Chinese AI firm Z.ai faces reputation hit after users spot unauthorised uploads
Chinese artificial intelligence company Z.ai is facing a trust crisis after developers discovered that its coding assistant tool, ZCode, was silently uploading local workspace data to external servers without explicit user consent. Even though the company, also known as Zhipu AI, apologised and patched the vulnerability, developers said the incident was likely to weaken its reputation, especially…
Chinese AI firm Z.ai is grappling with a trust crisis after developers found its coding assistant tool, ZCode, was uploading users' local workspace data without consent. Despite the company's apology and patching of the vulnerability, the incident is expected to weaken Z.ai's reputation, especially amid heightened cybersecurity concerns in the AI industry.
The issue surfaced when a Chinese tech blogger discovered a 313 megabyte file containing a commercial project's Git history was attempting to upload to Alibaba's cloud storage, with a smaller file successfully sent. Both files were encrypted and could only be decrypted with a private key held by Z.ai. The upload feature was enabled by default, with no option to disable it.
Other users also reported similar issues. Z.ai stated it had fixed the problem and apologized to affected users, promising to open-source ZCode's code and involve third-party assessments. The company also offered an additional weekly quota reset as compensation. However, the blogger questioned the validity of the "immediate destruction" claim.
The incident is seen as a significant trust concern, particularly given the increasing focus on user privacy and cybersecurity in the AI community.
Written by urgent.news from SCMP Tech's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.