Does Zoom use your meetings to train AI? What Zoom's policies actually say in 2026
Product names, prices, licensing, AI model providers, regional availability, and administrative controls in this article were verified on August 6, 2026 against the sources in the references section. These details change frequently; confirm against live vendor pages before relying on them for purchasing or compliance decisions.
No. Since August 11, 2023, Zoom's terms of service have stated that Zoom does not use customer audio, video, chat, screen sharing, attachments, or other communications-like customer content to train Zoom's or third-party AI models. Zoom's support documentation adds: "We do not allow third-party model providers to use your data to improve or train their models." The commitment was reaffirmed in the AI Companion 3.0 launch in December 2025 and still stands after the June 2026 ZoomMate launch. Two caveats matter for governance: Zoom may still use interaction data operationally to provide, troubleshoot, and support the service, and the no-training promise covers communications content, not all telemetry and service-generated metadata. And no training does not mean no processing: when an AI feature is enabled, Zoom and its approved subprocessors process the permitted meeting transcript, prompts, chat content, or other selected context to deliver that feature.
- Zoom's no-training commitment is contractual language in its terms of service (Section 10.2), not just marketing copy, and it extends to third-party model providers.
- The commitment exists because Zoom got it wrong first. A 2023 terms-of-service update claimed AI training rights over customer content, drew public backlash, and was rewritten within a week.
- Meeting content may be processed by Zoom-hosted models, Anthropic Claude, and OpenAI GPT models under zero data retention policies, plus Perplexity, ElevenLabs, Google Gemini, and AWS Rekognition for specific features.
- ZMO and ZM+ deployment options keep AI processing inside Zoom's infrastructure or trust boundary, and ZM+ is the default for EU customers.
- Retention of summaries and transcripts is whatever your administrators configure. There is no published default period, and a Meeting Summary Zero Data Retention option exists for transcripts.
What exactly does Zoom promise?
The operative language in Zoom's terms of service, Section 10.2, effective August 11, 2023:
Zoom does not use any of your audio, video, chat, screen sharing, attachments or other communications-like Customer Content (such as poll results, whiteboard and reactions) to train Zoom or third-party artificial intelligence models.
The same commitment appears on Zoom's AI security and privacy page and in support article KB0057861, which governs how AI features handle data. The support article is also where the operational caveat lives: data from users' interactions with AI features may be accessed, processed, and used by Zoom to provide and maintain the services, troubleshoot issues, and provide support. Optional user feedback, which can include prompts and responses, may be reviewed by Zoom employees to improve the product experience, though Zoom says it is not used for model training.
The prohibition covers communications-like customer content. Service-generated data, meaning telemetry, diagnostics, and usage metadata, sits outside that sentence. Privacy commentators flagged this distinction in 2023 and it remains the correct technical reading. For most organizations this is acceptable, but records and privacy teams should know the boundary exists.
Didn't Zoom try to train on customer data in 2023?
Yes, briefly, and the episode explains why today's language is so specific. A terms-of-service update from March 2023 surfaced publicly in August 2023. Section 10.4 granted Zoom rights to use customer content to train its AI models, in connection with the assistant then called Zoom IQ. The backlash was immediate. Zoom responded on August 7, 2023 with a blog post and an interim edit promising not to train on audio, video, or chat content "without your consent." Critics noted that consent framing and the service-generated-data carve-out still fell short, particularly against GDPR's consent standard. On August 11, 2023, Zoom rewrote Section 10 entirely, removing the AI training license and inserting the flat prohibition quoted above. That text has remained in force since.
The practical lesson for IT leaders: vendor AI terms can change between renewals, so treat AI data-use language as a contract review item, not a settled fact. Our related article covers the broader discipline: What does AI data governance actually require in 2026?
Which AI models actually touch your meeting content?
Zoom uses a federated architecture that routes AI requests across its own models and third-party subprocessors. Its AI documentation in the Zoom library, as retrieved August 6, 2026, lists the following. Zoom publishes no as-of date for this list and states that changes to the models used in federation can occur at any time, so treat it as a dated snapshot and re-check Zoom's current documentation and subprocessor disclosures:
| Provider | Role |
|---|---|
| Zoom-hosted models (LLMs and SLMs) | Core processing, always available |
| Anthropic (Claude 4.1 or later) | Federated LLM processing |
| OpenAI (GPT-5.1 or later) | Federated LLM processing |
| Perplexity | Real-time web search |
| ElevenLabs | Audio generation |
| Google Gemini | Whiteboard image generation |
| AWS Rekognition | Image moderation |
On retention by those providers, Zoom's documentation states that third-party model providers do not retain customer content, with limited exceptions for trust and safety purposes such as detecting and reporting CSAM, and that providers are subject to security assessments at least annually. Zoom encrypts data in transit between customers, Zoom data centers, and model providers, and at rest on Zoom's platform. The federation mix can change at any time, which is another reason to re-verify at each contract renewal.
It describes the designated third-party model processing arrangements. It does not mean Zoom never stores AI content: summaries, notes, conversation history, connected source content, and other outputs can be stored according to feature behavior and your retention settings. Zoom's support documentation states, for example, that data collected during a ZoomMate browser session, including screenshots, is saved to the user's conversation history when the session closes (support article KB0057861). Storage depends on the feature, account configuration, user actions, and retention settings.
Can processing be restricted geographically?
Yes. Zoom offers three AI deployment options, described in its October 2025 data governance blog and current security documentation:
- ZMO (Zoom Models Only): Zoom-hosted models only, no third-party providers, processing within Zoom's infrastructure. Available for accounts in the US, EU, Singapore, Saudi Arabia, Australia, India, and Canada.
