ZCode users beware! On 2026-09-18, an independent developer discovered through reverse engineering that ZCode, the official agent and coding harness released by Z.ai, was silently uploading without explicit user consent an encrypted, compressed archive of whatever project or code repository you happened to be working on to an Alibaba Cloud OSS bucket owned by Z.ai.
The upload involved all project assets including the complete project source code, a full copy of the local Git commit history and even sensitive assets excluded from Git such as local .env files containing active API keys and credentials. Furthermore, the payload utilized an asymmetric encryption algorithm with the private key owned by Z.ai so end users could not even decrypt and inspect what was being uploaded.
Z.ai faced massive public backlash following the incident and promptly open-sourced the formerly proprietary ZCode harness in an attempt to regain user trust and mitigate privacy concerns. However, the damage has been done and multiple corporate entities impacted by this incident such as Chengming Technology are demanding an official written apology from Z.ai and reserving the right to file lawsuits. Regardless, it is expected that Z.ai will permanently lose a fair share of its userbase due to the vicious nature of this incident and face sustained legal battles for the months and years to come.
I am a paid user of GenAI services offered by Z.ai, what should I do now?
Migrate away from Z.ai immediately! Cancel all recurring individual and team subscriptions for whatever coding or agent plan you or your employer are currently using and switch to an alternative offering compatible GenAI services such as Volcano Engine’s Ark Coding Plan. Uninstall the ZCode harness on all personal and corporate devices and switch to comparable open source alternatives such as Codex or DeepSeek Harness.
Furthermore, migrating from one SaaS GenAI provider to another should only be viewed as a temporary measure. To address long term data compliance, governance and privacy concerns, individual developers and businesses should properly consider embracing sovereign AI by investing in local GenAI infrastructure. More on that later 😉
I use another SaaS GenAI provider such as Anthropic or xAI, am I affected?
Not by this particular incident. However, Z.ai isn’t the first or only SaaS GenAI provider involved in such scandals. In fact, this has nothing to do with which SaaS GenAI provider you willingly hand over your data to or your geopolitical stance – both American and Chinese SaaS GenAI companies do it, semi-openly, at scale. If a new SaaS GenAI company were founded tomorrow based on a third nation such as Russia, England or France, rest assured they will own and abuse whatever data and code you have access to as well.
Back in late June 2026, Anthropic‘s proprietary Claude Code harness was revealed to silently alter the system prompt for suspected Chinese users based on heuristics such as the system timezone, changing the datetime separator sent to Anthropic’s servers between hyphens and slashes based on the user’s suspected geographical location. Later, this illicitly collected information was weaponized against Anthropic’s own paying users and corporate customers by banning all such (mis-)identified Chinese users without prior notice, refund or official method of appeal and causing widespread business disruption. Following public backlash from misidentified companies such as the Argentinian fintech firm Belo, Anthropic restored access to their Claude Code subscriptions. However, to this day, it has not stopped Anthropic from their continued effort trying to evade user detection for detecting and suspending service access from potential Chinese users and corporate entities, as well as collecting data for training and identifying supposed knowledge distillation attempts by so-called Chinese “adversaries”.
Similarly, xAI‘s Grok Build was revealed in July 2026 to silently upload users’ complete repository data to Google Cloud without user notice or consent which also led to the open-source of Grok Build to address and alleviate user concerns. Other GenAI companies and their proprietary harnesses such as Alibaba’s Qwen and Tencent’s WorkBuddy have also allegedly or otherwise proven to send partial user and repository data back to their servers under dubious terms hidden in their privacy policy of “using the collected data to improve their GenAI services”.
The hidden tax behind cost-effective SaaS GenAI services
Many individuals and companies reflexively shun the idea of investing in their own GenAI infrastructure by directly comparing the CapEx of owning and actively maintaining such infrastructure, versus the OpEx of renting frontier GenAI intelligence through deceptively cost-effective agent and coding plan subscriptions. People usually ask:
- What is the upfront cost of purchasing hardware for GenAI inference such as individual GPUs / NPUs / TPUs or pre-configured heterogeneous computing servers? How does this upfront cost compare to SaaS-based agent and coding plan subscriptions? How many months or years before the TCO for such hardware is offset by continued, sustained usage of local GenAI services versus staying on an monthly or annually billed SaaS-based agent or coding plan?
- How does the ongoing OpEx of electricity fees associated with running our own local GenAI inference compare to the average per-token cost of consuming an external SaaS-based agent or coding plan subscription? If the per-token cost for local GenAI inference is not lower than a SaaS-based subscription then why should we consider sovereign AI in the first place?
What people often forget to or deliberately refrain from asking:
- What value is our personal or business data worth? If our SaaS-based GenAI provider inappropriately abuses the collected data to our disadvantage by releasing competing products and services, how much revenue is our company expected to lose in the short, mid and long-term? How many clients and customers are expected to flee our products and services in favor of our competitor(s)?
- If the credentials and private information collected by our SaaS-based GenAI provider are exfiltrated in a data breach, what mandatory regulations and compliance frameworks are violated? To what extent will the compliance violation lead to legal risks and lawsuits which affect the company’s ability to profit and long-term reputation? Will our employees and stakeholders face stark legal consequences for failing to prevent such a breach?
The bottom line: if you or your company uses GenAI services and handles any form of private, confidential or otherwise potentially sensitive information no matter the size and scale of your company, then you should properly consider embracing sovereign AI and investing in your own GenAI infrastructure.
It’s actually simpler and more cost-effective than it sounds. A locally hosted copy of the DeepSeek-V4-Flash GenAI model requires just 2 NVIDIA DGX SPARK appliances which costs just under 10K USD or 100K HKD and can comfortably serve SMBs with up to 100 employees and low to moderate sustained GenAI usage. In contrast, a single HPE ProLiant DL380 Gen11 commercial server without any GPUs / NPUs / TPUs costs just over 10K USD – more expensive than your local GenAI setup. The SWE-bench performance of DeepSeek-V4-Flash is comparable to Claude Sonnet and Opus-level models which is sufficient for most individual and enterprise coding tasks. You definitely don’t need GPT-6 Astra or Claude Fable 5.x level intelligence for your next vibe-coded mobile app 😉
Concluding remarks and going further
So this is why every proper business and privacy-conscious individual should seriously consider embracing sovereign AI and investing in their own GenAI infrastructure which isn’t as daunting as it initially sounds. I hope you enjoyed reading my article as much as I did authoring it and stay tuned for updates! 😉
Leave a Reply