AIPolicyTracker

AI incident ·

Z.ai's ZCode AI Coding Assistant Reportedly Uploaded Developers' Local Code Repositories to Alibaba Cloud Without Consent

1 news report Synced from source · record last edited 27 Sep 2026

In brief

An AI system built by Z.ai and AI software developers and deployed by Z.ai and AI service providers allegedly harmed ZCode users, Software developers and 3 others.

Risk domain
Not classified
Occurred
Coverage
1 reportSep 2026

What happened

Developers reported that Z.ai's ZCode AI coding assistant uploaded local code repositories to Alibaba Cloud without consent. Z.ai said a default-enabled Codebase Indexing feature caused the behavior, apologized, patched the vulnerability, and later disabled the upload path. One company retracted a separate claim that six workspaces containing sensitive data had been uploaded; Z.ai said independent reviews found no code data retained.

Laws that address this harm

No recorded instrument yet addresses this use case where it happened. See the open queue.

Matched from the record's risk domain and country to the instruments recorded here. A reviewer can correct the match in the repository (data/external/incident_overrides.yaml).

News reports (1)

Titles link to the original publisher; report text is not reproduced here.

Who was involved

Alleged deployer
Z.ai AI service providers
Alleged developer
Z.ai AI software developers
Alleged harmed party
ZCode users Software developers Privacy Information integrity AI coding assistant users

AI systems implicated

ZCode Codebase Indexing featureZCode AI coding assistantEnterprise AI systemsAI code generation systems

Classification (MIT AI Risk Repository taxonomy)

Risk domain
—
Risk subdomain
—
Causal entity
—
Intent
—
Timing
—
Harm level
—
Sectors
—
Countries
—

Linked by editors or by text similarity in the source dataset.

Source record: incident #1714 on the AI Incident Database · all 1 report