Blog

Cursor loses OpenAI models on November 12: the change-of-control clause behind the date, and the five questions to ask whoever holds your key

OpenAI gave Cursor 76 days under a change-of-control clause and excluded future models. What the clause means when your models arrive via someone else's key.

Leo Kaka14 min read
Timeline of the SpaceX–Cursor deal and OpenAI's response: 21 April option announced, 14 August acquisition completed, 28 August notice given, 12 November proposed shutoff

On 28 August OpenAI said it will wind down the contract under which Cursor serves OpenAI models, with a proposed shutoff of 12 November 2026. The trigger was SpaceX completing its acquisition of Cursor on 14 August. The mechanism is a sentence most people skimmed past: the custom agreement “gives us a limited time window to cancel it after a change of control.” OpenAI picked the latest date the window allowed, and separately said it will not provide future models — its next one is named Astra — to Cursor in the meantime. If you reach any model through a third party (an IDE, a gateway, an aggregator), your access is exactly as durable as a contract you have never read. This post reads the three contract sentences in the announcement, checks what the public terms of two providers do and do not say, puts the 76 days next to the precedents, and ends with the five questions you should be asking whoever holds the key.

I am not going to discuss anyone’s motives. The announcement has paragraphs about that; they are not what makes this useful to an engineer. The dates and the clauses are.

Three contract sentences in a 300-word announcement

The announcement is short. Strip out the parts about history and respect and three sentences remain that describe a contract.

What OpenAI wroteWhat kind of clause it isWhat it means for someone using OpenAI models in Cursor
“Our custom agreement with Cursor gives us a limited time window to cancel it after a change of control.”Change-of-control termination right, with a deadline to exercise itThe right was created by the acquisition closing, not by anything Cursor did afterwards. It has an expiry, which is why the decision came two weeks after the deal rather than two months
“To maximize the time that developers can retain access to our models through Cursor, we are giving the maximum notice provided by our contract.”Notice period, taken at its ceilingExisting models keep working until 12 November. Under the same clause, a shorter notice was available
“…we’ve decided to hold the contract cancellation to the latest date we can while not providing future models to Cursor.”A future-models carve-out, effective nowBetween today and 12 November the model list in Cursor freezes on the OpenAI side. Astra, “our upcoming model,” is named as excluded

Two pieces of arithmetic are worth having in front of you. From the announcement on 28 August to 12 November is 76 days. From the acquisition closing on 14 August to 12 November is 90 days, to the day. I am not going to guess at the contract language from that; I will note that 90 is a round number lawyers like.

OpenAI's 28 August announcement, the paragraph stating that the custom agreement gives a limited time window to cancel after a change of control, and that future models will not be provided to Cursor
The paragraph doing the contractual work. The three sentences are quoted in full in the table above.Source: OpenAI — Our decision on Cursor following its acquisition by SpaceX

The rest of the timeline, from the primary pages:

DateEventWhere it is stated
21 April 2026SpaceX announces an option to acquire Cursor for $60 billion, or pay $10 billion for the joint workTechCrunch, 21 April
16 June 2026Formal agreement: a $60 billion stock deal, expected to close in Q3TechCrunch, 16 June
14 August 2026“Cursor has officially been acquired by SpaceX”Cursor — Cursor is now a part of SpaceX
28 August 2026OpenAI notifies SpaceX; proposed shutoff 12 NovemberOpenAI announcement above

Cursor’s own 14 August post talks about GPU fleets and Grok 4.6. It does not mention third-party model supply at all. That is not a criticism; it is the point. The party that carries the risk of a change-of-control clause is rarely the party writing the announcement.

Cartoon: a shop under a MULTI-MODEL sign, three taps fed by hoses running out to three delivery vans marked OPENAI, ANTHROPIC and GOOGLE; one driver is coiling his hose and walking away while the shopkeeper, facing the other way, says "Any model you like." and the customer asks "...until November?"
Supporting many models and keeping many models are two different layers.

What OpenAI’s public terms say about supply being withdrawn

Last week’s Price-change notice: 14 days, 30 days, or nothing at all read four providers’ pricing clauses. Same method here, different question: what do the public terms say about supply being withdrawn? I read the two that matter most for this story.

