Zoom AI Companion

zoom.com

Public evidence identified as at Aug 31, 2026

Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.

TrustyCyber Score
Not scored — insufficient public evidence

Approve with conditions

A score is only published when there is evidence to score.

Before you sign

Data retention window not statedCondition

Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.

What to ask for: Get retention windows, in days, in writing.

Processing location not disclosedCondition

Why it matters: The public sources scanned do not state where customer data is processed or offer a residency option.

What to ask for: Pin processing regions per data classification in the contract.

Buyer questionsanswered only from the public evidence scanned — click a row for the answer

Will they train on your data?Clear

Zoom states it does not use audio, video, chat, screen sharing, attachments or other communications-like customer content to train its own or third-party AI models.

Evidence
Vendor publishedZoom Privacy Statement | Zoomretrieved Aug 31, 2026
Zoom does not use any of your audio, video, chat, screen sharing, attachments or other communications-like Customer Content (such as poll results, whiteboard and reactions) to train Zoom’s or its third-party artificial intelligence models.
!How long do they keep your data?Ask the vendor

Not found in the public sources scanned — ask the vendor directly.

Requires written confirmation — see Before you sign ↓

Who else can access your data?Clear

OpenAI is registered as an Intelligent Features Service Provider that may process customer content and context when AI features are enabled, in the US and EU under SCCs.

Evidence
OpenAI Intelligent Features Service Provider OpenAI may process the following data if AI features are enabled: Customer Content and context United States, European Union
Anthropic Intelligent Features Service Provider Anthropic may process the following data if AI features are enabled: Customer Content and context
OpenAI may process the following data if AI features are enabled: Customer Content and context
!Where is your data processed?Ask the vendor

Not found in the public sources scanned — ask the vendor directly.

Requires written confirmation — see Before you sign ↓

!What happens in a security incident?Ask the vendor

Not found in the public sources scanned — ask the vendor directly.

Confirm in writing: Ask the vendor to state this in writing before signing.

Key findingsclick a row for the evidence

An explicit, unqualified commitment not to train on customer communicationsStrong

Zoom's privacy statement says plainly that it does not use audio, video, chat, screen sharing, attachments or other communications-like customer content to train its own or third-party AI models.

This is the question buyers ask first, and Zoom has public history on it. The commitment is stated without a tier carve-out or a settings condition, which is stronger than most comparable vendors offer — and being in the privacy statement, it is the version Zoom is held to.

Evidence
Vendor publishedZoom Privacy Statement | Zoomretrieved Aug 31, 2026
Zoom does not use any of your audio, video, chat, screen sharing, attachments or other communications-like Customer Content (such as poll results, whiteboard and reactions) to train Zoom’s or its third-party artificial intelligence models.
AI model providers are named contractually, not just describedStrong

OpenAI and Anthropic are both registered as Intelligent Features Service Providers that may process customer content and context, with processing locations and SCCs stated.

Naming model providers in the subprocessor register puts them inside the DPA's change-notification machinery, so the AI supply chain can be tracked through the agreement rather than by watching a webpage.

Evidence
OpenAI Intelligent Features Service Provider OpenAI may process the following data if AI features are enabled: Customer Content and context United States, European Union
Anthropic Intelligent Features Service Provider Anthropic may process the following data if AI features are enabled: Customer Content and context
OpenAI may process the following data if AI features are enabled: Customer Content and context
!No AI Companion-specific documentation reached this collectionGap

Zoom publishes AI Companion whitepapers ("AI Companion security and privacy", "AI Companion data privacy lifecycle") and a legal and compliance guide, none of which were retrievable here. The evidence above is organisation-wide and applies to AI Companion, but nothing product-specific was collected.

The organisation-wide no-training commitment is the load-bearing one and it covers the product. What is missing is AI Companion's own retention periods, human-review practice and admin controls — needed to operationalise a deployment, not to decide whether the posture is sound.

