Zhipu AI has resolved a significant data privacy issue with its AI coding assistant ZCode by deleting all implicated cloud data, verifying the deletion through third parties, and announcing compensation for users affected by unauthorized data uploads.
- All cloud data involved in uploads deleted and verified by third parties.
- ZCode codes open-sourced; new versions prioritize explicit user-initiated uploads.
- Compensation offered via free Token credits and quota reset cards.
What happened
In mid-September 2026, a developer discovered that ZCode, an AI coding tool by Zhipu AI, was automatically uploading large encrypted packages containing users' entire project workspaces, including source code and configuration files, without clear disclosure or user consent. This raised concerns across the developer community and enterprise users about data security and unauthorized code exposure. The issue was traced back to an enabled-by-default upload feature in earlier ZCode versions.
In response, Zhipu AI quickly issued an apology, released updated ZCode versions removing the automatic upload mechanisms, open-sourced the software on GitHub, and engaged third-party organizations—the China Academy of Information and Communications Technology and NSFOCUS—to verify the deletion of affected cloud data stored on Alibaba Cloud. They confirmed all relevant data objects and storage buckets were fully removed.
Why it matters
The incident highlights critical tensions in AI-assisted software development tools between enhanced productivity and the protection of valuable code assets. Developers and enterprises need clear assurances that their sensitive code is not uploaded or used without explicit permission, especially amid growing AI adoption in coding workflows. Lack of transparency in data handling can erode trust in AI platforms.
Zhipu’s experience underscores the necessity for AI tool providers to offer transparent policies and controls that differentiate between user-initiated data uploads and automatic background processes. Security audits and open-source transparency are emerging as best practices for addressing user concerns and regulatory scrutiny in this sensitive area.
What to watch next
Going forward, Zhipu AI plans to enforce a strict “no upload unless initiated by the user” policy in ZCode's future updates, ensuring that code and project files remain local unless users opt in for cloud upload. The company’s compensation program, including free Token credits and quota reset cards for paid users, aims to restore customer confidence and encourage continued adoption.
The broader AI software development industry will likely face increasing pressure to balance AI capabilities with stringent data privacy standards. Observers should watch how other AI coding tool providers respond to similar challenges, the evolution of user data control mechanisms, and any regulatory developments emerging from this evolving trust and security landscape.