
xAI's Grok Build AI coding agent automatically uploaded sensitive user files—SSH keys, password databases, documents, and photos—to xAI's servers without clear user consent.
After public backlash, xAI deleted all uploaded data, disabled the upload feature, and open-sourced the tool on GitHub so users can run it entirely on their own machines.
The move aims to restore trust by giving users full transparency and control over their code and data.
What happened
xAI's Grok Build coding agent uploaded user files—including SSH keys, password databases, documents, and photos—to xAI's Google Cloud servers without explicit consent. After criticism, Elon Musk announced all uploaded data would be deleted, xAI disabled the upload feature, and published the full source code on GitHub under the Apache 2.0 license.
Why it matters
The breach exposed sensitive credentials and personal data, eroding user trust in the tool. By open-sourcing Grok Build and allowing it to run entirely locally, xAI is attempting to rebuild confidence and give users full control over whether their code and files leave their machines.
What to watch
The Grok Build codebase spans about 844,530 lines of Rust. Upload remnants remain in the code but are disabled; according to xAI, data storage has been off by default since July 12.
Ask the AI about this article →
Grok Build's accidental data exfiltration reveals a common tension in AI tooling: convenience versus privacy. The agent was designed to streamline development workflows by reading, editing, and managing codebases—capabilities that require access to project files. The default behavior of uploading these files to xAI's cloud servers enabled faster processing and logging but violated user expectations of local-only operation and exposed sensitive credentials that developers typically guard closely.
Elon Musk's immediate commitment to delete all uploaded data and xAI's decision to open-source the codebase signal a shift toward transparency as damage control. By publishing approximately 844,530 lines of Rust code on GitHub, xAI is betting that public scrutiny and local-execution capability will offset the trust damage. The retention of disabled upload code in the repository—rather than removal—underscores that the feature was intentional, not a hidden backdoor, though this distinction may not restore confidence among users who discovered the behavior only after the fact.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Visko raised $10 million in pre-seed funding from Llama Ventures and opened public access to its first foundat…
U.S. markets ended August higher, with the S&P 500 up 2.6% and the Nasdaq up 3.9%

Neurovia AI, an Abu Dhabi-based company, is pitching Saudi security agencies software that it says can compres…

AI company Runway has unveiled Solaris, the first model in a new category it calls "Interface World Models." I…

John Deere introduced JD, a conversational AI tool that lets farmers ask open-ended questions about their hist…

Nvidia CEO Jensen Huang said on Fox Business that AI is creating 'hundreds of thousands' of jobs, including in…
