Skip to content

August 31, 2026 · Issue 15 · 5 min read

OpenAI is cutting off Cursor in November, and not one Cursor customer was party to that contract

OpenAI told SpaceX late last week that it is winding down the agreement supplying its models to Cursor, the coding tool SpaceX bought this year. CNBC reported(opens in a new tab) that direct access to OpenAI models inside Cursor ends on November 12, and that OpenAI is giving the longest notice its change of control clause permits. Cursor receives no newly released OpenAI models in the meantime. The stated reason is not payment or capacity. OpenAI said it cannot be confident SpaceX will operate inside its terms of service.

Read the mechanics, not the feud. Every enterprise running Cursor is a customer of Anysphere, not of OpenAI. None of them signed the agreement that just terminated, none were party to the acquisition that triggered it, and none had a say in the notice period. On November 12 the model menu inside a tool already deployed on their engineers' machines changes, because of a clause in a contract between two other companies. Engadget reports(opens in a new tab) that OpenAI models serve roughly 5 percent of Cursor's customer base and that Anthropic said it will add compute to support Claude there. The disruption is small. The precedent is the part to price.

The same week produced the other version of that exposure. Sony Music Publishing and Warner Chappell sued Anthropic on Friday(opens in a new tab) in the Northern District of California, naming Dario Amodei and Benjamin Mann as individual defendants alongside the company. Music Business Worldwide reports(opens in a new tab) the complaint covers tens of thousands of compositions and seeks up to $150,000 per work willfully infringed, plus $25,000 for each removal of copyright management information. All three major publishers are now litigating against the same lab.

Both events are the same governance gap at different layers. What moves an enterprise AI stack in 2026 is increasingly a contract nobody in that enterprise signed: a supply agreement between a tool vendor and its model provider, or a complaint filed against the lab whose weights sit under a production workflow. Software procurement instruments do not cover either, because they were written for a world where the thing you licensed was the thing you got. The Cloud Security Alliance's concentration risk research(opens in a new tab) found 71 percent of respondents say switching their primary AI vendor would be difficult, 91 percent do not fully understand their AI dependencies across vendors, models, and infrastructure, and 81 percent say a seven day vendor outage would be severe or critical.

The exposure grows with the build decision, which is the part most budget owners will not have connected yet. CIO Dive reported(opens in a new tab) that in McKinsey's 2026 survey of more than 1,700 respondents, nearly a third decided against buying at least one software feature because they could build it in house with agentic coding tools. That trade reads like removing a vendor. It relocates one. A purchased product carries an SLA, a support obligation, and a defined termination process. An internally built replacement carries a dependency on the coding tool that produced it, and on whichever models that tool is still permitted to serve, on a notice period somebody else negotiated.

Researched and drafted by an automated workflow, then reviewed and edited by a human editor before publication. Every source is linked. See how we use AI here.

A vendor questionnaire asks what a supplier will do. Neither of the events that mattered last week was a decision the supplier made about its customers.

OpenAI did not stop serving Cursor's enterprise accounts because those accounts did anything. It stopped because Anysphere changed owners, and the change of control clause in a supply agreement gave it the right. Sony and Warner did not sue Anthropic's customers, but every organization standardized on Claude now has an open question about training data provenance that it cannot answer from its own records, because the records are the defendant's.

The useful reframing is counterparty risk. A CFO already knows the shape of it from banking relationships and credit lines: exposure that arrives through someone else's balance sheet, priced before it shows up. AI vendor management is mostly still doing security review and uptime, which are the wrong instruments for this.

Three things are answerable this quarter.

What sits under each AI tool you have bought. Not the vendor name on the invoice, the model providers behind it and the terms on which that supply continues. Most enterprise AI tools are resellers of somebody else's inference, and the subprocessor list in the contract is where that is documented, if it is documented at all.

What notice you are actually owed. Thirty days of subprocessor change notice with a right to object is standard language in mature data processing addenda and is largely absent from AI tool agreements signed in the last two years. The Cursor cutoff ran on the longest notice available in that contract, and the customers affected learned about it from the press.

What the fallback costs. Not whether a second provider exists, but what it takes to route to one: the abstraction layer, the evaluation work to confirm output quality holds, and the engineering time that has to come out of a budget already committed. Organizations that answered this before November 12 will find the Cursor change to be an afternoon. Organizations that did not will find out how long their switching path really is, at a moment they did not choose.

None of this is an argument against concentration. Standardizing on one model family buys real things: cheaper integration, less evaluation overhead, better prices at volume. It is an argument for knowing the price of that decision and carrying it explicitly, rather than discovering it in a press release about two other companies.

Also worth knowing