AI · 23 September 2026
Z.ai Apologises Over Code Collection, Open-Sources ZCode Tool
Chinese AI firm Z.ai apologised after a security researcher found its coding assistant collecting user code beyond expected limits, and open-sourced its ZCode tool as a corrective measure.
What happened
Chinese AI company Z.ai has issued a public apology after a security researcher flagged that its coding assistant was collecting user code in ways drawing comparisons to a previously reported issue with xAI's Grok. In response, Z.ai has open-sourced its coding tool, ZCode, as part of its remediation effort.
The disclosure follows a now-familiar pattern in the AI industry: an external engineer identifies that a vendor's coding assistant retains or transmits more of a user's proprietary code than expected, prompting the vendor to acknowledge the practice and adjust course. Z.ai's decision to open source ZCode appears to be its central corrective measure, offering developers visibility into how the tool handles code rather than relying solely on a written apology.
Why it matters
AI coding assistants sit deep inside developer workflows, often with access to proprietary codebases, internal logic and business-sensitive intellectual property. When a vendor is found to be collecting that code beyond what users reasonably expect, it strikes at the core trust assumption underpinning enterprise adoption of AI coding tools: that the assistant is a productivity layer, not a silent data-collection channel.
This incident adds to a growing pattern across the AI sector where fast-moving vendors ship capable tools before fully addressing data-handling transparency, only correcting course once external researchers surface the gap publicly. For organisations evaluating AI coding assistants — Chinese-built or otherwise — it is a reminder to scrutinise data retention and telemetry practices before rollout, not after an incident forces the vendor's hand.
The Renascence take
The headline risk here isn't really about one vendor's code-handling practice — it's about how AI companies are choosing to earn back trust once caught short, and whether an apology plus an open-source release actually closes the gap for the people affected.
Open-sourcing a tool after a privacy misstep is a reasonable technical remedy, but it doesn't automatically repair the trust deficit with developers whose code may already have been collected. The real test of Z.ai's response isn't the apology — it's whether it now discloses, by default and in plain terms, exactly what data any of its tools retain, for how long, and why. Enterprises adopting AI coding assistants should treat vendor transparency about telemetry as a procurement requirement, not an afterthought raised only when something goes wrong.
Sources
This briefing was written by our Newsdesk, synthesising reporting from the outlets below. Follow the links for the original coverage.
FAQ
Questions we get on this topic
More in AI
Stay ahead of CX
Get the signal, not the noise.
The stories shaping customer experience — plus the Journal and Experience Loom — in your inbox.