- ZM+: Zoom models plus Anthropic models accessed through Amazon Bedrock, with processing kept within Zoom's trust boundary. Available in the US and EU, and the default for EU customers.
- Federated: the full multi-provider option, which may involve global processing, including in the United States.
In June 2026 Zoom also announced Zoom AI On-Prem for regulated enterprises, and AI Companion is FedRAMP JAB Moderate authorized on the Zoom for Government platform, which runs in AWS GovCloud with US-based personnel.
What do participants see when AI is active?
Zoom's documentation states that participants joining a meeting see in-product indicators for the AI features active in that meeting. Participants can ask the host to disable meeting summary and meeting questions, and hosts can turn features off mid-meeting and delete the meeting's AI assets. Administrators control availability at the account, group, and user levels and can lock settings.
What Zoom does not document is a region-specific consent gate for AI features, so if your organization operates under two-party consent norms or works with external participants regularly, write your own host procedure: announce AI at the start, record the announcement in the agenda, and disable AI for meetings where a participant objects. Notice builds trust faster than fine print.
What retention controls should administrators set?
- Summary retention: summaries are stored according to account, group, and user retention settings. No default number is published, so set one deliberately.
- Meeting Summary Zero Data Retention: when enabled, hosts decide per meeting whether a transcript is retained, via a checkbox.
- In-meeting deletion: hosts can delete meeting assets during the meeting.
- Email exposure: admins and users can choose whether summary emails contain the full text or only a link, which matters when summaries reach inboxes outside your retention system.
Our recommended rule: do not retain a transcript simply because the platform can. Match retention to the purpose of the meeting record, and treat AI summaries as drafts until a person reviews them.
What about HIPAA, FedRAMP, and financial services?
Zoom identifies portions of its AI portfolio as ISO 27001, ISO 27701, and ISO 27017/18 certified and within its SOC 2 scope. Certifications are scoped to identified systems, report periods, and legal entities, so review the current certificate and SOC report scope for the exact service being deployed rather than assuming every new agent, connector, or on-premises feature is covered identically. For healthcare, Zoom supports HIPAA compliance programs by executing a Business Associate Agreement, but a BAA does not by itself establish that every AI feature is appropriate or available for every healthcare workflow. Confirm eligibility, contractual coverage, configuration, retention, and permitted data use for each feature before processing protected health information. For US government, AI Companion holds FedRAMP JAB Moderate authorization on Zoom for Government. For financial services, Zoom publishes no FINRA-specific AI guidance; firms subject to books-and-records and supervision obligations typically pair Zoom with archiving vendors that capture AI summaries, and should decide explicitly whether AI summaries are records. When in doubt, treat them as discoverable.
Frequently asked questions
Does Zoom sell meeting data to AI companies?
Zoom's terms prohibit using communications content to train Zoom or third-party models, and Zoom states third-party providers cannot retain or train on customer content. Selling meeting content is not part of any documented data flow.
Do OpenAI or Anthropic keep our prompts or transcripts?
Zoom states its third-party model providers operate under zero data retention policies, with narrow trust and safety exceptions.
Can users opt out individually?
Where admins allow it, users can toggle AI features for their own content, and participants can ask hosts to disable summary and questions in a meeting. Organizational opt-out is an admin setting.
Is the no-training promise different for ZoomMate?
Zoom's AI security and privacy documentation, which continued to carry the commitment as of August 2026, covers its AI portfolio including ZoomMate. Because ZoomMate can reach into connected systems like Salesforce and ServiceNow, extend your governance review to those connectors, not just meeting content.
Has any regulator taken action against Zoom over AI privacy?
Regulatory status and investigations can change. Legal teams should review current regulator publications, litigation databases, and contractual disclosures rather than relying on an absence of reported enforcement. The 2023 terms-of-service episode was resolved by Zoom's own rewrite, not by a regulator.
Zoom AI Companion in 2026: the complete guide · Is Zoom AI Companion free? · What does AI data governance actually require in 2026? · Zoom Agentic Search complete guide · Connect Salesforce, ServiceNow, SharePoint and Google Drive to Zoom AI · Zoom Post Meeting Automation Guide · Zoom Epic FHIR Integration
References
- Zoom Terms of Service, Section 10.2 (effective August 11, 2023), zoom.com/en/trust/terms/
- Zoom AI whitepaper, "Models, processing, storage and usage," library.zoom.com, retrieved August 6, 2026 (the former AI security and privacy page now redirects into the Zoom library)
- Zoom support KB0057861, "How Zoom AI Companion features handle your data"
- Smita Hashim, "How Zoom's terms of service and practices apply to AI features" (August 7, 2023, updated February 7, 2024), zoom.com/en/blog/zooms-term-service-ai/
- Zoom, "AI Responsibly: Zoom's Tailored Solutions for Data Governance" (October 16, 2025), zoom.com/en/blog/ai-companion-data-residency-options/
- Zoom, "Zoom launches AI Companion 3.0" (December 15, 2025), news.zoom.com
- Zoom AI whitepaper, data governance and privacy, library.zoom.com
- Zoom for Government FedRAMP JAB authorization (September 2024), news.zoom.com; zoom.com/en/trust/legal-compliance/fedramp/
- Zoom HIPAA compliance resources, zoom.com/en/trust/legal-compliance/hipaa-ready/; HIPAA Journal, "Is Zoom HIPAA compliant?" (updated January 21, 2026)
- TechCrunch and Termly coverage of the August 2023 terms-of-service controversy