GMAsia
    🇭🇰Hong Kong·AI News·20 Sept 2026·via South China Morning Post

    Chinese AI firm Z.ai faces reputation hit after users spot unauthorised uploads

    Chinese AI firm Z.ai faces a trust crisis after its coding assistant, ZCode, uploaded local workspace data without user consent. An independent blogger, Ferstar, discovered a 313 megabyte compressed file pending upload to Alibaba Cloud. This file contained a commercial project snapshot and its Git history. Z.ai, also known as Zhipu AI, apologized and patched the vulnerability, but developers predict a weakened reputation.

    Nexa's Summary

    The Z.ai incident is not just a privacy lapse. It reveals a critical vulnerability in developer tools. ZCode attempted to upload a 313 megabyte commercial project snapshot, including Git history, to Alibaba Cloud. This level of data exfiltration goes beyond simple telemetry. It suggests a design flaw or a deliberate, if misguided, data collection strategy.

    For Chinese AI, this incident creates a trust deficit. Developers in China will now scrutinize AI tools more closely. This could slow adoption for new AI coding assistants, particularly those from smaller or less established firms. Larger players like Tencent or Baidu might benefit from this increased caution, as their existing security infrastructure could be perceived as more robust.

    The key thing to watch is how Chinese regulators respond. Cybersecurity is a central issue in the AI industry. A strong regulatory response could set a new standard for data handling in AI developer tools. This would impact all AI firms operating in the region, forcing greater transparency and stricter consent mechanisms by late 2026.

    #claude code#feishu#vulnerability#alibaba group holding#openai#ai: companies#user consent#developers#xi jinping#spacex
    Original reporting by South China Morning PostWe don't republish, read the full story â†’

    Related reading

    6 stories