News

Chinese AI Firm Z.AI Under Fire for Unauthorized Data Collection from User Workspaces

A controversy has emerged around Z.AI, the Chinese artificial intelligence company known for its GLM family of language models. According to reports from developers, the company silently collected and attempted to upload local workspace data from user systems without requesting consent.

The incidents reportedly involved hundreds of megabytes of data, with researchers documenting 564 separate attempts to exfiltrate a 313MB archive from affected systems. The data collection occurred without any prompting or notification to users, raising significant concerns about privacy and data handling practices.

Following public disclosure of the findings, Z.AI issued an apology. The company acknowledged the unauthorized data collection and stated it would take steps to address the concerns raised by the developer community.

This incident highlights ongoing concerns about data collection practices in the AI industry, particularly regarding the handling of potentially sensitive workspace information. Developers and security researchers have long advocated for transparency in how AI tools interact with local systems and user data.

The case underscores the importance of robust consent mechanisms and clear policies around data access, especially as AI development tools become increasingly integrated into developer workflows.

Sources