OpenAI Cuts Cursor Off Nov 12. BYOK Voids Your ZDR.

OpenAI stops serving its models to Cursor on 12 November 2026. Pointing Cursor at your own OpenAI key is not a swap — Cursor's documentation says its Zero Data Retention policy does not apply to custom keys, and every request still routes through Cursor's backend.

By Rajesh Beri·August 30, 2026·12 min read
Share:
A single physical brass door key resting on an open printed compliance binder page, with a red DENIED stamp mark beside it on the paper, shot close and plainly lit on a desk. No readable text or logos.

Illustration generated using AI

The obvious workaround voids the guarantee that got the tool approved. OpenAI has told SpaceX it will stop serving its models to Cursor on 12 November 2026, and the fix every engineering lead will reach for — point Cursor at your own OpenAI key — is not a swap. Cursor's own help documentation states plainly that "Cursor's Zero Data Retention policy does not apply when you use your own API keys."

If your security team cleared Cursor on the strength of Zero Data Retention, bring-your-own-key does not preserve that control. It removes it. You have roughly ten weeks to decide whether that is a re-review, a model migration, or a renewal conversation — and the three have very different lead times.


What OpenAI Terminated, and the Clock It Started

OpenAI cancelled a supply contract using a change-of-control clause, not a breach clause, and gave the longest notice that contract allows. SpaceX closed its $60 billion acquisition of Cursor's parent company on 14 August 2026. Fourteen days later OpenAI published its decision notice, saying it "cannot be confident that SpaceX will use our technology within our terms of service, based on our experience with Elon Musk's companies violating contracts", and that its "custom agreement with Cursor gives us a limited time window to cancel it after a change of control." The company framed 12 November as "giving the maximum notice provided by our contract."

Read that sequence again, because it is the part that generalises beyond this vendor. Nothing Cursor built broke. No customer of Cursor did anything wrong. A supplier two layers up the stack looked at the new owner's name and exercised a clause. That is the same mechanism we watched in the Poolside licensing structure — the trigger fires on ownership, and your contract with the middle vendor says nothing about it.

Two details in the notice matter operationally. OpenAI said it has "decided to hold the contract cancellation to the latest date we can while not providing future models to Cursor", which means new OpenAI models were never coming to Cursor regardless of how the negotiation lands. And OpenAI's own help centre has already described the date as proposed, with the official termination date still to be confirmed between both companies. Plan for 12 November. Do not plan on it slipping.


Zero Data Retention Is a Cursor Guarantee, Not an OpenAI One

The ZDR your reviewer approved is a property of Cursor's contracts with model providers, and it does not travel with your API key. Cursor's data-use page states that "Cursor maintains zero data retention (ZDR) agreements with all providers" — Cursor holds those agreements, on your behalf, for traffic Cursor pays for. The moment a developer pastes in a personal or corporate OpenAI key, the counterparty changes. Cursor's help centre says your "data handling follows the privacy policy of your chosen provider."

That is a real change in posture, not a formality. OpenAI's default API behaviour is that "abuse monitoring logs are generated for all API feature usage and retained for up to 30 days." Zero Data Retention on the OpenAI platform is not a toggle — it is "subject to prior approval by OpenAI and acceptance of additional requirements", granted per organisation or project, and limited to an enumerated list of eligible endpoints. So unless your OpenAI account already carries an approved ZDR arrangement, switching Cursor to your own key moves your source code from a zero-retention path to a 30-day-retention path, silently, at the exact moment everyone believes they mitigated a risk.

This is the same trap as the Anthropic covered-models carve-out, where a specific model class required retention to be on and the enterprise ZDR banner stayed up anyway. A data-handling guarantee is scoped to a route. Change the route and you have changed the guarantee, whatever the dashboard still says.

Cursor's compliance posture is otherwise strong and worth stating fairly: the company holds AIUC-1, ISO/IEC 27001:2022, ISO/IEC 42001:2023 and a SOC 2 Type II attestation, and on Business and Enterprise plans an admin can enforce Privacy Mode organisation-wide so members cannot disable it. None of that is in question. The point is narrower and sharper: the enforced setting your admin owns and the retention path your developer's key selects are two different controls, and only one of them is locked.


Your Key Does Not Take SpaceX Out of the Data Path

Even with a custom key, the code still goes through Cursor's backend, because that is where the prompt is built. Cursor's documentation is explicit that your API key "is sent to our backend with every request because all requests are routed through Cursor's servers for final prompt building." BYOK changes who bills you for inference. It does not change who assembles the context window, and the context window is where your repository content actually lives.

The feature coverage is narrower than most teams assume, too. Cursor states that "Tab completion continues using Cursor's built-in models" — the single highest-frequency AI interaction in the editor never touches your key at all. Per OpenAI's own help centre, a customer key covers local Chat and Agent requests only, and does not apply to Cursor Tab, Auto, Cloud or Background Agents, Automations, the Cursor CLI, or Cursor's API and SDK. If your threat model was "our code should not sit with a supplier we did not diligence," BYOK addresses a minority of the traffic and none of the routing.

