Background
As AI technology rapidly grows and expands, businesses and educational institutions have begun to take advantage of and offer AI functionality for their services. While many AI tools offer new and interesting features, OIT must still prioritize security when evaluating these tools.
Issue
Zoom users have the ability to install third-party apps and integrations to their individual accounts. Some of these third-party apps allow the user to add an AI bot as a participant in every Zoom meeting they join. This can cause confusion and concerns for the Zoom meeting host as they were not expecting an AI bot to join their meeting. AI bots have the ability to provide meeting summaries, transcripts, and recordings to other meeting participants without the permission of the meeting host.
Resolution
On December 13, 2024, OIT began restricting access to certain AI assistant bots within Zoom and Microsoft 365. Restricting access to AI assistant bots will be an ongoing effort for OIT. Please see our Zoom App Marketplace service page for the most up-to-date approved or denied Zoom applications.
In the meantime, there are a few extra security measures that can be put in place for Zoom meetings.
Prevent bots from joining meetings:
- Enable the Zoom waiting room feature for Zoom meetings.
- If your meeting is exclusively for CU Boulder Zoom users, set your meeting to require participants to authenticate in order to join.
- Enable blocking users in specific domains. Blocking user examples: otter.ai, read.ai, fireflies.ai, etc
If a bot has already joined the meeting:
- Click Participants (people icon) in the Zoom meeting toolbar
- Find the bot’s name you want to remove and click the More icon (three dots) next to their name.
- Select Remove from the drop-down menu to remove the bot from the meeting.
Reporting AI Bots to OIT
The assistance of Faculty and Staff in reporting any unwanted Zoom meeting joining AI bots to oithelp@colorado.edu is greatly appreciated. This assistance will help keep Zoom meetings secure campuswide.
Using 3rd Party AI Zoom Apps (Disclaimer)
Zoom AI Companion is the default and recommended AI choice for Zoom meetings.
All additional third-party apps, for Zoom, are reviewed by the Zoom administrators, Information Communication Technology (ICT) accessibility, and IT security before being approved for use. If an approved Zoom application is found later on to have security concerns, that app may be disabled and/or blocked.