Zoom AI Companion can be used at work only under specific conditions. Our verdict for a typical 50–500 person company handling client or regulated data, assessed 29 July 2026: Limited. Zoom states it does not train on customer content, and its own admin documentation shows the feature is genuinely governable — account, group and user-level toggles, a lock, and a setting for who automatically receives each summary. It stays Limited because none of that changes what a summary contains: consent and distribution of a written record of the meeting need rules you write, not defaults you inherit. The policy questions are consent and distribution: who gets the summary of the meeting where the layoff list was discussed? Zoom’s own admin settings answer that one — the automatic-sharing setting can send every summary to all invitees including external ones — so the policy work is choosing the value, not asking whether it exists.
This verdict reflects Zoom’s published terms as we read them on 29 July 2026. A vendor can change its terms the day after; the primary sources below are how you check.
| Vendor | Zoom |
|---|---|
| Category | Meeting AI |
| Our tier verdict | Limited (assessed 29 July 2026) — Zoom states it does not train on customer content, and its own admin documentation shows the feature is genuinely governable — account, group and user-level toggles, a lock, and a setting for who automatically receives each summary. It stays Limited because none of that changes what a summary contains: consent and distribution of a written record of the meeting need rules you write, not defaults you inherit. source |
| Trains on your data? | No (per vendor terms) No. Zoom states it does not use any customer audio, video, chat, screen sharing, attachments or other communications-like customer content to train Zoom’s or third-party AI models. Its admin article repeats the same commitment and adds what does leave: for AI Companion features that use third-party model providers, Zoom states it shares the relevant data with them — "if you use meeting summary to create an AI-generated summary, the meeting transcript will be sent to the relevant model to provide the service". source |
| Data retention | Admin-set, not a published clock. Zoom’s meeting-summary admin article documents an "Auto-delete meeting summaries" setting that moves summaries to the Trash after a number of days the account chooses; the article states no default period, so unless someone sets it, there is no deletion date to point at. The AI terms post we also read addresses training rather than retention. source (archived) |
| Admin controls | Substantial, and account-level. Zoom documents that account owners and admins enable or disable Meeting summary with AI Companion under Account Management → Account Settings → AI Companion, with the same toggle available at group and user level and a lock icon that stops users changing it. The sub-settings are the policy-relevant part: start summaries automatically when a meeting starts, restrict sharing to inside the organisation, choose who automatically receives the summary (host only, hosts, internal invitees, or all invitees including external), restrict access by IP range, display a custom disclaimer when AI Companion is turned on in a meeting, and auto-delete summaries after a set number of days. If the feature is disabled and locked, admins choose whether participants still see it and can request enablement. Read from a 25 February 2026 archive snapshot: support.zoom.com serves its knowledge base as an empty JavaScript shell to a plain fetch. source (archived) |
| Compliance certifications | Zoom publishes compliance material separately; we did not verify its current certification list from a primary document on this check date. |
| HIPAA / BAA | Enterprise- or plan-dependent — By BAA with Zoom, not by product page. Zoom’s meeting-summary admin article lists among the feature’s requirements: "Meeting summary is available to customers with an active BAA." Two things follow from that sentence and no more — Zoom has customers holding an active BAA with it, and it does not withhold meeting summary from them. We did not read Zoom’s BAA itself, so it tells you nothing about which AI Companion features your own agreement covers. Confirm that in writing before a call could touch PHI. source (archived) |
No. Zoom states it does not use any customer audio, video, chat, screen sharing, attachments or other communications-like customer content to train Zoom’s or third-party AI models. Its admin article repeats the same commitment and adds what does leave: for AI Companion features that use third-party model providers, Zoom states it shares the relevant data with them — "if you use meeting summary to create an AI-generated summary, the meeting transcript will be sent to the relevant model to provide the service".
Retention: Admin-set, not a published clock. Zoom’s meeting-summary admin article documents an "Auto-delete meeting summaries" setting that moves summaries to the Trash after a number of days the account chooses; the article states no default period, so unless someone sets it, there is no deletion date to point at. The AI terms post we also read addresses training rather than retention.
