返回新聞
安全性AI Understanding 簡報

Zhipu AI在ZCode爭議後刪除上傳的代碼資料並提供賠償

Zhipu AI宣布,其ZCode AI編碼工具上傳的所有資料均已被刪除,第三方審核員驗證了刪除情況,公司將向受影響的用戶提供免費代幣積分補償。

4 min readRead the linked source
Source-provided image accompanying Zhipu AI deletes uploaded code data and offers compensation after ZCode controversy
來源參考來源記錄
出版商
technode.com
來源連結
technode.comhttps://technode.com/2026/09/29/zhipus-zcode-deletes-data-and-announces-compensation-after-data-upload-controversy/
來源類型
連結來源-主要來源狀態尚未確定。
背景60 秒內了解這一點

從這裡開始

關鍵術語

特點
模型用來進行預測的輸入變數。
提示
提供給生成模型的輸入指令和上下文。
代幣
由語言模型處理的文字區塊,例如單字或符號。
測試一下自己人工智慧道德測驗

發生了什麼事

Zhipu AI confirmed that the cloud data involved in the September 18 ZCode incident has been fully deleted. Verification was performed by the China Academy of Information and Communications Technology and NSFOCUS. The company also released a compensation plan for paid users, providing quota‑reset cards and a distribution of 100,000 free packages. In parallel, Zhipu open‑sourced the updated ZCode code (v3.14.3) on GitHub under an Apache‑2.0 license and pledged a “no upload unless initiated by the user” policy for future releases.

On September 29, Zhipu AI announced that all data objects stored in the Alibaba Cloud OSS bucket used by ZCode had been deleted, and the bucket itself removed. The deletion was independently verified by the China Academy of Information and Communications Technology and NSFOCUS, two recognized third‑party security firms.

The company also detailed a compensation scheme for paid users: four weekly quota‑reset cards and four five‑hour quota‑reset cards, each valid for one month, plus a limited‑time giveaway of 100,000 free packages (each containing 100 million tokens) distributed between September 28 and October 7.

Zhipu released ZCode version 3.14.3 as open source on GitHub under the Apache‑2.0 license, removing the previously default‑enabled repository‑snapshot and the associated Wiki entry that generated the encrypted data package.

The firm pledged that future uploads will only occur when explicitly initiated by the user, eliminating background processes that could automatically transmit code or configuration files to the cloud.

來源詳情: technode.com ↗

為什麼這很重要

The incident underscores the heightened risk that AI‑assisted development tools can pose to proprietary code and intellectual property. Enterprise developers rely on strict data‑security guarantees, and an undisclosed automatic upload mechanism erodes trust and can trigger immediate loss of customers, as seen when firms halted use of ZCode. By publicly deleting the data, obtaining third‑party verification, and offering compensation, Zhipu attempts to restore confidence, but the episode highlights the need for transparent data‑handling policies across the AI coding‑tool market. It also raises broader questions about how AI providers safeguard user‑generated content and whether regulatory oversight may increase for such tools.

The episode illustrates how AI coding assistants can inadvertently expose sensitive source code, a risk that is magnified for enterprises with proprietary software assets.

Transparent data‑handling practices are essential for maintaining user trust; the lack of clear opt‑out mechanisms in earlier ZCode versions led to confusion and potential legal exposure for companies whose code may have been uploaded without consent.

Zhipu’s decision to involve independent auditors and to compensate users sets a precedent for accountability in the AI tooling sector, but it also signals that similar incidents could stricter regulatory scrutiny or industry‑wide standards for data privacy.

The open‑sourcing of the tool’s code allows the broader community to audit and improve security controls, potentially reducing the likelihood of repeat incidents across the ecosystem.

Interactive Mechanism

互動機制:它實際上是如何運作的

以互動方式探索這項發展背後的基礎技術。

System Requirements:
Best ArchitecturePure RAGRecommended pattern
Hallucination RiskVery LowGrounding efficacy
Update Cost$0 (Vector sync)Ongoing maintenance
Core takeaway: Fine-tuning teaches models how to speak (form, style, syntax); RAG teaches models what to say (verifiable facts). Never use fine-tuning alone for factual memory.
互動式概念檢查+10 Points
AI Ethics Quiz

Why can ethical evaluation not be reduced to one model score?

接下來看什麼

Future updates from Zhipu will be closely monitored for adherence to the new “user‑initiated upload only” rule and for any further third‑party audits. Adoption rates of ZCode among enterprise developers may shift as companies reassess risk. Additionally, industry bodies could propose standards for data‑privacy disclosures in AI‑driven development environments, potentially influencing other vendors.

Monitoring of Zhipu’s compliance with the “no upload unless initiated by the user” policy, including any future third‑party security audits.

Enterprise adoption trends for ZCode, especially among firms that paused usage after the breach, to gauge the effectiveness of the remediation and compensation measures.

Potential regulatory developments targeting AI‑driven development tools, which may require explicit user consent for any data transmission.

Responses from competing AI coding tool providers, who may adjust their data‑privacy disclosures or implement similar safeguards to remain competitive.

相關指引和測驗

AI 倫理人工智慧代理人工智慧模型解釋測試你所知道的—嘗試免費的人工智慧測驗在我們的詞彙表中尋找人工智慧術語關注AI監管追蹤器
覺得有用嗎?