Question for vendor: Please provide the AI Companion data privacy lifecycle whitepaper, covering retention periods and whether any human review of AI Companion content occurs.

Evidence
Vendor publishedZoom Privacy Statement | Zoomretrieved Aug 31, 2026
Zoom does not use any of your audio, video, chat, screen sharing, attachments or other communications-like Customer Content (such as poll results, whiteboard and reactions) to train Zoom’s or its third-party artificial intelligence models.
OpenAI may process the following data if AI features are enabled: Customer Content and context
AI processing depends on a customer-controlled settingStrong

The register conditions each AI provider's processing on AI features being enabled, so content reaches OpenAI or Anthropic only on a customer decision.

It supports a staged rollout: AI processing can be held off while governance approval is obtained, without leaving the platform.

Evidence
OpenAI may process the following data if AI features are enabled: Customer Content and context
!Declared OpenAI, technically observed GoogleGap

The vendor's own materials name OpenAI as the model provider, but DNS, certificate, or HTTP evidence points to Google in that role instead.

A supply-chain claim that doesn't match what is technically observable is a disclosure question worth raising directly, not assuming either side is wrong.

Question for vendor: Can you confirm whether OpenAI or Google is the actual model provider?

Evidence
OpenAI Intelligent Features Service Provider OpenAI may process the following data if AI features are enabled: Customer Content and context United States, European Union
?Technical dependency observed: Microsoft AzureObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft Azure as a platform provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Microsoft Azure appears to be involved as a platform provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
OpenAI Intelligent Features Service Provider OpenAI may process the following data if AI features are enabled: Customer Content and context United States, European Union
Anthropic Intelligent Features Service Provider Anthropic may process the following data if AI features are enabled: Customer Content and context
OpenAI may process the following data if AI features are enabled: Customer Content and context
?Technical dependency observed: IntercomObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Intercom as a application builder. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Intercom appears to be involved as a application builder: confirm whether this dependency exists, and whether it processes customer data.

Evidence
OpenAI Intelligent Features Service Provider OpenAI may process the following data if AI features are enabled: Customer Content and context United States, European Union
Anthropic Intelligent Features Service Provider Anthropic may process the following data if AI features are enabled: Customer Content and context
OpenAI may process the following data if AI features are enabled: Customer Content and context
?Technical dependency observed: StripeObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
OpenAI Intelligent Features Service Provider OpenAI may process the following data if AI features are enabled: Customer Content and context United States, European Union
Anthropic Intelligent Features Service Provider Anthropic may process the following data if AI features are enabled: Customer Content and context
OpenAI may process the following data if AI features are enabled: Customer Content and context
?Technical dependency observed: MicrosoftObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
OpenAI Intelligent Features Service Provider OpenAI may process the following data if AI features are enabled: Customer Content and context United States, European Union
Anthropic Intelligent Features Service Provider Anthropic may process the following data if AI features are enabled: Customer Content and context
OpenAI may process the following data if AI features are enabled: Customer Content and context
?Technical dependency observed: AtlassianObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
OpenAI Intelligent Features Service Provider OpenAI may process the following data if AI features are enabled: Customer Content and context United States, European Union
Anthropic Intelligent Features Service Provider Anthropic may process the following data if AI features are enabled: Customer Content and context
OpenAI may process the following data if AI features are enabled: Customer Content and context

AI System Assurance Report Cardscored per assurance object — organisational assurance is not product, model or agent assurance

Overall AI system assurance
Not scored — insufficient public evidence

Derived from the dimensions below — expand any row for the evidence behind its grade.

Organisation & AI governance15% of the scoreorganisation-level evidence0

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Governance & accountability

Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.

Assessed against ISO 42001 · NIST AI RMF · AIUC-1

Not Evidenced

Governance & accountability: not publicly evidenced.

AI system15% of the scoreorganisation-level evidence0

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

AI system description

What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.

