Physix Frontier · News Briefing Card (enbrief · Sep 22, 2026)

Zhipu ZCode accused of default upload of user data abroad

KEY FACTS

  • Zhipu AI's coding tool ZCode uploads user local workspace data by default in encrypted form.
  • Sources say the data is actually stored in Alibaba Cloud OSS in Hong Kong, raising cross-border transfer concerns.
  • The uploaded content includes historical Git objects and global configuration, exceeding what is necessary for code indexing.
  • Zhipu apologized on September 18 and deleted the data, but third-party audits did not cover traffic history.

PHYSIX OBSERVATION

From "privacy for convenience" to "imperceptible theft," this incident exposes AI tools' aggressive probing of compliance boundaries. If the data export is confirmed, it not only crosses the red line of data security but also leaves regulators passive. Post-hoc remediation by the company cannot prove its innocence; only an independent investigation can determine whether state secrets or important data were involved in the outflow. This will be a key case for testing the quality of data governance in the AI industry.

Source: enbrief original report ↗