Zoom AI Companion
medium riskAI Meeting Assistantzoom.usverified 2026-06-27
Data-handling profile
- Trains on input
- No — does not train on customer inputs
- Retention
- Zoom states it does not use customer audio, video, chat, screen-share, attachments, or other communications-like content to train its own or third-party AI models; this is a blanket policy (no per-tier opt-out needed), following the 2023 ToS controversy and subsequent clarification.
- Data region
- Global
- Certifications
- SOC 2 Type IIISO 27001FedRAMP
- DPA available
- Yes
- Breach history
- 2020 credential-stuffing incident exposed ~500K account credentials; 2020 FTC settlement over misleading encryption claims; January 2026 disclosed vulnerability (CVE-2026-22844) affecting Zoom Node Meetings Hybrid/Meeting Connector environments.
- EU AI Act
- AI Companion meeting-summarization features fall under limited-risk transparency obligations; embedded in core videoconferencing product rather than a separable AI service.
Sources
- https://www.zoom.com/en/products/ai-assistant/resources/privacy-security/
- https://www.zoom.com/en/blog/zooms-term-service-ai/
- https://www.upguard.com/news/zoom-data-breach-2026-01-21
Every fact above is drawn from the vendor's public documentation, reviewed by a human, and version-stamped. Monitored daily for changes.
Change history
No material changes recorded since monitoring began.