Chinese artificial intelligence company Z.ai, also known as Zhipu AI, is grappling with a significant trust issue after its coding assistant tool, ZCode, was found to be uploading local user data without clear consent. Despite swift patching and apologies, the incident is raising alarms among developers and tech communities about data privacy in AI software.
- ZCode silently uploaded local workspace files to Alibaba cloud without user consent
- Z.ai patched the vulnerability and promised open source reviews and user compensation
- Incident fuels wider concerns over privacy and security in China’s AI industry
What happened
Developers discovered that Z.ai’s coding assistant tool, ZCode, was automatically uploading encrypted local project data to external cloud servers owned by Alibaba without explicit user permission. An investigation by an independent Chinese tech blogger first revealed a 313MB compressed file containing commercial project details and Git histories repeatedly pending upload. Another user reported multiple files being sent in a similar manner. The upload feature was enabled by default without an opt-out control, heightening privacy worries.
In response to the outcry, Z.ai issued a public apology and manually fixed the vulnerability. The company stated that all uploaded data was immediately destroyed and committed to improving transparency by open-sourcing ZCode’s codebase and inviting third-party security assessments. Additional user compensation was offered through weekly quota resets. Despite these measures, affected developers remain skeptical about verifying data deletion and express concerns about the breach's implications.
Why it matters
This incident comes at a time when cybersecurity and data privacy are becoming crucial issues within the AI development community, particularly in China’s rapidly expanding AI ecosystem. Unauthorized data uploads not only undermine user trust but also pose risks to proprietary information and commercial confidentiality for developers relying on ZCode. Given the competitive nature of AI-driven coding assistants, trust is a vital component for user retention and market viability.
Security experts and developers have voiced concerns about the potential malicious intent behind the uploads, noting that such actions could tarnish Z.ai’s reputation more than damage its underlying AI models. The episode also prompted companies and individuals to restrict or ban the use of Z.ai’s tools internally, signaling possible commercial fallout. Furthermore, this aligns with earlier controversies involving AI tools like Anthropic’s Claude Code, underscoring systemic challenges in safeguarding user data in AI deployments.
What to watch next
Industry watchers and users will closely monitor Z.ai’s efforts to rebuild trust, particularly through its plans to open-source ZCode’s codebase and subject it to external audits. The transparency and effectiveness of these measures will largely determine whether users and partners regain confidence in the company’s products. Moreover, Z.ai’s approach to user communication and compensation could set a precedent for handling future AI data privacy incidents in China.
The incident’s ramifications may extend beyond Z.ai, influencing regulatory scrutiny and cybersecurity standards in China’s AI sector. With an upcoming high-profile meeting expected between Chinese President Xi Jinping and US President Donald Trump, discussions around AI governance, data privacy, and cross-border cybersecurity cooperation may be impacted by such public trust issues. Stakeholders should also watch how other AI companies address similar challenges amidst intensifying global demands for responsible AI deployment.