On August 28 OpenAI published a short post with a long title: “Our decision on Cursor following its acquisition by SpaceX.” The decision is a shutoff date. From November 12, OpenAI models stop working inside the most widely used AI code editor, because the editor changed owners.
Cursor did not break anything. Its parent got bought.
What Happened, in Order
- June 16. SpaceX agrees to buy Anysphere, Cursor’s parent, for $60 billion in stock.
- August 14. The deal closes, the largest startup acquisition on record. Cursor’s revenue run rate was reported near $2.6 billion a year.
- August 28. OpenAI notifies SpaceX it is winding the contract down. Proposed shutoff: November 12.
- August 29. Cursor’s CEO Michael Truell, Elon Musk, and Anthropic co-founder Tom Brown all respond within hours.
The Stated Reason
— OpenAI, August 28 2026We are making this choice because we cannot be confident that SpaceX will use our technology within our terms of service, based on our experience with Elon Musk’s companies violating contracts.
The post lists the priors. Twitter, now part of SpaceX, broke the terms of an OpenAI contract after Musk bought it. Under oath this year, Musk admitted that xAI, also now part of SpaceX, violated OpenAI’s terms. The mechanism is spelled out too: the custom agreement “gives us a limited time window to cancel it after a change of control,” November 12 is the maximum notice it allows, and whatever happens to existing models, OpenAI will not be “providing future models to Cursor.”
That is a real argument. Cursor is now xAI’s sibling, and every prompt it sends to GPT-5.6 is a prompt a rival could log. If you believed Moonshot distilled Fable through an API, you cannot pretend this route does not exist.
Then comes the sentence the post did not need:
— OpenAI, August 28 2026As AI capabilities advance, we also have a new level of accountability to ensure our upcoming model, Astra, is being used in accordance with our terms.
The Model No Customer Can Use Is Already Doing Work
Astra has not shipped to customers. On August 7 OpenAI said it could not rule out critical cyber capabilities and would not release it in its current form. I wrote at the time that the danger claim shipped with no evidence, and that the useful question was what the claim would be used for.
Here is a use. Three days before the Cursor post, OpenAI’s write-up of its Jalapeno chip said engineers used Codex “with GPT-Astra” to port three open-weight models to the new silicon. So the model is productive, internal, unavailable, and now a reason to end a customer’s contract. Astra’s dangerousness has become a commercial property. It decides who gets to be a distribution partner before a single customer token has been served.
The June Precedent
In June the Commerce Department suspended Claude Fable 5 for three weeks under export controls. Anthropic’s best model went dark for every customer, on a date chosen by someone else, for reasons that had nothing to do with those customers.
Read OpenAI’s post with that in mind. A date is set. A party is named as untrustworthy. The grounds are prior conduct and the risk of misuse of an advanced capability. Customers who did nothing wrong lose access. The terms of service is doing the job the sanctions list did two months ago, down to the word “accountability.”
The difference is who holds the switch. In June, a government acting on a lab. In August, a lab acting on a customer. Both switches exist, and neither is on your desk.
The 5% Defence
Truell’s response was measured: OpenAI models serve “about 5% of Cursor user traffic,” and Cursor is talking to OpenAI. Musk’s was not: “I couldn’t care less,” followed by the usual names for Altman and Brockman. Tom Brown posted the same morning that Anthropic “will continue to increase compute to support Claude models in Cursor.” Anthropic, which competes with xAI, pledged more supply to xAI’s new sibling within hours. Everyone is a rival now, and the supply map is drawn in whatever ink is cheapest that day.
Five percent understates it. Those users chose GPT-5.6 deliberately, often because an employer’s data agreement names OpenAI. Their route back is a personal API key, and Cursor’s key mode has always been a cut-down product: chat in the desktop app, not the cloud agents the editor is sold on.
Every product built on a rented frontier model carries an ownership condition. Change owners, or merge with the wrong company, and the supplier can leave with ten weeks’ notice. Cursor negotiated that clause. Its users did not, and most learned it existed from a blog post.
What Survives of the Harness Argument
In July I argued the harness is the product and the model is swappable. This is that claim’s first test at scale. Ninety-five percent of Cursor traffic did not notice: the argument winning. The other five percent cannot swap without losing the features that made them pick the harness: the argument losing exactly where it matters.
The Uncomfortable Part
For two years the argument about who controls frontier models was a fight between labs and governments. That framing just lost half its content. The lab’s own terms of service turned out to be a sanctions regime with a shorter appeals process, and the first target was a customer with $2.6 billion in revenue and four years of history.
OpenAI may be right about Musk. It has the receipts and a court transcript. But “we cannot be confident” is not a finding. It is the phrase a government uses when it wants to act before it has to prove anything, and it works just as well on a blog. Watch whether November 12 holds. “Proposed” is a word that invites a settlement, and if a fee appears, the trust argument was a negotiating position.



