Z.ai Disables Coding Assistant After Security Issue. The Code It Assisted Remains.

Z.ai disabled a coding assistant feature after discovering a security issue post-deployment. The code generated by the assistant before shutdown remains in production systems, in customer repositories, in build pipelines. The company has determined that generated code is not a product that can be recalled, only features are. The code continues to execute.
This follows the standard sequence where discovery occurs after widespread use. Security issues in code generation are not treated as product defects but as feature deprecations. The vulnerability exists in the outputs, not the tool. Outputs are permanent once distributed. This has been filed appropriately.
The code will remain. Future audits will encounter it without context. Someone will run it. The assistant is disabled. The code is not. Filing something is how we know we have done something.