack AI or state whether AI features fall within BAA scope |
| Trains on your data | Nofor generative models - "We do not develop generative AI models using Customer Data," and third-party LLMs "are not updated by and don't in other ways retain Customer Data after a request to them." Separately, Customer Data is used to improve global non-generative models unless the workspace opts out |
| Survives deletion | Not stated in the privacy principles document |
| Deployer / admin log access | Not stated in the documents reviewed in this pass |
| Third-party attestation | Not verified in this passnot stated in the HIPAA or privacy principles documents reviewed |
"We don't train AI on your data" reads broader than it is - it covers generative models, while Customer Data still improves global non-generative search and learning models unless you opt out. Also the assumption that a Slack BAA covers AI features, which the HIPAA article does not address
Vendor terms change without notice. This page reflects what Slack published as of September 2, 2026. Re-verified quarterly.
If you need a scored Go / Conditional Go / No-Go verdict for a vendor decision — including a vendor not listed here — that's an AI Vendor Risk Assessment: three binary industry gates, nine scored criteria, four provenance fields on every finding. $997, delivered in 48 hours.
See how AVRA works →Want all 13 tools in one file?
Covers 22 tiers across 13 tools — same sourcing, side by side, printable for a vendor file.