Zoom executes BAAs but does not state whether AI Companion outputs are in scope · Does not use customer content to train Zoom's or third-party AI models · Outputs stored under your account's retention settings
| AI Companion - admin-enabled | |
|---|---|
| HIPAA BAA | Zoom executes BAAs, but its public HIPAA page does not state which plans qualify, whether AI Companion outputs are in scope, or what configuration is required |
| Trains on your data | No"Zoom does not use any customer audio, video, chat, screen sharing, attachments, or other communications-like customer content... to train Zoom's or its third-party artificial intelligence models" |
| Survives deletion | AI Companion outputs are stored per the customer's retention settings; Zoom states customers may choose the retention period for "some of the AI Companion outputs" - the scope of "some" is not defined |
| Deployer / admin log access | Admins enable and manage features in the Admin Portal; summaries are stored in the web portal under account, group or user retention settings. No dedicated audit-export path specified |
| Third-party attestation | SOC 2 + HITRUST report referenced for healthcare customers |
The assumption that an existing Zoom BAA automatically covers AI Companion outputs - Zoom's public HIPAA page does not state this. Also the assumption AI Companion is off: admins enable it account-wide, and hosts activate it per meeting
Vendor terms change without notice. This page reflects what Zoom AI Companion published as of September 2, 2026. Re-verified quarterly.
If you need a scored Go / Conditional Go / No-Go verdict for a vendor decision — including a vendor not listed here — that's an AI Vendor Risk Assessment: three binary industry gates, nine scored criteria, four provenance fields on every finding. $997, delivered in 48 hours.
See how AVRA works →Want all 13 tools in one file?
Covers 22 tiers across 13 tools — same sourcing, side by side, printable for a vendor file.