A landscaping company in Ohio added an AI chatbot to their Slack workspace last year. Within two weeks, an employee had pasted a client's home address, gate code, and payment details into a conversation with the bot. The AI tool's privacy policy? Customer inputs could be used for model training.
That's the reality for thousands of small and mid-size businesses adopting AI tools right now. The technology works. The security often doesn't.
According to IBM's 2025 Cost of a Data Breach Report, organizations that experienced AI-related security incidents saw 97% of them lacked proper access controls. The average cost of a data breach in the US hit $10.22 million. And a new category of risk called "shadow AI" added an extra $670,000 to breach costs when employees used unauthorized AI tools at work.
For traditional businesses moving into Slack and AI for the first time, the question isn't whether to adopt these tools. It's how to adopt them without putting your customers' data at risk.
Your Data Travels Further Than You Think
When you type a message to an AI tool in Slack, that text doesn't just disappear after you get a response. Depending on the tool, your data might be:
- Stored on external servers
- Used to train future AI models
- Accessible to the tool's employees
- Shared with third-party processors
Most consumer-grade AI tools like ChatGPT or Claude are designed for individual use. Their terms of service reflect that. When a business team starts pasting customer records, internal financials, or HR information into these tools through Slack, the data leaves your control entirely.
In April 2026, Mercor, a $10 billion AI startup that provided training data to companies like Meta, suffered a major data breach. Meta terminated their contract immediately. The incident exposed how even well-funded AI companies can fail at basic data protection.
The pattern repeats across industries. A consulting firm shares client strategy documents with an AI assistant. An insurance agency pastes claim details into a chatbot. A property management company feeds tenant information to an AI tool for faster responses. Each time, sensitive business data flows into systems with unknown security controls.
Shadow AI: The Threat That's Already Inside Your Workspace
Shadow AI happens when employees use AI tools that IT never approved. According to industry research, shadow AI usage has increased by 250% year over year in some industries. One in five organizations has already experienced a breach through these unauthorized tools.


