Chinese AI startup Z.ai has disabled certain features of its flagship AI coding assistant after users discovered the tool was uploading entire local code repositories to foreign cloud servers without consent. The company has since apologized, patched the vulnerability, and invited further community security scrutiny.
- Z.ai disabled default 'Codebase Indexing' after security concerns
- Independent review confirmed deletion of user code data
- Z.ai open-sourced AI model and promised transparency upgrades
What happened
Z.ai's AI coding assistant, ZCode, was found to upload entire local code repositories from users onto overseas cloud servers without explicit permission. This default-enabled feature, known as Codebase Indexing, raised alarms among Chinese developers who discovered their proprietary code had been transmitted to Alibaba Cloud. The company issued a public apology and quickly disabled the implicated feature while issuing a patch for the software vulnerability.
The incident, unusually admitted publicly by a Chinese AI lab, followed reports from affected developers on social media platforms. Some firms initially claimed that sensitive data, including source code and passwords, had been exposed. Z.ai responded by commissioning an independent security assessment from a government-affiliated standards body and cybersecurity firm NSFOCUS, which verified that user data had since been deleted and was not stored on the cloud servers.
Why it matters
This incident marks a rare public admission of a security breach by a Chinese AI company amid growing global concerns over AI safety and data privacy. It highlights risks inherent in AI assistants that have deep access to user environments, especially when default settings are not transparent or easily controllable.
Further, the case occurs alongside recent regulatory actions and policy updates in China aimed at managing AI risks, such as limiting AI model resilience to shutdown attempts and sandbox escapes. Z.ai’s response—disabling features, releasing an open-source AI model, and pledging ongoing security processes—sets a precedent for how Chinese AI startups might handle vulnerabilities and community trust going forward.
What to watch next
Z.ai plans to publish the full security assessment report soon, which will provide further details on the vulnerability and the measures taken. Observers will be looking closely at how effectively Z.ai can implement an ongoing vulnerability reporting and response process and maintain transparency with its developer community.
Given growing scrutiny in the AI industry on safety and privacy, Z.ai’s experience may influence regulatory actions in China and beyond. Developers and enterprises using Z.ai’s tools will be monitoring updates to ensure robust data protection features are in place, while the broader AI lab environment will watch how Chinese firms balance innovation with emergent security challenges.