Is Zoom AI Companion Private? What AI Companion 3.0 Actually Does With Your Meeting Data
Published August 03, 2026
- Zoom AI Companion 3.0 launched in December 2025 with agentic workflows and a federated AI approach that routes data to OpenAI, Anthropic, and NVIDIA Nemotron models.
- Since January 26, 2026, participants must click 'Agree' to a disclaimer or lose mic and camera — a consent model that legal scholars and universities are already flagging.
- Zoom's 'we don't train on your content' pledge does not mean your transcripts stay private — they still leave your machine and are retained by third-party subprocessors.
- AI Companion can now join Microsoft Teams and Google Meet meetings as a guest, expanding the same all-party-consent exposure that drove the Otter.ai and Fireflies class actions.
- On-device tools like Basil AI eliminate the subprocessor chain entirely: no cloud disclaimer, no federated model call, no third-party data retention.
Quick answer: Zoom AI Companion 3.0 is not a private, on-device assistant. It sends meeting transcripts to Zoom's cloud and, under Zoom's federated AI approach, routes some requests to third-party models from OpenAI and Anthropic. Zoom pledges not to train on customer content, but data still leaves your machine, is retained by subprocessors, and — as of January 26, 2026 — participants must click 'Agree' to a disclaimer or have mic and camera disabled.
Zoom AI Companion is not a private, on-device assistant — and with the December 2025 launch of AI Companion 3.0 and the January 26, 2026 rollout of a forced consent disclaimer, the gap between what users think it does and what it actually does with meeting data has widened. Under Zoom's own "federated AI" architecture, a single meeting summary can be processed by Zoom's models, by OpenAI, by Anthropic, or by open-source models like NVIDIA Nemotron. Zoom promises not to train on customer content, but training is only one of several things a cloud AI provider can do with your transcript — and by the time the disclaimer pops up on your screen, most participants no longer have a meaningful choice.
What Changed With AI Companion 3.0
On December 15, 2025, Zoom announced the next evolution of its assistant. According to Zoom's AI Companion 3.0 launch announcement, the new version introduces "agentic AI" features that go well beyond meeting summaries. AI Companion can now locate information across meeting summaries, transcripts, and notes in Zoom Workplace, plus connected third-party apps including Google Drive and Microsoft OneDrive, with Gmail and Outlook support coming.
Two facts about that architecture matter for privacy. First, AI Companion 3.0 explicitly uses a "federated AI approach that combines the power of Zoom's own LLMs and SLMs with leading third-party LLMs from OpenAI and Anthropic" — and open-source models like NVIDIA Nemotron. Second, the new conversational work surface pulls context from your meetings without requiring you to upload transcripts, because the transcripts are already sitting in Zoom's cloud. Agentic AI doesn't work without a lot of your data staying accessible to the model layer.
The January 26, 2026 Disclaimer Isn't Really Consent
Beginning January 26, 2026, Zoom rolled out a new AI Companion Policy Disclaimer that appears when a host enables Meeting Summary or Smart Recording. As Stanford University IT documented, all meeting participants must either click "Agree" to remain active in the meeting or click "Leave Meeting." If you take no action, the desktop pop-up disappears after 90 seconds, and while you can stay in the meeting, your microphone and camera are disabled until you agree.
The mechanics get even more coercive in conference-room deployments. In a Cisco conference-room setup, participants can press * to leave or # to consent — and if you make no selection within 30 seconds, Stanford's Zoom documentation notes, you consent automatically. That is not the standard the Ninth Circuit has been applying to the wave of AI-notetaker cases in 2025 and 2026, and it's not the standard California's Invasion of Privacy Act was written to require.
Why That Matters for CIPA and Wiretap Exposure
In the consolidated In re Otter.AI Privacy Litigation coverage from the National Law Review, the complaint alleges that Otter automatically joined Google Meet, Zoom, and Microsoft Teams meetings and "records, accesses, reads, and learns" the contents of conversations involving non-users without their consent. The article notes an important point often missed by IT teams: the fact that a notetaker does not store audio does not eliminate exposure, because CIPA prohibits "reading, attempting to read, or learning" the contents of communications without consent. A pop-up participants can dismiss or auto-consent to in 30 seconds is a weak record when a plaintiff's lawyer starts asking whether all-party consent was actually obtained.
"We Don't Train On Your Content" ≠ "Your Content Stays Private"
Zoom repeatedly emphasizes — including on its public privacy page and its AI Companion Security and Privacy resource — that it does not use customer audio, video, chat, screen sharing, attachments, or other communications-like customer content to train Zoom's or its third-party AI models. That's a meaningful commitment. It is also not the same as "your content stays private."
On the Zoom Community forum, Zoom staff clarified that even when data is shared with third-party model providers, "we do not allow third-party AI models to use your data to improve or train their models," but "your data may be temporarily retained by those third-parties for Trust and Safety purposes or to comply with legal obligations." Translation: OpenAI and Anthropic see your meeting content, keep it long enough to run their own trust-and-safety pipelines, and may retain it further if legally compelled.