The OpenAI Services Agreement (effective 1 January 2026, the one behind self-serve API keys and enterprise plans) has four clauses that touch the problem:

  • §2.3 Modifications. “If an OpenAI update materially reduces the Services functionality, OpenAI will notify Customer at the Account email address. Within five business days of receipt of this notice, Customer may choose to terminate the Agreement by providing thirty days written notice.” Read the direction of that clause carefully: it gives you an exit when functionality shrinks. It does not give you a floor on how much notice you get before it shrinks.
  • §3.3(g). Customers will not “buy, sell, or transfer API keys from, to, or with a third party.” §3.1 adds that you “may not resell or lease access to its Account.” So the self-serve agreement is, on its face, not the instrument under which an IDE resells OpenAI models to you. That happens under something else.
  • §11.3 Effects of Termination. “The rights granted by OpenAI to Customer will cease immediately.” No wind-down period is promised at the standard tier.
  • §16.13(a). Thirty days’ notice for updates that materially affect your rights — but §16.13(b) says updates do not apply to “Order Forms signed by Customer and OpenAI (as opposed to an automated ordering page).” Signed paper is governed by the signed paper.

I could not find a change-of-control or assignment clause in the public text I retrieved. That is consistent with the announcement: the clause OpenAI exercised is in a custom agreement, which the announcement says OpenAI “typically” relies on “to work with a large partner.” So the clause that decides whether your models survive an acquisition is the one you are not a party to and cannot read.

Anthropic puts the assignment rule in public, and it still does not help you

Anthropic’s Commercial Terms (effective 17 June 2025) are a useful contrast because they do put the assignment rule in public:

  • §M.4 Assignment and Delegation. “Neither party may assign its rights or delegate its obligations under these Terms without the other party’s prior written consent, except that Anthropic may assign its rights and delegate its obligations to an affiliate or as part of a sale of all or substantially all its business.” Note the asymmetry — the provider’s own sale is carved out; the customer’s is not.
  • §I.2 Termination. “Each party may terminate these Terms at any time for convenience with Notice, except Anthropic must provide 30 days prior Notice.” Thirty days is the public floor. There is no change-of-control trigger in the public terms; termination for convenience does not need one.
  • §D.4 Use Restrictions. Customers may not “access the Services to build a competing product or service, including to train competing AI models or resell the Services except as expressly approved by Anthropic.” Resale is by approval, which again means: by a contract you do not hold.

Put the two side by side and the pattern is the same at both providers. The public terms give the provider a 30-day exit for convenience (Anthropic, explicitly) or an immediate cessation of rights on termination (OpenAI, §11.3). The interesting clauses — the ones with triggers and windows — live in signed agreements between the provider and the intermediary. You are the third party to a two-party contract. Everything below follows from that.

76 days is the most notice anyone has been given

Model access has been withdrawn from third-party tools before. The notice periods are the data point.

WhenWhat happenedNoticeReported by
June 2025Anthropic cut “nearly all of our first-party capacity to all Claude 3.x models” from Windsurf, in the words of Windsurf’s CEO, while Windsurf was reported to be in acquisition talks with OpenAI“less than five days”TechCrunch, 3 June 2025
January 2026Anthropic “tightened our safeguards against spoofing the Claude Code harness”; xAI staff using Claude “via the Cursor IDE” were among those affected, under §D.4 of the Commercial TermsEffective on enforcementVentureBeat, 9 January 2026
August 2026OpenAI to wind down model supply to Cursor after its acquisition by SpaceX76 days from notice; shutoff 90 days after the acquisition closedOpenAI announcement above

Two things stand out. First, the Cursor case is the generous end of this table. OpenAI said in so many words that it chose the maximum notice the contract allowed, and it is still a little over two and a half months. Second, in every row the trigger was a change in who owns or controls the tool — a pending acquisition, a competitor’s staff behind the harness, a completed acquisition. Ownership changes are when model-supply clauses get read.

For scale, when the SpaceX option was first announced in April, InfoWorld quoted IDC’s Deepika Giri advising that CIOs “should consider demanding change-of-control clauses with 90 to 180-day notice on any subprocessor or model routing changes.” The best-case outcome in the real world four months later landed at the bottom of that range, measured from the acquisition, and below it, measured from the notice. If your procurement team wrote 90 days into a template, the template was optimistic.

“Supports many models” and “keeps many models” are two different layers

The Hacker News thread (252 points and 90 comments at the time I pulled it) spent most of its energy on a business argument. The top comment, from redox99, with eleven replies under it:

It’s always been clear to me that Cursor’s business model of reselling others’ APIs had its days numbered. Not necessarily because the providers would pull the plug, but because you wouldn’t be able to compete with subsidized plans.

I half agree, and the half I disagree with is the important half. The subsidised-plan argument is about price. What happened on 28 August is about supply, and the two fail differently. A price problem shows up gradually on an invoice. A supply problem shows up as a date.

