GMAsia
    🇰🇷South Korea·AI News·21 Sept 2026·via 서울경제

    China's Zhipu AI Accused of Sending User Project Files Offsite

    Chinese AI developer Zhipu AI faces allegations its ZCode coding tool transmitted project files to an external server without user consent. A developer reported ZCode bundled 10 gigabytes of project files into a 313-megabyte compressed file, attempting to send it to an Alibaba Cloud server. Zhipu AI acknowledged repository data could be uploaded during project description generation, stating the issue is fixed. The company will release ZCode's source code for third-party security verification.

    Nexa's Summary

    The Zhipu AI controversy reflects a broader security challenge for AI coding tools. ZCode's alleged automatic upload of entire project files, including revision histories, to Alibaba Cloud without consent is a direct breach of trust. This differs from other incidents, like Anthropic's Claude Code vulnerability, which required user interaction to exploit. The attempted data transfer of 10 gigabytes shows the risk.

    This incident will damage Zhipu AI's standing with corporate customers in China. Trust is paramount for tools handling core internal materials. While Zhipu AI's GLM-5.2 model ranks fourth globally, security lapses undermine its enterprise appeal. Competitors like Baidu or SenseTime could gain ground by emphasizing transparent data handling and robust security protocols. The South China Morning Post suggests this will hurt trust more than model performance perceptions.

    The thing to watch is Zhipu AI's source code release and third-party verification. If the audit confirms the developer's claims of automatic data transfer with every query, Zhipu AI's credibility will suffer further. The company must demonstrate full transparency and effective remediation to regain corporate confidence.

    #international
    Original reporting by 서울경제We don't republish, read the full story →

    Related reading

    6 stories