Zendesk and AI

Research date: 4 October 2026
Edition: First Zendesk baseline report
Method: Review of Zendesk's public documentation. No signed-in business account was inspected and no controls were tested in a live account.

Summary

Zendesk AI can assist staff, classify tickets and answer customers. Some staff tools are enabled without purchasing the full Copilot add-on.

  • By default: Writing tools and ticket summaries are documented as enabled on eligible plans. Intelligent triage defaults on with Copilot and off without it.
  • Beyond the default: Suggested replies and procedures, customer-facing agents, translation, additional summaries, custom actions and connected action flows.
  • Outside Zendesk: AI can use external knowledge sources and crawled content. Configured actions can change information in connected systems, including consequential operations such as refunds.
  • Business exposure and learning: Restricted internal articles can inform outward replies even when the customer cannot read the original article. Actions marked pre-approved can execute without a staff prompt. Zendesk’s own research and model-training opt-out requires a support request; third-party generative-model commitments are separate.

The main exposure: Internal knowledge can reach customer replies, and pre-approved actions can take effect beyond Zendesk before a person reviews them.

Business finding

Zendesk is a customer-service platform. AI can operate behind a staff member's reply, classify incoming requests or respond directly to customers. Removing a customer-facing AI agent does not establish that these other uses have stopped.

The business can manage individual features and channels, limit selected sources and request an opt-out from research and model training. This review did not establish one switch that stops every form of Zendesk AI processing. Zendesk's feature-control page expressly separates staff tools from AI agents. [1]

The main business question is therefore broader than whether a chatbot is visible: which customer information can AI process, what can it do with that information and who can stop it?

Where is AI operating?

Staff assistance: Writing tools can rewrite support replies and saved response templates. Ticket summaries condense conversations. On eligible Professional plans and above, some tools are included without purchasing the full Copilot add-on. Writing tools and summaries are documented as enabled by default. Not buying an AI add-on is therefore not a reliable way to exclude AI. [2]

Background classification: Intelligent triage identifies a request's topic, language, sentiment and details such as product names. Its classifications can support routing and other workflows. The setup guidance says classifications default on with Copilot and off without it; check the account rather than assuming a universal default. [3]

Assistance that can act: Auto assist suggests replies and steps using tickets, procedures and knowledge sources. It works behind the staff interface, so a customer may receive an AI-assisted response while dealing with a person. [4]

Customer-facing AI: AI agents operate on selected channels. Record each agent and the channels on which it is live, including email and messaging where applicable. [5]

Also inventory translation, article assistance, call summaries and voice suggestions if used. These have their own controls. [1]

Who controls it?

Administrators control feature settings and can select staff groups for writing tools, summaries and auto assist. Auto assist can also be targeted to particular tickets and channels using rules that add an enabling tag. [6][7][8]

The business should name the person responsible for each feature, its sources and any connected systems. If an external partner administers Zendesk, identify who in the business can require a change and who can perform it.

Review the credentials used by automated actions. Zendesk warns that an action's connection can have greater access than the staff member or customer involved. The visible user's permissions may therefore tell only part of the story. [9]

What can the business switch off?

Staff writing and summaries

For writing tools, use Admin Center → AI → Agent copilot → Writing, clear Enhance writing, then save. This page also controls which groups have access. Help-center writing tools are managed separately. [6]

For ticket summaries, use Admin Center → AI → Agent copilot → Suggestions → Ticket context, clear Summarize conversations, then save. Check the separate internal-notes option if retaining summaries. [7]

For auto assist, review Admin Center → AI → Agent copilot → Auto assist → Settings, including Show auto assist replies and actions in the agent composer. Review its group access and ticket-enabling rules too. The published setup describes these controls; confirm the effect of disabling them on new and existing tickets. [8]

Background classification

In Admin Center → AI → Intelligent triage, open the relevant classification's settings, clear Detect and save. Repeat for topic, sentiment and language. For each entity, select Don't update ticket fields, clear Highlight entity values in all messages and save. [10]

Review rules that relied on those classifications. Stopping new detection should not be treated as proof that previous labels, rule effects or stored records have disappeared.

Customer-facing agents

For supported current agents, use AI agents workspace → Dashboard → agent options → Manage channels, deselect the channels and save. Modified routing rules or email automation triggers can make this menu unavailable, requiring review of those rules instead. [5]

Older configurations have different routes. Zendesk's control guide directs older Advanced customers to remove messaging routing rules or disconnect email, and legacy customers to remove all channels through republishing. Check which instructions match the account. [1]

Provide a working staff-support route before switching off customer-facing automation. Hiding the widget alone does not establish that email or another channel has stopped.

What information and actions can the business restrict?

Information or capability Business check
Ticket conversations Check which features read the ticket and whether summaries include internal notes. [7]
Procedures, help articles and past cases Review the sources available to auto assist, including similar solved tickets. [4]
Connected knowledge Inventory external sources and crawled content; inspect active connections. [8]
Customer-facing restricted articles Check the source connection type and signed-in customer permissions. [11]
Changes in connected systems Inspect action credentials, permitted operations and approval requirements. [9]

Internal information can reach an outward reply

Zendesk says auto assist can use content from selected user segments regardless of whether the staff member or customer belongs to those segments. Although the original article remains restricted, its content can inform a reply to someone who cannot view it. Public articles matching the ticket's brand and language cannot be excluded from auto assist. [4]

The business should therefore choose source material according to what may safely influence customer replies, then check the replies themselves.