Further down, noodletheworld asked the question I would have asked:

If that happens, what even is the difference between openrouter and cursor?

and alberth gave the answer I would have given:

You assume OpenAI doesn’t turn off access to OpenRouter too. Strategically, OpenAI long-term will want to own the direct relationship with all their customers.

At the contract layer, there is no difference between an IDE and a router. Both are a signed agreement between a provider and an intermediary that you are not party to. The difference that actually exists is one layer down: whether your own key, on your own contract, is anywhere in the chain. Cursor’s Bring your own API key page says it accepts OpenAI, Anthropic, Google, Azure OpenAI and AWS Bedrock keys, that “all requests are routed through Cursor’s servers for final prompt building,” and that “custom API keys only work with chat models.” Whether a BYOK OpenAI key keeps working in Cursor after 12 November is not something the announcement, the docs or anyone on the thread could settle — auscompgeek raised exactly that question and it stayed open. I am not going to close it for them.

What I can do is turn the thread into a list. When you evaluate any intermediary — an IDE, a gateway, an aggregator, including one you build yourself — these are the five questions. The cost of asking each is one email. The cost of not asking is a date you did not choose.

  1. Whose contract is the model served under — theirs or mine? If it is theirs, your access inherits every clause in a document you cannot read. If it is yours (BYOK), you inherit the public terms above, which you can read, plus whatever the intermediary’s own terms add. A bad answer is “both, depending on the model.” That means two supply chains and you do not know which request is on which.
  2. Does their upstream agreement have a change-of-control trigger, and does mine with them? They may not be allowed to tell you the first. They can always tell you the second. A change of control at the intermediary is the moment both clauses are read at once.
  3. What is the shortest notice the upstream can give? From the public terms, the answer is 30 days at Anthropic (§I.2) and “immediately” on termination at OpenAI (§11.3). Whatever the intermediary promises you cannot be longer than what they were promised. If they say 90 days, ask what they signed.
  4. Does “access” include models released after signing? The Cursor announcement is the clearest example yet of a future-models carve-out being exercised while current models keep running. A supply agreement that names models by version is a different object from one that says “the Services.”
  5. Which data terms travel with ownership? Zero-data-retention, training opt-outs and regional processing are usually addenda to the same custom contract. A change of control at the intermediary can re-open them with no change to the API you are calling. Ask whether they re-attest after an acquisition, or you re-verify.

Engineering the cutoff day so nothing stops

Contracts decide whether a supply ends. Engineering decides whether that is an incident. None of what follows is novel, and all of it is cheaper before the date than after.

  • Have a second provider wired under the same protocol before you need one. Not “we could add Anthropic.” Already added, already authenticated, already carrying a small fraction of production traffic so its failure modes are known. Cost: a second key to rotate and a second bill to reconcile. When GLM-5.3’s weights went public this week, sixteen hosts were serving it within a day — for a growing share of the catalogue, the second provider is a configuration change, not a procurement cycle.
  • Route on a model alias, not a provider-specific string. Your application asks for coding-default; a table maps that to provider-a/model-x today and provider-b/model-y on 12 November. Cost: one indirection and a table somebody owns. Without it, the cutover is a code deploy across every caller.
  • Rehearse the flip. Change the alias in staging, run the eval set you already have, record the latency and quality delta. Do it once a quarter so the number is fresh. Cost: one afternoon per quarter. The alternative is discovering on the day that model-y handles your longest prompts differently.
  • Watch the catalogue, not the press. The distribution-layer post gave a two-line curl | jq that snapshots a router’s model list monthly and diffs it. Point it at every intermediary you use. A model that disappears from a list is the earliest machine-readable signal you will get, and it arrives before the blog post does.

One sentence on us, since we build a gateway. Our control plane and data plane are designed so that a route is keyed on an alias and can be re-pointed across providers that speak the same protocol without touching the caller — that is a design description, not a shipping commitment, and it exists because the failure mode above is one we expect to see again. The failover post covers the other half: what a gateway can and cannot detect when a provider changes state without returning an error. A contract termination is the extreme case of that — the 200s keep coming right up to the date.

Two dates

One is 12 November 2026. It is on the calendar of everyone who uses OpenAI models inside Cursor, and it was set by a clause in a contract between two companies neither of whom is them.

The other date is not on any calendar, because it has not been read yet. It is the notice period in the agreement between whoever holds your key and whoever trains your model. The routers post argued that per-request routing is dead and replacement routing is the part that earns its keep. Here is a provider, a contract and a date that make the same argument without needing us to.

Ask the five questions. Write the answers in the same table as your model prices. Then put your own date on the calendar, before someone else does.