Zoom's own data residency blog post confirms the split: only the Zoom-hosted Models Only (ZMO) deployment keeps processing inside Zoom's trust boundary. Any deployment using external providers processes AI Companion data "outside our trust boundary" — Zoom's own words. Whether that matters to you depends entirely on whether "my meeting summary might be temporarily processed by OpenAI" is compatible with your firm's confidentiality obligations.
Zoom AI Companion Can Now Join Teams and Google Meet
The privacy exposure isn't confined to Zoom-hosted meetings. Under a feature Zoom rolled out in 2026, licensed users can invite Zoom AI Companion to attend meetings on third-party platforms including Microsoft Teams and Google Meet, where it joins as a guest, transcribes the meeting, and emails a summary. UW-Madison's IT documentation frames this as an alternative to "unapproved third-party AI note taking apps such as Fireflies, Otter.ai, Read.ai, and more."
The problem: from a CIPA or Illinois BIPA perspective, a Zoom bot joining a Teams meeting looks a lot like an Otter bot joining a Zoom meeting. It's the same fact pattern — an AI participant added by one attendee, capturing the voices of others, processed by a cloud vendor and its subprocessors. We wrote about the mechanics of that exposure in our analysis of employer liability for AI notetakers, and the pattern doesn't change when the brand on the bot is Zoom instead of Otter.
Cloud vs. On-Device AI Meeting Notes: A Direct Comparison
| Dimension | Zoom AI Companion 3.0 (Cloud + Federated) | Basil AI (On-Device) |
|---|---|---|
| Processing location | Zoom cloud + third-party models (OpenAI, Anthropic, NVIDIA Nemotron) | Your iPhone, iPad, or Mac — Apple SpeechAnalyzer / Neural Engine |
| Subprocessors touch content | Yes — federated AI approach routes data to external providers | None — no vendor server holds the recording |
| Model training on your content | No (per current terms) | No (technically impossible — data never leaves the device) |
| Third-party retention | "Temporarily retained" for trust & safety and legal compliance | None |
| Consent mechanism | Forced disclaimer; 30–90s auto-consent in some rooms | User controls their own device; no bot to consent to |
| Works offline | No | Yes — full transcription without internet |
| Subpoena surface | Zoom's servers, plus subprocessor servers | Only your device — no third-party custodian to serve |
What This Means for Regulated Industries
Universities are already treating AI Companion as a partial-use tool, not a general-purpose one. Northwestern University's IT department has approved AI Companion only for Level 1 and 2 data, with Level 3 and higher — PHI, HIPAA-covered data, and Business Sensitive Data — prohibited in any use case where AI Companion is present. Michigan State's IT team confirmed AI Companion will not be enabled on HIPAA-protected Zoom instances like MSU Healthcare. UC Irvine excludes its HIPAA Zoom instance entirely.
Those aren't marketing choices — those are institutions with in-house counsel who read Zoom's DPA and decided the federated-AI architecture wasn't compatible with their regulatory posture. That is a data point regulated professionals should not ignore.
GDPR and the EU AI Act Layer
For European deployments, the picture gets more complex. Article 5 of the GDPR requires data minimization and purpose limitation — principles that sit awkwardly with a federated architecture where a single meeting can be routed through multiple external processors. As HR Executive reported in April 2026, beginning in August 2026 the EU AI Act introduces a separate layer of obligation for AI systems used in worker monitoring and management — a category that could encompass tools offering sentiment analytics or productivity scoring alongside transcription. In co-determination countries like Germany and France, deploying an AI notetaker may require works-council consultation before rollout.
What Zoom AI Companion Is Actually Good At (Credit Where It's Due)
None of this means AI Companion is bad software. It has real strengths: agentic retrieval across Docs, Drive, and OneDrive; conversational catch-up for late joiners; smart chaptering of recordings. For low-sensitivity internal meetings inside a Zoom-first organization, it's a genuine productivity gain. Zoom's responsible-AI documentation is more transparent than most cloud vendors publish, and the no-training pledge is unusually explicit.
The question isn't whether AI Companion is a well-built product. It is. The question is whether the shape of that product — cloud-first, federated across external LLM providers, with agentic retrieval reaching into your Drive and OneDrive — is the right shape for your specific meetings. For attorney-client calls, therapy sessions, deal-team discussions, or any conversation involving MNPI, the answer is usually no. For a weekly engineering standup, it might be fine.
How Basil AI Solves This
Basil AI is built on a different premise: the meeting should never leave your device in the first place. Instead of routing audio to Zoom's cloud and then federating to OpenAI or Anthropic, Basil uses Apple's on-device Speech framework and, on iOS 26 and macOS 26, the new SpeechAnalyzer API — which Apple's speech-recognition documentation and third-party analysis describe as fully on-device, with no server fallback. There is no subprocessor list because there are no subprocessors. There is no forced-consent disclaimer for other participants because Basil isn't a bot that joins their meeting; it's a recorder running on your device, the same way a notepad would be.
That architecture solves the specific things AI Companion 3.0 does not: no cloud storage of your transcripts, no federated model calls that expand the subprocessor chain, and no data-residency ambiguity. If you want the productivity of AI meeting notes without inheriting Zoom's, OpenAI's, and Anthropic's data-processing terms, on-device is the only architecture that gets you there. For a deeper look at the underlying technology, see our guide to iOS 26 on-device transcription and our comparison of how to block external AI bots from Teams meetings.