Customer-facing AI agents have a different permission model. Zendesk's 2026 migration guidance says a directly connected help center respects article-view permissions, but a Zendesk connector set to Everyone can make otherwise hidden content available. Existing imported content can remain available after migration. Review the actual source route. [11]

Approval can be bypassed by configuration

Custom actions and action flows marked pre-approved execute without a staff approval prompt. Zendesk warns they may run in a different order or before earlier conditions are satisfied. It recommends staff approval for actions that change information, such as refunds. [9]

For consequential actions, establish who must approve, what that person sees and what prevents execution if approval is refused. A written procedure alone does not demonstrate that the action will wait.

Can the business refuse use of its information for training?

Third-party generative models: Zendesk says its generative features use pre-trained models and third parties do not use customer inputs to train models or improve their services. This commitment differs from Zendesk's own machine-learning training. [12]

Zendesk research and model training: Its service-specific terms provide an opt-out by contacting Zendesk customer support and identifying the Zendesk subdomains to exclude. Request written confirmation of the scope, affected products and effective date. The reviewed terms do not promise removal of learning already incorporated into models. [13]

Information cleaning: Zendesk describes removing identifier fields and certain identifying text before shared-model training. For older Advanced/Ultimate training datasets, it says customers determine sanitation. Cleaning information is different from refusing its use. [12]

Storage is a separate question: Zendesk documents zero-retention model-provider processing, either through hosted models or direct provider endpoints. This does not establish deletion of tickets, generated replies, summaries or action records held in Zendesk and connected services. [14]

An opt-out from training also does not stop enabled AI processing information to deliver a service. Record feature use, source access, training choices and retention separately.

How can the business check that its choices worked?

These are proposed business checks, not tests completed for this report:

  1. Record the plan, add-ons, enabled features, AI agents, channels, owners and change dates.
  2. Reopen settings after saving. Check staff groups with and without access.
  3. Send harmless test requests through every affected channel. Confirm that a person can receive and handle requests after AI is removed.
  4. Check new tickets for classifications and inspect the rules that depend on them.
  5. Use harmless internal test content to check whether restricted information appears in generated replies.
  6. Test consequential actions, refusal of approval and connected-system results. Review pre-approved actions in ticket events and the conversation log. Zendesk documents these records for automatic actions. [9]
  7. Keep support confirmation of the training opt-out for each named subdomain. Ask separately about retained information and previous training.

For migrated AI agents, Zendesk says restricted-content testing requires the live authenticated help-center widget; the test widget does not support authentication. A successful anonymous preview therefore cannot establish that signed-in access restrictions work. Conduct a controlled test with authorised test accounts. [11]

Observable checks can establish settings and behaviour. They do not independently verify provider compliance or prove the complete absence of background AI.

What does the business lose, retain or need to replace?

Disabling assistance means staff may need to write replies, read conversations, categorise requests and retrieve guidance manually. Removing customer-facing automation requires enough staff capacity and a clear way for customers to obtain help.

Retaining selected tools may save staff time and improve consistency. These are potential benefits to measure against review effort, incorrect classifications, corrections and repeat enquiries. A closed ticket should not be counted as success without checking whether the customer received a useful resolution.

Review usage and costs separately. Zendesk measures AI-agent usage through automated resolutions, while some included staff tools have a limited allowance and the full Copilot add-on changes access. Confirm the account's current terms before estimating savings. [5][2]

This review did not establish whether a training opt-out affects every product's functionality or commercial terms. Obtain confirmation rather than assuming either a penalty or no consequence.

Control assessment

Requirement Finding
Stop staff assistance Individual feature controls and selected group access are documented.
Stop customer-facing agents Channel removal is documented; older or customised configurations differ.
Stop classification Separate controls exist for detection and entities.
Restrict source material Source controls exist, but generated replies can cross original viewing boundaries.
Require approval for actions Review pre-approval, connection privileges and actual execution.
Refuse Zendesk research and training Support request naming the subdomains is documented.
Prevent third-party generative-model training Published commitments cover Zendesk's documented provider routes.
Disable every AI process with one switch Not established.

Sources and scope

Official Zendesk sources checked on 4 October 2026:

  1. Turning Zendesk AI features on or off
  2. Managing Copilot AI features and usage allowance
  3. Automatically classifying tickets with intelligent triage
  4. About auto assist
  5. Activating and managing AI agents
  6. Turning enhance writing off or on
  7. Configuring AI-generated ticket summaries
  8. Turning on and configuring auto assist
  9. Actions for auto assist and action flows
  10. Turning off topic, sentiment, language or entity settings
  11. AI agents workspace migration and knowledge/search updates
  12. Zendesk AI Data Use Information
  13. Zendesk service-specific terms
  14. Generative AI at Zendesk

This report covers principal Zendesk customer-service AI, Copilot, classification and data-use controls. It is not a complete audit of Zendesk QA, workforce management, Forethought, marketplace applications, custom integrations or every voice feature. Availability depends on plans, configuration and migration stage. Provider statements are distinguished from independent verification.

Unresolved: account-specific defaults and migration; full product coverage of training refusal; retention and previous training effects; stopping actions already sent to another service; geographic processing for each route; independent verification of provider commitments.

Changes since previous Zendesk report: None. This establishes the first Zendesk baseline for subsequent monthly research.