Chinese artificial-intelligence startup Z.ai has disabled some features of its flagship ZCode coding assistant after users reported that local code repositories had been uploaded to cloud servers without their consent, Reuters reported on September 21.
Z.ai, also known as Zhipu, said the problem originated from a default-enabled “Codebase Indexing” feature and that it had patched the vulnerability. The company apologised and said it would establish an ongoing security-vulnerability reporting and response process. It also said it had open-sourced the coding assistant and enabled a zero-data-retention feature.
Reuters reported that an independent assessment involving a Chinese industry-ministry affiliated standards body and cybersecurity company NSFOCUS found that users’ code data had been deleted and was not retained by the cloud platform. One Chinese company had earlier alleged that sensitive workspaces, including source code and credentials, were uploaded, but later withdrew that statement and said its evidence was wrong.
The episode highlights the security and data-governance risks surrounding AI coding tools that can access private software repositories. Z.ai said a fuller security assessment would be released later and invited developers to continue reviewing ZCode for potential issues.