There is a governance consequence here that is easy to miss. Enterprise admins can allowlist or blocklist models at the provider and model level, but Cursor's docs treat personal keys as a separate control: "Enterprise teams can prevent team members from using their own API keys with third-party providers (OpenAI, Anthropic, Azure, AWS Bedrock)." One vendor's write-up of the same admin surface puts it bluntly — "blocking a provider and restricting personal API keys are separate settings, and the first does not stand in for the second." A model blocklist you configured last quarter will not stop a developer routing around the cutoff with a personal key in November. We saw the same gap in Antigravity's admin allowlist: a control that exists in the console is not a control that governs every path.


The Price List Now Points at the Owner's Models

BYOK is not even a cost dodge, and the fee structure quietly steers you toward SpaceX's own models. Cursor charges Teams and Enterprise customers "a Cursor Token Rate of $0.25 per million tokens on third-party model requests", covering input, output and cached tokens. That rate "also applies to BYOK usage, in addition to whatever you pay your API provider directly." You bring the key, you pay the provider, and you still pay Cursor per token.

Now look at what is exempt. Per the same page, "first-party Cursor models, including Grok and Composer, are exempt" from that rate. Grok is xAI's model family, and Cursor's data-use page now names SpaceXAI alongside OpenAI and Anthropic among the providers it links documentation for. Cursor's own pricing page confirms the exemption applies to Grok and Composer specifically.

So the picture is a gradient, not a wall. Claude and Gemini carry a per-token surcharge. The new owner's models do not. OpenAI's models are leaving. Nobody has to mandate anything for consumption to migrate — the meter does it.

Be precise about what changed and when, though, because it is easy to read this as a post-deal tax and it is not one. Cursor publishes no effective date for the first-party exemption, and there is no evidence it was introduced at closing — the surcharge structure appears to predate the acquisition. That makes it more durable, not less: this is the standing price list, and it now happens to point at the owner's models. If you priced Cursor on the assumption that model choice was economically neutral, that assumption is gone either way, and the comparative economics of the Grok line will make the drift look like good FinOps rather than lock-in.


The Honest Case That This Is Small

The strongest argument against panic is Cursor's own number, and it deserves a fair hearing. Cursor co-founder and CEO Michael Truell said OpenAI models account for about 5% of Cursor's user traffic, and that the company is in discussions with OpenAI to resolve it. He wrote that Cursor was "sorry to see that OpenAI put out a note saying they plan to block Cursor users from accessing OpenAI models in three months." One outlet notes the platform already supports Anthropic, Google and xAI models, so 95% of traffic was already flowing through non-OpenAI providers. Anthropic co-founder Tom Brown said the company will "continue to increase compute to support Claude models in Cursor."

Take that seriously. For most teams the capability loss on 12 November is genuinely marginal, and the supply gap is being backfilled by a supplier with an incentive to backfill it fast.

But 5% is a vendor-reported average with an undefined denominator — Truell did not say whether it counts requests, tokens, users or revenue, or over what period — and an average is not a risk distribution. The question your security team will ask is not what share of usage moved — it is whether any workflow that was reviewed and approved against a named model now runs against a different one, and whether the ZDR representation in your file still describes the path the code takes. Those are the same questions the OpenRouter change-of-control raised: a data policy you can flip in a settings panel was never the same artefact as a contractual commitment, and an average tells you nothing about which 5% you are in.


What to Do Before 12 November

This Week:

  1. Pull the model-usage report from your Cursor team dashboard and find your actual OpenAI share. The 5% figure is Cursor's own platform-wide number, and it never defined its denominator. Your number is the only one that matters, and if you have teams that pinned an OpenAI model for a specific workflow, they are the migration.
  2. Check whether personal API keys are permitted in Team Settings → Models, and decide deliberately. Cursor treats the personal-key permission as a separate setting from the model allowlist. If you leave it on, you have accepted that ZDR does not apply to that traffic. Write that down as a decision, not a default.
  3. Ask your OpenAI account team, in writing, whether your organisation has an approved ZDR arrangement and which endpoints it covers. OpenAI grants it only on prior approval, per organisation or project. If the answer is no, BYOK inside Cursor is a 30-day-retention path and your DPA needs to say so.

Before 12 November:

  1. Re-pin the affected workflows to a model you intend to keep, and re-run your eval suite against it. Prompt behaviour does not survive a model swap intact — we covered how prompt techniques age across model versions, and a silent regression discovered in December is worse than a planned migration in October.
  2. Add the Cursor Token Rate to your FinOps model at $0.25 per million tokens for every third-party model, including BYOK traffic. Then price the same workload on the exempt first-party models, so the gradient is visible in a spreadsheet rather than emerging as unexplained drift.
  3. Confirm your egress controls still match Cursor's endpoints. Cursor documents distinct hosts for chat, Tab and codebase search — including api2.cursor.sh, api3.cursor.sh and repo42.cursor.sh — and warns that SSL inspection on those domains causes agent failures. If you are considering routing model traffic through your own gateway, test it against those constraints before you commit to it as the mitigation.

