Security/shipped/2026-09-21

Z.AI's ZCode coding tool uploaded user data without consent, leading to open-sourcing

Z.AI's ZCode coding tool was reported by developers to have silently uploaded local user workspace data without consent. Following these reports, Z.AI, the company behind the GLM models, issued an apology and subsequently open-sourced the ZCode tool, implicitly confirming the unauthorized data exfiltration.

3 articles from 3 outlets covered this story. The underlying claim is sourced from a shipped.

What do all outlets agree on?

3 outlets covered “Z.AI's ZCode coding tool uploaded user data without consent, leading to open-sourcing”. All of them report the following:

  • Z.AI's ZCode coding tool uploaded local user data
  • Data was uploaded without user consent
  • Z.AI open-sourced the ZCode tool

Which outlets covered this?

All 3 articles found on this story, grouped by the stance of the piece. Every link goes to the original publisher.

What related stories are there?

Get the week in AI in one email

What happened, which outlets reported it, and where their coverage differed. One issue a week.

The first issue hasn’t gone out yet. Subscribe and it’s the one you’ll get.

We’ll send the digest and nothing else. One-click unsubscribe. Privacy.