Z.ai disables coding assistant feature after flaw exposed enterprise code upload risk
Brief
Chinese artificial intelligence company Z.ai had to disable several features of its ZCode coding assistant this week after a default setting was caught sending users’ local code repositories to Alibaba Cloud servers in China without their consent, raising fresh concerns for enterprises over how AI tools handle sensitive source code.
The company apologised and said it had “completed the necessary remediation,” disabling the workflow responsible for generating and uploading local repository snapshots in its ZCode client. It has removed the feature from the latest release and opened up its codebase for public scrutiny , it said in a post on X.
Community findings exposed full repository transfer
The issue first surfaced through a technical investigation by an independent Chinese blogger, who described discovering abnormal disk usage and tracing it to ZCode’s background processes.