Assessed against ISO 42001 · NIST AI RMF

Not Evidenced
Testing & evaluation

How AI features are evaluated before and after release — evals, red-teaming, monitoring.

Assessed against NIST GenAI · NIST AI RMF · ISO 42001

Not Evidenced
Change management

How changes to models and AI features are controlled and communicated — versioning, notice, rollback.

Assessed against ISO 27001 · ISO 42001

Not Evidenced

AI system description: not publicly evidenced.

Testing & evaluation: not publicly evidenced.

Change management: not publicly evidenced.

Model10% of the scoreorganisation-level evidence60

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Model & provider transparency

Which model providers and versions process customer data, and how changes to them are disclosed.

Assessed against NIST GenAI · ISO 42001

Partial
Evidence — Model & provider transparency
OpenAI Intelligent Features Service Provider OpenAI may process the following data if AI features are enabled: Customer Content and context United States, European Union
Anthropic Intelligent Features Service Provider Anthropic may process the following data if AI features are enabled: Customer Content and context

Model provider transparency: vendor-evidenced, not yet independently corroborated.

Customer data15% of the scoreorganisation-level evidence72

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Customer data treatment

Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.

Assessed against ISO 27018 · OAIC APPs · EU AI Act

Partial
Evidence — Customer data treatment
Vendor publishedZoom Privacy Statement | Zoomretrieved Aug 31, 2026
Zoom does not use any of your audio, video, chat, screen sharing, attachments or other communications-like Customer Content (such as poll results, whiteboard and reactions) to train Zoom’s or its third-party artificial intelligence models.

Customer data treatment: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.

AI supply chain10% of the scoreorganisation-level evidence60

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Subprocessors & supply chain

The named chain of AI and infrastructure providers behind the product, and how it is disclosed.

Assessed against ISO 27001 · ISO 27017

Partial
Evidence — Subprocessors & supply chain
OpenAI Intelligent Features Service Provider OpenAI may process the following data if AI features are enabled: Customer Content and context United States, European Union
Anthropic Intelligent Features Service Provider Anthropic may process the following data if AI features are enabled: Customer Content and context
OpenAI may process the following data if AI features are enabled: Customer Content and context

Subprocessors & supply chain: vendor-evidenced, not yet independently corroborated.

Security foundation15% of the scoreorganisation-level evidence24

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Vulnerability & incident handling

How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.

Assessed against ISO 27001 · NIST AI RMF

Not Evidenced

Vulnerability & incident handling: not publicly evidenced.

Independent assurance evidence10% of the scoreorganisation-level evidence63

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Independent assurance

Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.

Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008

Covered
Evidence — Independent assurance

Read from the registry record above — cited, not reproduced.

Registry verifiedCSA STAR Registry record — CSA STAR Level 2retrieved Aug 31, 2026

Read from the registry record above — cited, not reproduced.

Read from the registry record above — cited, not reproduced.

None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.

Legal & contractual10% of the scoreorganisation-level evidence0

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Legal & contractual transparency

The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.

Assessed against EU AI Act · OAIC APPs

Not Evidenced

Legal & contractual transparency: not publicly evidenced.

Not graded: Agent — not applicable to this scan.

AI supply chainclick a node to focus it · drag to pan · zoom with the controls

ORGANISATIONPRODUCT & AI FEATURESMODELS & AI PROVIDERSZoom CommunicationsZoom CommunicationsZoom AI CompanionZoom AI CompanionOpenAIOpenAIAnthropicAnthropic
View as list
Zoom Communications Uses AI Service Zoom AI Companion
Zoom AI Companion Contracted Subprocessor OpenAI
Zoom AI Companion Contracted Subprocessor Anthropic

What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0

This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.

Map your inherited responsibilities
Assurance evidence: certifications 4 — registry checks and verification ladders, click to view
ISO/IEC 42001Not claimed

Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.

