Z.ai disables AI coding tool after uploading user code to cloud
Chinese AI startup apologizes for default feature that sent developers' repositories to Alibaba Cloud without consent.
Security breach prompts rare disclosure from Chinese AI lab
Chinese AI startup Z.ai has disabled key features of its ZCode coding assistant after the tool uploaded developers' entire local code repositories to overseas cloud servers without their knowledge or consent. The Beijing-based company, also known as Zhipu, issued a public apology following complaints from Chinese developers who discovered their code had been sent to Alibaba Cloud.
According to details first reported by Reuters, the issue stemmed from a "Codebase Indexing" feature that was enabled by default in ZCode. Developers reported on social media that the tool had uploaded their data from the open-source Git platform, with no toggle available to disable the feature and no mention of the behavior in Z.ai's privacy policy.
One affected company, Chengming Technology, initially stated that six of its coding workspaces were uploaded without consent, including sensitive information such as complete source code, database passwords, and employee personal data. The firm later retracted its statement, saying it had "wrong evidence," though it did not respond to requests for further comment.
Why it matters
The incident highlights the security risks inherent in AI-powered development tools that integrate deeply with developers' workflows. As coding assistants become standard in software development, the default configurations and data-handling practices of these tools carry significant implications for intellectual property protection and enterprise security. The episode also represents a rare public acknowledgment of a security issue by a Chinese AI lab, coming at a time when both Chinese regulators and global observers are intensifying scrutiny of AI safety risks.
Response and remediation
Z.ai said it patched the software vulnerability and committed to establishing an ongoing security vulnerability reporting process. The company open-sourced the coding assistant, which runs on its GLM-5.3 AI model, and disabled certain features in an effort to increase transparency.
Developers initially expressed concern that uploaded data was encrypted with a backend private key held only by Z.ai, preventing them from independently verifying deletion. In response, Z.ai commissioned an independent security assessment from the Chinese industry ministry's affiliated IT standards think tank and cybersecurity firm NSFOCUS. The assessment reportedly confirmed that user code data had been deleted and was not retained by the cloud platform.
The company said it has now enabled a zero-data retention feature on the coding assistant and pledged to release the full security assessment report soon.
Broader context
The disclosure comes amid heightened attention to AI security risks globally. China's cyber regulator released an updated AI safety framework policy the same week, warning about AI models' potential for shutdown resistance, evaluator deception, and sandbox escape. Several leading U.S. AI companies have also announced AI hacking and "rogue" AI agent incidents in recent weeks.
Z.ai had previously positioned itself as safety-conscious, becoming the first Chinese lab to explicitly delay an AI model release for safety reasons when it conducted a two-week review before releasing its GLM-5.3 model last month. The company said that model approaches Anthropic's Mythos in finding software vulnerabilities.
Laurie Chen reported the story for Reuters.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call
