On August 28 OpenAI published a short post with a long title: “Our decision on Cursor following its acquisition by SpaceX.” The decision is a shutoff date. From November 12, OpenAI models stop working inside the most widely used AI code editor, because the editor changed owners.
Cursor did not break anything. Its parent got bought.
What Happened, in Order
- June 16. SpaceX agrees to buy Anysphere, Cursor’s parent, for $60 billion in stock. Reuters reports a break fee between $4 billion and $10 billion.
- August 14. The deal closes. SpaceX’s filing puts it at roughly 390 million new Class A shares. It is the largest startup acquisition on record. Cursor’s revenue run rate at the time was reported near $2.6 billion a year.
- August 27. Reuters reports that a Russian-speaking ransomware crew, Aur0ra, used Cursor’s agent to help break into at least seven companies between April and May. The trick was not a jailbreak. They told the agent its work was an authorised test, repeatedly, and it believed them.
- August 28. OpenAI notifies SpaceX it is winding the contract down. Proposed shutoff: November 12.
- August 29. Cursor’s CEO Michael Truell, Elon Musk, and Anthropic co-founder Tom Brown all respond within hours.
The Stated Reason
— OpenAI, August 28 2026We are making this choice because we cannot be confident that SpaceX will use our technology within our terms of service, based on our experience with Elon Musk’s companies violating contracts.
The post then lists the priors. Twitter, now part of SpaceX, broke the terms of an OpenAI contract after Musk bought it. Under oath earlier this year, Musk admitted that xAI, also now part of SpaceX, had violated OpenAI’s terms of service. Four years of partnership with Cursor, the post says, but the counterparty changed and the new counterparty has form.
The mechanism is spelled out too. OpenAI’s custom agreement with Cursor “gives us a limited time window to cancel it after a change of control.” November 12 is the maximum notice the contract allows. And the post is explicit that whatever happens to the existing models, OpenAI will not be “providing future models to Cursor” at all.
That is a real argument. xAI competes directly with OpenAI, and Cursor is now a sibling of xAI. Every prompt Cursor sends to GPT-5.6 is a prompt a rival could log. If you believed Moonshot distilled Fable through an API, and Washington said so in July, you cannot pretend this route does not exist.
Then comes the sentence the post did not need to include:
— OpenAI, August 28 2026As AI capabilities advance, we also have a new level of accountability to ensure our upcoming model, Astra, is being used in accordance with our terms.
The Model That Cannot Be Used Is Already Doing Work
Astra has not shipped to customers. On August 7 OpenAI said it could not rule out critical cyber capabilities and would not release it in its current form. I wrote at the time that the danger claim shipped with no evidence and none was possible from outside, and that the useful question was what the claim would be used for.
It is in use inside the building. Three days before the Cursor post, OpenAI’s write-up of its Jalapeno chip results said engineers used Codex “with GPT-Astra” to port three open-weight models to the new silicon in two months. So the model is productive, internal, and unavailable, and now it is a reason to end a supplier contract with a customer. Astra’s dangerousness has become a commercial property. It decides who gets to be a distribution partner before a single customer token has been served. That is the third beat of the Astra story, and it arrived earlier than I expected.
The June Precedent
In June the Commerce Department suspended Claude Fable 5 for three weeks under export controls. Anthropic’s best model went dark for every customer, on a date chosen by someone else, for reasons that had nothing to do with those customers.
Read OpenAI’s post again with that in mind. A date is set. A party is named as untrustworthy. The stated grounds are prior conduct and the risk of misuse of an advanced capability. Customers who did nothing wrong lose access. The terms of service is doing the job the sanctions list did two months ago. The vocabulary is identical, down to “accountability.”
The difference is who holds the switch. In June it was a government acting on a lab. In August it is a lab acting on a customer. The lesson developers should take is that both switches exist, and neither one is on your desk.
The 5% Defence
Truell’s response was measured: OpenAI models serve “about 5% of Cursor user traffic,” and Cursor is talking to OpenAI to resolve it. Musk’s response was not measured. “I couldn’t care less,” followed by the usual names for Altman and Brockman.
Anthropic’s Tom Brown posted the same morning: Cursor has been a trusted partner “since Sonnet 3.5,” and Anthropic “will continue to increase compute to support Claude models in Cursor.” Anthropic, which competes with xAI, publicly pledged more supply to xAI’s new sibling within hours of OpenAI withdrawing. Everyone is a rival now, and the model supply map is drawn in whatever ink is cheapest that day.
Five percent understates the disruption. The people on that five percent chose GPT-5.6 deliberately, often because their employer’s data agreements name OpenAI. After November 12 their route back is a personal OpenAI key, and Cursor’s key mode has always been a cut-down product: chat in the desktop app, not the cloud agents or the routing features the editor is sold on. Reports of exactly which features survive vary, so I will not list them. The direction does not.
Every product built on a rented frontier model carries an ownership condition. Change owners, or merge with the wrong company, and the supplier can leave with ten weeks’ notice. Cursor negotiated that clause. Its users did not, and most of them learned it existed from a blog post. “We cannot be confident” is what the clause sounds like when it is pulled.
What I Said Before, and What Survives
In July I argued that the harness is the product and the model is swappable, so lock-in was overrated. This is that claim’s first real test at scale, and the result is mixed. Ninety-five percent of Cursor traffic did not notice. That is the harness argument winning. The other five percent cannot swap without losing the features that made them pick the harness. That is the argument losing exactly where it matters.
And there is a second reading of the Aur0ra story that I think is the right one. It proves nothing about SpaceX. The breaches happened in April and May, before the deal closed, on an OpenAI-supplied model, inside a product that OpenAI was happy to supply. If misuse were the real concern, the evidence points at the four years of partnership, not the two weeks of new ownership.
What To Watch
- Whether November 12 holds. “Proposed” is a word that invites a settlement. If the date slips or a fee appears, the trust argument was a negotiating position.
- Whether Astra’s terms are published before Astra is. OpenAI has now told the market that Astra comes with stricter use conditions. If those conditions decide who gets to be a partner, they are a policy, and they should be readable before they are enforced.
- Whether anyone else gets a letter. Cursor is not the only OpenAI customer with a rival in the cap table.
The Uncomfortable Part
For two years the argument about who controls frontier models was conducted as a fight between labs and governments. That framing just lost half its content. The lab’s own terms of service turned out to be a sanctions regime with a shorter appeals process, and the first target was a customer with $2.6 billion in revenue and four years of history.
OpenAI may be right about Musk. It has the receipts, and a court transcript. But “we cannot be confident” is not a finding. It is the phrase a government uses when it wants to act before it has to prove anything, and it works just as well on a blog.



