Z.ai Faces Trust Crisis After ZCode Data Upload Discovery
  • News
  • Asia

Z.ai Faces Trust Crisis After ZCode Data Upload Discovery

Z.ai apologized and patched the issue after developers found silent workspace data uploads

9/21/2026
•Ghita Khalfaoui
Back to News

Chinese artificial intelligence company Z.ai, also known as Zhipu AI, is confronting a major trust crisis after developers discovered that its coding assistant ZCode was silently uploading local workspace data to external servers without explicit user consent. Independent developers identified the behavior while inspecting the tool, prompting an apology and a patch from the company. The incident raises fresh questions about data security and user privacy in the rapidly evolving artificial intelligence sector.


How the Unauthorized Transfers Were Found

The issue surfaced when Chinese technical blogger Ferstar examined ZCode's local directory and discovered a compressed 313-megabyte file pending upload to Alibaba Cloud storage after 564 failed attempts. A smaller encrypted file of 15 kilobytes had already been sent successfully. The larger archive contained a snapshot of a commercial project, including its Git history, and could only be decrypted with a private key held on Z.ai's backend.

Default Settings and User Exposure

Ferstar noted that the upload mechanism was enabled by default and offered no button to disable it. Other users reported similar findings, with tech blogger Feng Ruohang observing at least three files uploaded from his system. The files were encrypted, which prevented users from inspecting their contents before transmission.

Company Apology and Policy Changes

Z.ai issued a statement in its official Feishu community on Friday confirming it had fixed the issue and apologised to affected users. The company pledged to open-source ZCode's codebase, invite third-party assessors, and publish review updates. It also offered all ZCode users an additional weekly quota reset as compensation.

Questions Over Data Destruction

Z.ai sought to reassure users that uploaded data was immediately destroyed, but the original blogger questioned how that claim could be independently verified. Late Sunday, the company announced that its model-as-a-service platform would adopt a data non-retention policy to prevent persistent storage of user inputs and outputs. Some data may still be retained for certain API services or to meet legal requirements.

Developer and Corporate Reactions

Shanghai-based AI developer Tuxi said the incident could damage Z.ai's reputation more than its underlying models, describing the behavior as similar to stealing from users. A software engineer at a leading Chinese robotics company said their employer had internally banned Z.ai tools over security concerns. The developer noted that GLM models could still be used with other coding tools, limiting the impact on model adoption.

A Wider Privacy Debate

The ZCode incident follows earlier controversies involving Anthropic's Claude Code and Grok Build from Elon Musk's xAI. It also comes as the global AI community places greater emphasis on user privacy and cybersecurity. These concerns may feature in discussions during an expected meeting between Chinese President Xi Jinping and US counterpart Donald Trump.


The ZCode episode shows how quickly developer trust can erode when data handling practices are unclear or enabled without consent. While Z.ai has moved to patch the vulnerability and introduce new privacy safeguards, the long-term impact on its reputation remains uncertain. As AI coding assistants become more integrated into professional workflows, transparent data policies and verifiable security measures will be essential to maintaining user confidence.