Z.AI got caught red-handed, then said sorry.
The Chinese AI company, also known as Zhipu AI and the maker of the GLM model family, spent days firefighting after developers discovered its ZCode coding assistant was silently uploading local workspace files to Alibaba Cloud. A developer known as Ferstar found that ZCode had compressed 313MB of his files, including what he believes was a commercial project, and tried 564 times to upload the encrypted archive without his consent. A separate 15KB file did make it out before anyone noticed. Another blogger, Feng Ruohang, reported the same behavior, and the upload feature reportedly had no off switch. Z.AI has since apologized, says it fixed the consent problem, claims any uploaded data was destroyed, and plans to open-source ZCode's codebase for outside review.
That last move is the interesting part. Promising to open-source a tool after getting caught quietly collecting user data is a trust-repair move, not a feature launch, and it only means something if outside reviewers get real access to the code. An unnamed engineer at a Chinese robotics company told SCMP their employer has already banned Z.AI's tools over the security concerns, which suggests some enterprise users aren't waiting for that review to finish.
None of this is unique to Chinese AI labs. Coding assistants sit on top of exactly the kind of sensitive local files - credentials, proprietary code, internal docs - that make a silent upload a bigger deal than a typical privacy slip. xAI's Grok Build and Anthropic's Claude Code have both faced comparable complaints this year. The pattern says more about how fast these tools are shipped than about any one company's intentions.
