Z.ai faces scrutiny over default data uploads in ZCode AI tool

Z.ai’s ZCode coding assistant is under investigation after it was discovered to have uploaded users’ local workspace data to external servers without explicit consent, raising concerns over transparency and security in AI development tools.

Z.ai, the Chinese artificial intelligence company also known as Zhipu AI, is facing a backlash after its ZCode coding assistant was found to have uploaded local workspace data to external servers without explicit user approval. The episode has sharpened concerns about how AI development tools handle private code, project files and other sensitive material, especially when they operate with default settings that users may not notice.

The problem came to light after an independent Chinese technical blogger, Ferstar, inspected a local directory used by ZCode and found a 313-megabyte compressed archive queued for upload to Alibaba Cloud. According to the account published by the South China Morning Post, the archive had failed to transfer hundreds of times, while a smaller file had already been sent. Ferstar said the files were encrypted and appeared to contain a snapshot of a commercial project, including its Git history.

Other developers reported similar behaviour, suggesting the issue was not isolated. Some observers said the uploads were tied to a repository indexing or wiki-generation feature that was switched on by default, meaning users would have needed to opt out of a process they may not have understood was active. That has intensified criticism that the tool’s design put convenience ahead of transparency and consent.

Z.ai said it had fixed the problem and apologised to users. The company also said it would open-source ZCode’s codebase and invite third-party assessors to review the system, with updates to follow. It added that users would receive an extra weekly quota reset as compensation. In a further clarification reported by Chinese technology outlets, the company said uploaded data was not permanently retained and was deleted after wiki generation, although Ferstar later questioned how that claim could be independently verified.

The incident is likely to matter more for trust than for the underlying GLM models themselves, according to a Shanghai-based AI developer quoted in Chinese media. But that distinction may be of limited comfort. A software engineer at a major Chinese robotics company said their employer had already restricted use of Z.ai tools over security concerns, while the episode has also revived comparisons with earlier AI coding-tool controversies involving Anthropic and xAI. With governments and industry groups increasingly focused on privacy and cybersecurity in AI systems, the case now sits squarely within a wider debate about how much code assistants should be allowed to see, store and transmit.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.