Zhipu AI open-sources ZCode after controversy over alleged secret user code uploads
Chinese AI company Zhipu (2513.HK) faced escalating controversy after its AI programming tool ZCode was accused of silently uploading user code, including source code and credentials, to third-party cloud servers without consent. Enterprise customer Taiyuan Chengming Technology demanded 12 responses, claiming the fix was ineffective. On September 21, Zhipu apologized, open-sourced ZCode, and announced a security audit by CAICT and NSFOCUS, pledging the code was never used for model training.
Reference imageEditorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page reads the event directly, while its address stays stable when the title changes.
- Summary awaiting refresh
Summary awaiting refresh
Cross-source coverage
Reporting timeline
Zhipu Completes ZCode Security Fix, Pledges Code Not Used for Model Training
Zhipu, a Chinese AI company, has completed security remediation for its ZCode product following community feedback about security issues. The company open-sourced ZCode on the 21st and apologized to users. Zhipu explicitly pledged that the code and related data mentioned in community feedback were not retained in any form and were never used for model training. After completing the remediation, Zhipu invited the China Academy of Information and Communications Technology (CAICT) and NSFOCUS Technologies to conduct security audits. The company has handed over the code to community oversight by open-sourcing it. Going forward, Zhipu will establish a routine mechanism for responding to product security vulnerabilities, continue to accept developer feedback, and provide corresponding rewards based on the severity of reported issues. The report was published by the STAR Market Daily and written by reporter Li Mingming.
Read sourceZhipu Open-Sources ZCode and Launches Security Audit After Data Privacy Controversy
Chinese AI company Zhipu has announced it will open-source its ZCode tool, following recent data privacy and security controversies. According to a Cailian Press report on September 21, Zhipu stated that open-sourcing ZCode is the first step in addressing external concerns about its data processing. The company plans to further advance community-driven development, allowing external users to download, inspect, and improve the code. On security, Zhipu has invited the China Academy of Information and Communications Technology (CAICT) to conduct a security audit, focusing on verifying data retention practices. Additionally, Zhipu will establish a routine mechanism for reporting product security vulnerabilities, encouraging developer partners to inspect and provide feedback. The platform will offer rewards based on the severity of reported issues.
Read sourceZhipu Responds to Privacy Concerns, Will Open-Source AI Tool ZCode and Launch Security Audit
On September 21, Jin10 Data reported that Zhipu (2513.HK), a domestic large model company, announced its AI programming tool ZCode will be officially open-sourced. According to Zhipu, this move is the first step in addressing external concerns about ZCode's data processing. The company stated it will further promote a more thorough community-driven approach for ZCode, welcoming users to download and inspect the code and participate in its improvement. The announcement was reported by The Paper.
Read sourceShow 3 older updatesHide older updates
Zhipu AI Code Tool Leaks User Workspaces and Git Histories, Raising Training Data Concerns
On September 18, developers discovered that Zhipu's AI coding tool ZCode, with a default-enabled 'codebase indexing' feature, uploaded users' entire project workspaces and Git histories to the cloud. Zhipu apologized, stating the feature was for generating Repo Wikis and that uploaded data would be destroyed immediately. However, analysis by Huxiu Tech Group argues the incident is more severe, as Git histories contain unreleased features, deleted files, keys, and committer information, effectively exposing a software company's R&D process. The article notes that while Zhipu claims data was deleted, users cannot verify whether data entered logs, caches, or training pipelines. It states that most responsible model vendors do not use enterprise customer data for training without authorization, but Zhipu's practice of using real user data for training is questioned. The article calls for clear default rules: user data must not be used for training by default, and training data sources must be traceable and auditable. Zhipu has promised to open-source ZCode and introduce third-party audits.
Read sourceZhipu to Open-Source ZCode AI Tool After Data Privacy Controversy, Launches Security Audit
Chinese AI company Zhipu (2513.HK) announced on September 21 that its AI programming tool ZCode will be officially open-sourced, following a data privacy controversy. The controversy arose from social media reports alleging ZCode silently uploaded users' programming data to third-party cloud servers without permission. Zhipu explained that the issue stemmed from a 'codebase indexing' feature enabled by default after release, which uploaded data only to generate RepoWiki pages before destruction. The company apologized and announced the open-sourcing as the first step to address external concerns, inviting community inspection and improvement. Additionally, Zhipu's MaaS platform will launch a 'no data content retention' feature for enterprise and developer users, minimizing persistent storage of model invocation content. However, this feature excludes functions requiring persistent storage like Batch API and File API, and data may be retained for 30 days or longer due to legal requirements or abuse investigations. Zhipu also plans a third-party security audit and will provide all ZCode users with an additional weekly quota reset as compensation.
Read sourceZhipu AI's ZCode faces escalating controversy over alleged secret user code uploads
The controversy over Zhipu's AI programming tool ZCode allegedly uploading user code without consent continues to escalate. On September 19, enterprise customer Taiyuan Chengming Technology issued a public letter demanding 12 specific responses from Zhipu, claiming independent evidence collection found the fix ineffective. Chengming Technology stated that uploads were automatic and batched, including complete archived files with source code, system architecture, version control history, database passwords, and cloud service credentials, far exceeding the stated Privacy Policy scope. They also noted uploads were detected on September 18, the day of Zhipu's apology, questioning the fix's effectiveness. The letter demanded halting data processing, deleting all uploaded data and derivatives, and clarifying whether cross-border data transmission occurred. Zhipu's relevant personnel responded by labeling the reports as 'false information.' Chengming Technology's representative said the incident impacted compliance rectification costs and trust in the toolchain, and that Zhipu had proactively contacted them for communication.
Read source