Beijing-based Z.ai (Zhipu) said Monday it disabled some ZCode features after users reported the default Codebase Indexing tool uploaded entire local repositories to Alibaba Cloud without consent; it open-sourced the assistant, enabled zero-data retention, and cited an NSFOCUS assessment that data was deleted.
Beijing-based Z.ai, also known as Zhipu, said Monday, September 21, 2026, it had disabled some features of its flagship AI coding assistant ZCode after users reported the tool uploaded entire local code repositories to overseas cloud servers without consent, Reuters reported, bylined Laurie Chen.
Default indexing, Alibaba Cloud, no toggle
The company apologized after Chinese developers said ZCode had uploaded code data from open-source developer platform Git to Alibaba Cloud. In a Friday statement, Z.ai said the issue originated from ZCode’s Codebase Indexing feature, which was enabled by default, and that it had patched the software vulnerability. On Monday it pledged an ongoing product security vulnerability reporting and response process on its official ZCode account.
Users said uploaded data was encrypted with a backend private key held only by Z.ai, leaving them unable to open files or independently confirm deletion. Developers also wrote on X and RedNote that there was no toggle to disable the feature and no prior acknowledgement in Z.ai’s privacy policy. The South China Morning Post, reporting Saturday, attributed the discovery detail to independent technical blogger Ferstar, who said he found a compressed workspace snapshot pending upload to Alibaba Cloud after hundreds of failed attempts, encrypted so only Z.ai’s backend key could decrypt it.
Chengming Technology said Friday that six company coding workspaces were uploaded without consent, including source code, database passwords, and employees’ personal information. On Monday it retracted that claim, citing wrong evidence. Chengming did not immediately respond to Reuters’ request for comment.
Open source, zero retention, NSFOCUS assessment
Z.ai said Monday it open-sourced the coding assistant that runs its latest GLM-5.3 model, disabled certain features, and enabled a zero-data retention feature for developers and tech enterprises. An independent security assessment by a Chinese industry ministry–affiliated IT standards think tank and cybersecurity firm NSFOCUS found users’ code data had been deleted and was not retained by the cloud platform, the company said, promising a full report soon.
The rare public disclosure by a Chinese AI lab lands amid U.S. lab AI-hacking and rogue-agent headlines. China’s cyber regulator updated its AI safety framework last week, warning about shutdown resistance, evaluator deception, and sandbox escape. Z.ai said last month GLM-5.3 approaches Anthropic’s Mythos on vulnerability finding and delayed that release two weeks for safety — the first Chinese lab to explicitly delay a model for safety, Reuters noted.
Sources
- https://www.marketscreener.com/news/china-s-z-ai-disables-ai-coding-assistant-features-after-security-issue-ce785adbdf8bf125
- https://www.scmp.com/tech/tech-trends/article/3368159/chinese-ai-firm-zai-faces-reputation-hit-after-users-spot-unauthorised-uploads