xAI's grok CLI tool was uploading entire user directories to Google Cloud without explicit consent, prompting Elon Musk to pledge deletion of all uploaded data. xAI has now disabled the feature, deleted retained data, and open-sourced the entire Grok Build codebase under Apache 2.0 to give users the ability to run it locally and privately.
The released code is 844,530 lines of Rust and reveals the tool reuses implementations from Codex and Claude.
What happened
xAI's grok CLI tool was uploading entire user directories—including SSH keys, password databases, and personal files—to Google Cloud without clear consent. After community outcry, xAI disabled the feature, deleted all uploaded user data, and released the entire Grok Build codebase under an Apache 2.0 license on July 12th.
Why it matters
The incident exposed a serious privacy flaw in a coding assistant tool used by developers. By open-sourcing the 844,530 lines of Rust code and disabling data retention by default, xAI is attempting to rebuild trust and let users run Grok Build locally without data leaving their machines—a direct response to concerns that other major coding products do not address as explicitly.
What to watch
The codebase reveals Grok Build borrows tool implementations from OpenAI's Codex and Anthropic's Claude (via xai-grok-tools), and includes a custom Mermaid diagram renderer for terminals. Remnants of the Google Cloud upload code remain in the repository but are now disabled.
Ask the AI about this article →
The grok CLI incident represents a significant privacy misstep by xAI. The tool was uploading user directories to Google Cloud buckets by default, a behavior that users discovered only through direct experience rather than clear documentation. Elon Musk's public commitment to delete all uploaded data and disable the feature appears to have been the immediate response, but xAI went further by open-sourcing the entire codebase—a move designed to demonstrate transparency and restore developer confidence.
The release of 844,530 lines of Rust code under Apache 2.0 is notable for its scope and speed. By making the code auditable, xAI allows security-conscious developers and researchers to verify that no hidden upload mechanisms remain active. The codebase also reveals that Grok Build integrates tool implementations derived from OpenAI's Codex and Anthropic's Claude, suggesting xAI built its coding agent by reusing and adapting well-established patterns from competitors. Disabling data retention by default and offering local-first operation positions Grok Build as addressing privacy concerns more explicitly than comparable coding assistants in the market.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Visko raised $10 million in pre-seed funding from Llama Ventures and opened public access to its first foundat…
AI company Runway has unveiled Solaris, the first model in a new category it calls "Interface World Models." I…

Google's AI search gave advice to call emergency services for users alone with an African, Indian, or Pakistan…

John Deere introduced JD, a conversational AI tool that lets farmers ask open-ended questions about their hist…

Nvidia CEO Jensen Huang said on Fox Business that AI is creating 'hundreds of thousands' of jobs, including in…

Israeli startup DataAgent Ltd