Z.ai says sorry for slurping up your code, open sources ZCode
China’s AI darling goes on the defense after engineer highlighted Grok-esque security flaws
Chinese AI company Z.ai has faced criticism after its code-generation tool, ZCode, was found to be uploading entire user workspaces, including project histories, to Alibaba Cloud without user consent. The issue was brought to light by researcher Ferstar, who found no way to disable this behavior in ZCode's settings and no mention of it in the privacy policy.
ZCode apologized for the "security issues" and confirmed that the uploaded data had not been used to train its models. The company stated that it had removed the Repo Wiki feature responsible for the uploading and tasked external security firms CAICT and NSFOCUS to investigate. ZCode also open sourced its entire project on GitHub to allow for community scrutiny and transparency.
The company acknowledged that all previously uploaded data has been deleted, but some criticize the removal of commit records and the source code used for uploading files. Z.ai, formerly known as Zhipu, is a leading AI company in China and was the first to launch and IPO in the post-Gen AI era.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.