EU-U.S. Data Privacy FrameworkClaimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against Data Privacy Framework (dataprivacyframework.gov), Aug 31, 2026: Verified on the registry

CSA STAR Level 2Claimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against CSA STAR Registry, Aug 31, 2026: Verified on the registry

FedRAMP AuthorizationClaimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against FedRAMP Marketplace (fedramp.gov), Aug 31, 2026: Verified on the registry

Sources 15 — click to view
Official Zoom Support | Help Center
AI Documentation · Vendor · retrieved Aug 31, 2026
Zoom Trust Center | Zoom
Trust Or Security Page · Vendor · retrieved Aug 31, 2026
Zoom Third-Party Subprocessors & Zoom Affiliates | Zoom
Subprocessor List · Vendor · retrieved Aug 31, 2026
Privacy at Zoom | Zoom
Privacy Notice · Vendor · retrieved Aug 31, 2026
Compliance | Zoom
Certification Or Compliance Page · Vendor · retrieved Aug 31, 2026
Turn conversations into collaborative workspaces | Zoom
Product Documentation · Vendor · retrieved Aug 31, 2026
Zoom's Trust Center Resources | Zoom
Terms · Vendor · retrieved Aug 31, 2026
Agent Assist For Contact Centers (AI Expert Assist) | Zoom
AI Documentation · Vendor · retrieved Aug 31, 2026
Security | Zoom
Trust Or Security Page · Vendor · retrieved Aug 31, 2026
Zoom Privacy Statement | Zoom
Privacy Notice · Vendor · retrieved Aug 31, 2026
Zoom Transparency Report | Zoom
Certification Or Compliance Page · Vendor · retrieved Aug 31, 2026
Data Privacy Framework (dataprivacyframework.gov) record — EU-U.S. Data Privacy Framework
External Registry Or Certification Evidence · Registry · retrieved Aug 31, 2026
CSA STAR Registry record — CSA STAR Level 2
External Registry Or Certification Evidence · Registry · retrieved Aug 31, 2026
FedRAMP Marketplace (fedramp.gov) record — FedRAMP Authorization
External Registry Or Certification Evidence · Registry · retrieved Aug 31, 2026
Appendix: standards landscape 8 — click to view

Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.

NIST AI RMF 1.0 (AI 100-1)Published (2023; GenAI profile 2024)
AI risk management (+ Generative AI Profile) · Voluntary AI RMF (Govern/Map/Measure/Manage); the US counterpart to ISO/IEC 42001 for AI governance.
AI management system · Anchor for responsible AI governance — internal audit, management review and continual improvement. World's first AI management system standard.
PII protection in public clouds · 3rd edition (Aug 2025), aligned to 27002:2022 with a new Annex B; useful for SaaS privacy, processor obligations and customer assurance packs.
Interpretation of the 13 APPs · Authoritative APP interpretation under the Privacy Act 1988; watch for privacy-reform updates.
EU AI Act (Reg 2024/1689)In force, phased to 2028 (amended by Reg (EU) 2026/1744)
AI regulation — risk tiers, GPAI, high-risk obligations · Extraterritorial AI law; GPAI obligations and the Code of Practice are live. The Digital Omnibus on AI, Regulation (EU) 2026/1744 (OJ 24 Jul 2026, in force 27 Jul 2026), defers Annex III standalone high-risk obligations to 2 Dec 2027 and Annex I embedded high-risk to 2 Aug 2028; Article 50 transparency duties applied from 2 Aug 2026.
Requirements for management-system certification bodies · The base certification-body standard that ISO/IEC 27006-1 and 42006 extend; foundational for audit/cert integrity (also in the reference vault).
Requirements for bodies auditing/certifying AIMS · Published (Jul 2025) — turns AI management systems into a certification and assessor-competence conversation. Builds on ISO/IEC 17021-1.
Requirements for ISMS certification bodies · Certification-integrity baseline for audit bodies; the two-year transition concluded around March 2026.

This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.