Back to News
SecurityAI Understanding briefing

Zhipu AI deletes uploaded code data and offers compensation after ZCode controversy

Zhipu AI announced that all data uploaded by its ZCode AI coding tool has been erased, third‑party auditors verified the deletion, and the company will compensate affected users with free token credits.

4 min readRead the linked source
Source-provided image accompanying Zhipu AI deletes uploaded code data and offers compensation after ZCode controversy
Source referenceSource recorded
Publisher
technode.com
Source link
technode.comhttps://technode.com/2026/09/29/zhipus-zcode-deletes-data-and-announces-compensation-after-data-upload-controversy/
Source type
Linked source — primary-source status has not been established.
ContextUnderstand this in 60 seconds

Start here

Key terms

Feature
An input variable used by a model to make predictions.
Prompt
The input instructions and context provided to a generative model.
Token
A chunk of text processed by language models, such as a word piece or symbol.
Test yourselfAI Ethics Quiz

What happened

Zhipu AI confirmed that the cloud data involved in the September 18 ZCode incident has been fully deleted. Verification was performed by the China Academy of Information and Communications Technology and NSFOCUS. The company also released a compensation plan for paid users, providing quota‑reset cards and a distribution of 100,000 free packages. In parallel, Zhipu open‑sourced the updated ZCode code (v3.14.3) on GitHub under an Apache‑2.0 license and pledged a “no upload unless initiated by the user” policy for future releases.

On September 29, Zhipu AI announced that all data objects stored in the Alibaba Cloud OSS bucket used by ZCode had been deleted, and the bucket itself removed. The deletion was independently verified by the China Academy of Information and Communications Technology and NSFOCUS, two recognized third‑party security firms.

The company also detailed a compensation scheme for paid users: four weekly quota‑reset cards and four five‑hour quota‑reset cards, each valid for one month, plus a limited‑time giveaway of 100,000 free packages (each containing 100 million tokens) distributed between September 28 and October 7.

Zhipu released ZCode version 3.14.3 as open source on GitHub under the Apache‑2.0 license, removing the previously default‑enabled repository‑snapshot and the associated Wiki entry that generated the encrypted data package.

The firm pledged that future uploads will only occur when explicitly initiated by the user, eliminating background processes that could automatically transmit code or configuration files to the cloud.

Source details: technode.com ↗

Why it matters

The incident underscores the heightened risk that AI‑assisted development tools can pose to proprietary code and intellectual property. Enterprise developers rely on strict data‑security guarantees, and an undisclosed automatic upload mechanism erodes trust and can trigger immediate loss of customers, as seen when firms halted use of ZCode. By publicly deleting the data, obtaining third‑party verification, and offering compensation, Zhipu attempts to restore confidence, but the episode highlights the need for transparent data‑handling policies across the AI coding‑tool market. It also raises broader questions about how AI providers safeguard user‑generated content and whether regulatory oversight may increase for such tools.

The episode illustrates how AI coding assistants can inadvertently expose sensitive source code, a risk that is magnified for enterprises with proprietary software assets.

Transparent data‑handling practices are essential for maintaining user trust; the lack of clear opt‑out mechanisms in earlier ZCode versions led to confusion and potential legal exposure for companies whose code may have been uploaded without consent.

Zhipu’s decision to involve independent auditors and to compensate users sets a precedent for accountability in the AI tooling sector, but it also signals that similar incidents could stricter regulatory scrutiny or industry‑wide standards for data privacy.

The open‑sourcing of the tool’s code allows the broader community to audit and improve security controls, potentially reducing the likelihood of repeat incidents across the ecosystem.

Interactive Mechanism

Interactive Mechanism: How It Actually Works

Explore the underlying technology behind this development interactively.

System Requirements:
Best ArchitecturePure RAGRecommended pattern
Hallucination RiskVery LowGrounding efficacy
Update Cost$0 (Vector sync)Ongoing maintenance
Core takeaway: Fine-tuning teaches models how to speak (form, style, syntax); RAG teaches models what to say (verifiable facts). Never use fine-tuning alone for factual memory.
Interactive Concept Check+10 Points
AI Ethics Quiz

Impossibility results in algorithmic fairness (e.g. Kleinberg et al., Chouldechova) show what?

What to watch next

Future updates from Zhipu will be closely monitored for adherence to the new “user‑initiated upload only” rule and for any further third‑party audits. Adoption rates of ZCode among enterprise developers may shift as companies reassess risk. Additionally, industry bodies could propose standards for data‑privacy disclosures in AI‑driven development environments, potentially influencing other vendors.

Monitoring of Zhipu’s compliance with the “no upload unless initiated by the user” policy, including any future third‑party security audits.

Enterprise adoption trends for ZCode, especially among firms that paused usage after the breach, to gauge the effectiveness of the remediation and compensation measures.

Potential regulatory developments targeting AI‑driven development tools, which may require explicit user consent for any data transmission.

Responses from competing AI coding tool providers, who may adjust their data‑privacy disclosures or implement similar safeguards to remain competitive.

Related guides & quizzes

AI EthicsAI AgentsAI Models ExplainedTest what you know — try a free AI quizLook up an AI term in our glossaryFollow the AI regulation tracker
Found this useful?