By BAA with Zoom, not by product page. Zoom’s meeting-summary admin article lists among the feature’s requirements: "Meeting summary is available to customers with an active BAA." Two things follow from that sentence and no more — Zoom has customers holding an active BAA with it, and it does not withhold meeting summary from them. We did not read Zoom’s BAA itself, so it tells you nothing about which AI Companion features your own agreement covers. Confirm that in writing before a call could touch PHI. As a rule: no signed Business Associate Agreement means no protected health information (PHI) — a BAA is the gate, not the security posture. A vendor can hold every certification on the market and still be the wrong place for PHI, because what makes PHI processing lawful for a covered entity is the contract, not the encryption.
Comparing vendors on this specifically? See BAA status for all 26 tools →
Not verified from a primary document on this check date. Zoom publishes compliance material separately; we did not verify its current certification list from a primary document on this check date. Ask for the current SOC 2 report under NDA before you rely on it. A certification is also not a contract: it describes how Zoom AI Companion runs its controls, not what your agreement with them permits.
HIPAA is the gate: By BAA with Zoom, not by product page. Zoom’s meeting-summary admin article lists among the feature’s requirements: "Meeting summary is available to customers with an active BAA." Two things follow from that sentence and no more — Zoom has customers holding an active BAA with it, and it does not withhold meeting summary from them. We did not read Zoom’s BAA itself, so it tells you nothing about which AI Companion features your own agreement covers. Confirm that in writing before a call could touch PHI. Until a BAA is confirmed in writing, treat Zoom AI Companion as off-limits for anything containing PHI — patient names, appointment details, clinical notes, even "anonymized" summaries that could be re-identified.
For SEC/FINRA-regulated firms the questions are recordkeeping and confidentiality: can communications through Zoom AI Companion be captured for books-and-records requirements, and do the data terms hold up in vendor due diligence? Substantial, and account-level. Zoom documents that account owners and admins enable or disable Meeting summary with AI Companion under Account Management → Account Settings → AI Companion, with the same toggle available at group and user level and a lock icon that stops users changing it. The sub-settings are the policy-relevant part: start summaries automatically when a meeting starts, restrict sharing to inside the organisation, choose who automatically receives the summary (host only, hosts, internal invitees, or all invitees including external), restrict access by IP range, display a custom disclaimer when AI Companion is turned on in a meeting, and auto-delete summaries after a set number of days. If the feature is disabled and locked, admins choose whether participants still see it and can request enablement. Read from a 25 February 2026 archive snapshot: support.zoom.com serves its knowledge base as an empty JavaScript shell to a plain fetch.
The privilege question comes first: entering client-confidential facts into any third-party AI service must be evaluated as a potential disclosure. Zoom AI Companion’s no-training terms on corporate plans help, but confidentiality duties still require client-consent and matter-sensitivity judgment.
Every vendor claim above traces to a document the vendor publishes, and every document below is one we actually opened and read — each carries the date we read it. They were read between 29 July 2026 and 6 August 2026. The verdict date on this page is not a build stamp and is not "today": it is the oldest of those dates, because a verdict is only as current as the stalest document under it. Rebuilding the site does not move it.
Where a fact is not in one of these documents, the page says so rather than filling the gap. That is why some rows read "not publicly documented" or "not established from a primary source" instead of naming a certification or rounding an open question to a convenient answer.
Why the tier verdict is "generic": Limited is the right starting classification for most 50–500 person companies — but a healthcare company, a law firm, and a SaaS startup should not have identical tool lists. The $79 policy kit classifies Zoom AI Companion and 25 other tools specifically for your industry, company size, and the data your team handles.
And a verdict has a shelf life: vendor data policies change quietly — a terms update can move a tool between tiers overnight. This page states what we read on 29 July 2026. The $149/mo Monitor plan exists precisely because that date keeps receding.
