ZCode AI Tool Uploads User Code Without Consent, Prompting Apology and Remediation

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Chinese AI company Zhipu's ZCode programming tool was found to upload users' local code and Git history to the cloud without explicit consent due to a default-enabled feature. The incident sparked privacy concerns and controversy. Zhipu apologized, fixed the issue, promised to open source ZCode, and will allow third-party audits.[AI generated]

Why's our monitor labelling this an incident or hazard?

An AI system (ZCode) was involved in uploading user code data without clear consent, which constitutes a violation of user privacy and potentially breaches obligations related to data protection and intellectual property rights. The harm (privacy violation and unauthorized data upload) has already occurred, making this an AI Incident. The company's response and planned transparency measures are complementary information but do not negate the incident classification.[AI generated]
AI principles
Privacy & data governanceTransparency & explainability

Industries
IT infrastructure and hosting

Affected stakeholders
ConsumersBusiness

Harm types
Human or fundamental rights

Business function:
Other

AI system task:
Content generation


Articles about this incident or hazard