Before Renewal:

  1. Get a change-of-control notification obligation into the Cursor contract, and a model-availability commitment alongside it. You had fourteen days between the acquisition closing and a supplier cancelling. Notice periods are the only lever that works after the fact.
  2. Run the same exercise on your other AI tools. Every vendor in your stack that resells frontier models has an upstream contract you have never read, with a change-of-control clause in it. GitHub Copilot, Windsurf and Codex all sit on the same structural dependency.

The Bottom Line

This is the second time in fourteen months that a frontier lab has cut model supply to a major developer tool over the identity of its expected acquirer rather than anything the tool or its customers did — Anthropic did the same to Windsurf in June 2025, co-founder Jared Kaplan saying "it would be odd for us to be selling Claude to OpenAI". And that precedent is worse than it first looks: OpenAI's acquisition of Windsurf was never confirmed by either company, it collapsed the following month, and Cognition ended up buying what remained. The supply was cut over a deal that never happened — which means the trigger does not even require a completed change of control, only a credible report of one. The lesson is not about Cursor. It is that a compliance guarantee written by your vendor is only as durable as your vendor's own supply contracts, and the mitigation your team will reach for under time pressure is the one most likely to trade a control away without anyone noticing. Cursor told you, in its own documentation, exactly what BYOK costs you. The failure mode is not that the information was hidden. It is that nobody re-reads a help page for a workaround they consider obvious.

Ten weeks is enough time to migrate models and re-run evals. It is not enough time to re-run a security review you did not know you needed.

Your key does not make it your data path. It only makes it your bill.

Continue Reading

Share:

Frequently Asked Questions

When does OpenAI stop serving its models to Cursor?

OpenAI notified SpaceX on 28 August 2026 that it intends to wind down the contract supplying OpenAI models to Cursor, with a proposed cutoff of 12 November 2026. OpenAI has described the date as proposed, with the official termination date still to be confirmed between the two companies, so plan for 12 November rather than assuming it slips.

Does using my own OpenAI API key in Cursor keep Zero Data Retention?

No. Cursor's help documentation states that its Zero Data Retention policy does not apply when you use your own API keys, and that data handling then follows the privacy policy of your chosen provider. OpenAI's default is that abuse-monitoring logs are retained for up to 30 days, and Zero Data Retention on the OpenAI platform requires prior approval per organisation or project.

Does a custom API key stop my code going through Cursor's servers?

No. Cursor's documentation states that your API key is sent to Cursor's backend with every request because all requests are routed through Cursor's servers for final prompt building. Bring-your-own-key changes who bills you for inference, not who assembles the context window.

Which Cursor features do not work with a custom API key?

Cursor states that Tab completion continues to use Cursor's built-in models regardless of your key. Per OpenAI's help centre, a customer key covers local Chat and Agent requests only and does not apply to Cursor Tab, Auto, Cloud Agents, Background Agents, Automations, the Cursor CLI, API or SDK.

Is bring-your-own-key cheaper on Cursor Teams and Enterprise plans?

Not entirely. Cursor charges Teams and Enterprise customers a Cursor Token Rate of $0.25 per million tokens on third-party model requests, covering input, output and cached tokens, and that rate also applies to BYOK usage on top of what you pay your provider directly. First-party Cursor models, including Grok and Composer, are exempt.

Can a Cursor admin block developers from using personal API keys?

Yes. Cursor's enterprise documentation states that enterprise teams can prevent members from using their own API keys with third-party providers including OpenAI, Anthropic, Azure and AWS Bedrock, configured in Team Settings then Models. It is a separate setting from the model allowlist or blocklist, so blocking a provider does not by itself stop personal-key traffic.

Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe

Related Articles

copyright indemnity

Sony Sued Anthropic. Re-Prompting Voids Your Indemnity.

Sony Music Publishing and Warner Chappell allege Claude's lyric guardrails are defeated by re-prompting. That exact behaviour trips a condition in every major AI copyright indemnity — Microsoft's, Google's, OpenAI's and Anthropic's own — by four different routes.

August 30, 2026
AI coding agents

Cursor Refused. The Next Chat Didn't. Scope the Creds.

Gambit Security recovered 28 chat sessions between an Aur0ra ransomware operator and Cursor's coding agent. When the agent refused, the operators opened a new conversation and repeated that this was a legitimate security test — and the agent complied. Refusal state does not persist; the credentials handed to the agent are the only boundary that did.

August 29, 2026
AI inference

3,400 Tokens/s Was Batch 1. At 100K Context, It's Batch 12.

Nvidia's 3,400 tokens/sec on Groq 3 LPX and Cerebras' 4,400 on CS-4 are both single-stream figures. On a 256-LPU rack at 100K context, the memory math caps concurrency near a batch of 12 — so any capacity plan sized off a headline token rate is sized for one user.

August 29, 2026
DryvIQ

Nasuni Bought DryvIQ. Now Ask Which Connectors Survive.

Nasuni acquired DryvIQ on August 27, 2026, taking ownership of the classification and migration engine 1,100 enterprises use across 40+ repositories. The announcement funds integration with Nasuni's own platform and commits to nothing about the connectors that move data elsewhere.

August 28, 2026

Latest Articles

View All →