What On-Device Doesn't Solve
Basil AI's on-device architecture is a data-flow fact, not a compliance guarantee. It does not, on its own, satisfy state wiretap statutes — you are still responsible for obtaining all-party consent in California, Illinois, Massachusetts, and other two-party-consent jurisdictions. It does not satisfy financial-services recordkeeping obligations under SEC Rule 17a-4 or FINRA 4511; those rules require preservation of business communications, and choosing where they're processed is separate from choosing whether to preserve them. It does not preempt EU AI Act obligations if your usage falls into a high-risk worker-monitoring category. What it does do is remove the third-party subprocessor chain — which is often the biggest single source of privacy exposure in a cloud-AI notetaker deployment.
A Practical Checklist Before Enabling AI Companion in Your Org
- Read Zoom's current DPA and confirm whether your deployment is Zoom-hosted Models Only (ZMO) or a federated deployment that includes OpenAI/Anthropic.
- Map your consent story — is a 30-second auto-consent prompt in a conference room defensible under your local wiretap statute? For California and Illinois, the answer is usually no.
- Segment your Zoom accounts — as MSU, Northwestern, and UCI have done, keep AI Companion off HIPAA-covered accounts entirely.
- Audit third-party subprocessor lists — federated AI means your subprocessor list is longer than "Zoom."
- Consider on-device tools for the highest-sensitivity meetings — attorney-client, executive strategy, deal team, therapy, coaching. The cloud round trip isn't worth the exposure.
The Bottom Line
Zoom AI Companion 3.0 is a well-engineered cloud AI product with a transparent no-training pledge and a real disclaimer mechanism. It is not a private, on-device assistant, and Zoom has never claimed it was. The mistake most organizations make is assuming that "we don't train on your content" is the same as "your content is safe" — those are two different statements, and the gap between them is where the OpenAI and Anthropic subprocessors live. If that gap matters to your practice, your patients, your clients, or your regulators, the answer isn't a better disclaimer. The answer is an architecture where the transcript never leaves the device in the first place.
Try Basil AI: 100% On-Device Meeting Notes
No cloud, no subprocessors, no federated model calls. Just private meeting transcripts and summaries that stay on your iPhone, iPad, or Mac.
Frequently Asked Questions
Does Zoom AI Companion train AI models on my meeting data?
No. Zoom's current terms (reviewed April 2026) state that Zoom does not use customer audio, video, chat, screen sharing, or other communications-like customer content to train Zoom's or its third-party AI models. However, that promise only covers model training — your transcripts and summaries still leave your device, are processed in Zoom's cloud, and may be temporarily retained by third-party subprocessors like OpenAI and Anthropic for trust-and-safety and legal-compliance purposes.
Which third-party AI models does Zoom AI Companion use?
Zoom uses a 'federated' approach that combines Zoom's own large and small language models with third-party LLMs from OpenAI and Anthropic, and open-source models like NVIDIA Nemotron. That means a single meeting summary may be processed by any of several external providers, each with its own data-handling terms. Zoom requires subprocessors to satisfy obligations equivalent to Zoom's Data Processing Addendum, but the data still leaves Zoom's trust boundary.
What happens if I don't accept the AI Companion disclaimer?
Since January 26, 2026, when a host enables AI Companion features participants must click 'Agree' or 'Leave Meeting.' If you take no action, you can stay in the call but your microphone and camera are disabled until you agree. On desktop the pop-up disappears after 90 seconds; on some conference-room systems, no selection within 30 seconds counts as automatic consent. That is coerced consent, not informed consent.
Can Zoom AI Companion join Microsoft Teams or Google Meet meetings?
Yes. Zoom now lets licensed users invite AI Companion into meetings on third-party platforms like Microsoft Teams and Google Meet, where it joins as a guest, transcribes the call, and emails a summary. That means a Zoom AI bot can appear in a meeting hosted on a completely different platform — expanding the surface area of consent problems flagged in cases like In re Otter.AI Privacy Litigation.
Is Zoom AI Companion HIPAA-safe for therapists and clinicians?
It depends on the deployment, but most universities and healthcare organizations block it on HIPAA-covered accounts. Michigan State, for example, explicitly does not enable AI Companion on HIPAA-protected Zoom instances, and UC Irvine excludes its HIPAA Zoom users entirely. Northwestern prohibits Level 3 data (PHI) in any meeting where AI Companion is present. If you handle protected health information, an on-device transcription tool avoids the cloud subprocessor chain altogether.
How does Basil AI differ from Zoom AI Companion?
Basil AI transcribes and summarizes meetings entirely on your iPhone or Mac using Apple's on-device SpeechAnalyzer framework. Audio never leaves the device, no subprocessors touch the transcript, there is no federated model call, and there is no cloud disclaimer to force on other participants. You keep the productivity — summaries, action items, speaker labels — without adding OpenAI, Anthropic, or Zoom to your data-processing chain.