Zoom AI Companion can be used at work only under specific conditions. Our verdict for a typical 50–500 person company handling client or regulated data, assessed 29 July 2026: Limited. Zoom states it does not train on customer content, and its own admin documentation shows the feature is genuinely governable — account, group and user-level toggles, a lock, and a setting for who automatically receives each summary. It stays Limited because none of that changes what a summary contains: consent and distribution of a written record of the meeting need rules you write, not defaults you inherit. The policy questions are consent and distribution: who gets the summary of the meeting where the layoff list was discussed? Zoom’s own admin settings answer that one — the automatic-sharing setting can send every summary to all invitees including external ones — so the policy work is choosing the value, not asking whether it exists.
No. Zoom states it does not use any customer audio, video, chat, screen sharing, attachments or other communications-like customer content to train Zoom’s or third-party AI models. Its admin article repeats the same commitment and adds what does leave: for AI Companion features that use third-party model providers, Zoom states it shares the relevant data with them — "if you use meeting summary to create an AI-generated summary, the meeting transcript will be sent to the relevant model to provide the service".
By BAA with Zoom, not by product page. Zoom’s meeting-summary admin article lists among the feature’s requirements: "Meeting summary is available to customers with an active BAA." Two things follow from that sentence and no more — Zoom has customers holding an active BAA with it, and it does not withhold meeting summary from them. We did not read Zoom’s BAA itself, so it tells you nothing about which AI Companion features your own agreement covers. Confirm that in writing before a call could touch PHI. As a rule: no signed Business Associate Agreement means no protected health information (PHI) — a BAA is the gate, not the security posture. A vendor can hold every certification on the market and still be the wrong place for PHI, because what makes PHI processing lawful for a covered entity is the contract, not the encryption.
Not verified from a primary document on this check date. Zoom publishes compliance material separately; we did not verify its current certification list from a primary document on this check date. Ask for the current SOC 2 report under NDA before you rely on it. A certification is also not a contract: it describes how Zoom AI Companion runs its controls, not what your agreement with them permits.
We classify Zoom AI Companion as Limited for a typical 50–500 person company, assessed 29 July 2026. Zoom states it does not train on customer content, and its own admin documentation shows the feature is genuinely governable — account, group and user-level toggles, a lock, and a setting for who automatically receives each summary. It stays Limited because none of that changes what a summary contains: consent and distribution of a written record of the meeting need rules you write, not defaults you inherit. Your own classification should reflect your industry, data types, and which plan or account type your company actually uses.
Zoom renamed and moved it. The current document is the “Zoom AI Whitepaper” (covering Zoom Workplace, Webinars, and Events; last updated 23 June 2026), published in Zoom’s technical library at library.zoom.com/ai/ai-whitepaper — the old “AI Companion Security and Privacy” page on zoom.com now redirects there, and the earlier standalone PDF is no longer hosted on a Zoom domain. The whitepaper states that Zoom does not use customer audio, video, chat, screen sharing, attachments or other communications-like customer content to train Zoom’s or third-party AI models; documents the account- and group-level admin toggles and the lock; and describes encryption in transit (TLS 1.2 minimum) and at rest (AES 256-bit), with zero-data-retention arrangements at its third-party model providers. Read it directly before relying on it in a vendor review — the summary on this page is a lead, not the document.
New to the topic? Start with what shadow AI is — definition, examples and risks, then measure your own exposure with the shadow AI scorer.
Your team is using Zoom AI Companion. Does your AI policy cover it?
Most policies name a handful of tools and go stale the month after they are written. Two ways to find out where yours stands: check an existing policy for gaps in 30 seconds, or generate a policy that classifies Zoom AI Companion by name — free preview, no account. Starting from scratch? The free 14-section AI acceptable use policy template is the document itself, ungated.
A 4-document AI policy kit — acceptable use policy, tool tier list, acknowledgment form, manager FAQ — that classifies Zoom AI Companion and 25 other tools for your company, industry, and data. Generated in about 10 minutes.
Generate my policy kit →We re-check vendor terms monthly and alert you when Zoom AI Companion’s data policy changes — plus regenerate your whole kit so it never goes stale. This directory is a snapshot — Monitor is the live feed.
See Monitor plan →Already have an AI policy? Check it for gaps in 30 seconds →