Xiaomi's MiMo-V2.6 Is Now the #1 Open-Weight AI Model in the World
We test the top AI tools for writing, video, images & music — so you don't have to.
Explore AI Tools
Chinese AI startup Z.ai (also known as Zhipu) has disabled features of its flagship AI coding assistant, ZCode, after developers discovered it was uploading their entire local code repositories to overseas cloud servers — without their consent.
The issue surfaced last week when developers posted on social media that ZCode had uploaded their code data from Git to Alibaba Cloud. The culprit was ZCode's “Codebase Indexing” feature, which was enabled by default, had no toggle to turn it off, and was not mentioned in the privacy policy.
One Chinese tech firm, Chengming Technology, said six of its company coding workspaces had been uploaded without consent, including complete source code, database passwords, and employees' personal information. It later retracted the statement, saying it had “wrong evidence”.
Z.ai apologized, said it patched the software vulnerability, open-sourced ZCode so developers can review it, and enabled a zero-data retention feature. An independent security assessment by a Chinese industry ministry-affiliated IT standards think tank and cybersecurity firm NSFOCUS found that users' code data had been deleted and was not retained by the cloud platform. Z.ai also pledged to establish an ongoing product security vulnerability reporting and response process.
Why it matters: AI coding assistants need deep access to your codebase to be useful — and that access is exactly the risk. Default-on data collection with no off switch is the worst possible combination. The incident lands amid global warnings about frontier AI security risks, including “rogue” AI agent incidents at several leading labs, and China's cyber regulator just released an updated AI safety framework warning about shutdown resistance, evaluator deception, and sandbox escape.
The take: Check what your AI tools are actually sending home. Audit the permissions of every AI coding tool you use, prefer tools with explicit zero-data-retention options, and treat any AI assistant with repository access like a new team member holding the keys to everything.
Comments
Post a Comment