The Filing That Changed the Counterparty
On August 14, a merger became effective and roughly 389 million shares of Class A stock changed hands. The document recording it runs to a few pages of standard language: an implied equity value of $60.0 billion, a share price set by the volume-weighted average close over the seven trading days before closing, and assumed options and restricted stock units converted at the effective time.1 By the following Monday, Anysphere—the company behind the AI coding tool Cursor—was a wholly owned subsidiary of Space Exploration Technologies Corp., and Cursor’s own announcement placed the team inside the SpaceXAI group that ships Grok.2
Nothing changed in the product that day. The models available in the editor were the same. The keybindings, the indexed codebases, the project rules files all survived the transaction untouched. Engineers who opened Cursor on Monday morning had no way to tell from the software that anything had happened.
That is exactly the problem worth thinking about. The thing that changed was not the tool. It was every commitment standing behind the tool—the data-retention policy, the roadmap, the model relationships, the incentives governing all three—and every one of those now belongs to a different company with a different balance sheet and a different strategic map. Cursor says its coding agents are used by 64 percent of Fortune 500 companies, a figure the company reports about itself rather than one an auditor confirmed.3 Even discounted, it describes a lot of enterprises whose development platform quietly acquired a new owner while they were doing something else.
The distinction that matters An enterprise does not adopt a product. It adopts an operator—a specific company with specific incentives that happens to ship that product—and the assurances that cleared the security review are properties of the operator, not artifacts of the code.
This is not an argument about Cursor, whose engineering reputation is well earned, nor about SpaceX, which has stated no intention of changing what enterprise customers rely on. It is an argument about a structural exposure that this transaction happens to illuminate more clearly than anything else in the market right now.
Procurement Approved an Operator, Not a Binary
Ask what actually got a coding assistant through a large enterprise’s approval gate and the answer is rarely technical. Sanchit Vir Gogia, chief analyst at Greyhound Research, framed the stakes in terms of position rather than features: a tool of this kind has stopped being a developer convenience and now operates at the point where software gets produced, sitting directly alongside the intellectual property that constitutes the firm’s value. On his reading, that makes it a control plane, and control planes seldom change owners without consequence.4
What cleared the gate was a stack of representations. Zero data retention. A defined set of subprocessors. Model choice presented as a durable product principle. A roadmap owned by founders whose incentives were legible to any CIO who had raised venture money. Justin Greis, CEO of the consulting firm Acceligence, observed that zero data retention was not merely a security feature for many buyers—it was the foundational element that made security teams, legal departments, and compliance officers comfortable with AI-assisted development in the first place.5
Representations of that kind sit on a spectrum. At one end are contractual terms with defined remedies, audit rights, and survival clauses that bind a successor. At the other are product principles, blog posts, and the general sense a buyer forms about a company’s character. Most enterprise AI adoption over the past three years has leaned heavily on the second category, because the first category was thin and the pace of adoption did not wait for it to thicken.
A change of control tests which category each assurance falls into. Gogia’s test for whether a retention promise means anything is worth adopting wholesale, and he also pointed out that the guarantee was layered rather than absolute even before the transaction: Cursor’s standard Privacy Mode permits some code data to be stored for product functionality, while only a stricter legacy setting retains nothing.4 Zero was the exception, not the default, and a buyer who assumed otherwise had made an assumption rather than signed a term.
“…survives only where it stays contractual, auditable, enforceable and fenced from affiliate use.”
— Sanchit Vir Gogia, chief analyst, Greyhound Research, on zero-data-retention commitments, June 2026
A second dynamic catches procurement teams off guard, and it is not vendor evasiveness. Between announcement in June and closing in August, antitrust rules restricted how far a buyer and a target may coordinate before a deal completes. Elon Musk declined to discuss combined-company roadmap questions on an earnings call, citing the need to avoid “gun jumping.”6 The uncertainty window is therefore a legal feature of merger review, not a communications failure—which means the period when customers most want commitments is precisely the period when neither party is permitted to give them.
Model Neutrality: An Agreement You Never Signed
The most consequential dependency in an AI development platform is the one the customer has the least visibility into.
When an enterprise buys seats in a model-agnostic coding tool, it is implicitly relying on a chain: its contract with the tool vendor, the vendor’s commercial agreements with each model provider, and each model provider’s own access to compute. The enterprise is party to exactly one link in that chain. The rest are agreements between other people, terminable on terms the enterprise will never read.

That is not a theoretical concern in this market. Anthropic’s commercial terms prohibit using its models to build competing products, and the company has enforced them repeatedly. It restricted a rival coding tool’s access in June 2025 on short notice. It revoked OpenAI’s API access in August 2025 after finding OpenAI staff using Claude Code ahead of a launch, with a spokesperson stating the use violated its terms of service.7 In January 2026, it blocked xAI staff from reaching Claude models through Cursor, an action first reported after xAI cofounder Tony Wu told employees in an internal message that Anthropic’s models had stopped responding in the editor.8

That last episode is worth holding still for a moment. The tool through which a competitor’s access was severed is now owned by that competitor’s parent company. Under a plain reading of the terms that produced the January enforcement, whether Cursor continues to offer Claude is not a product decision Cursor’s team can make unilaterally. It is a commercial judgment belonging to Anthropic.
The countervailing force is unusual, and it is why the alarmed reading of this deal is probably wrong. In May 2026, Anthropic contracted for the entire compute capacity of SpaceX’s Colossus 1 data center—more than 300 megawatts and over 220,000 NVIDIA GPUs—capacity it said would directly improve service for paying Claude subscribers.9 Anthropic’s landlord now owns one of its largest distribution channels. Neither party has an obvious interest in a rupture. Mutual dependency is currently doing the work that a contract would normally do.
An enterprise architecture that depends on two firms continuing to find each other useful is not governed. It is fortunate. Fortune is a fine thing to have and a poor thing to plan around, and that distinction is the whole point of a risk function.
Count the Exits Before You Need One
Every honest conversation about platform risk comes down to the same question: what would it actually take to leave? Most organizations have a confident answer and very little evidence for it.
A survey of 542 U.S. C-suite executives and decision-makers at companies with paid AI vendor contracts, fielded in early 2026, found 89 percent believed they could switch AI vendors within a month. Among those who had actually attempted a migration, 58 percent said it either failed outright or demanded far more effort than expected. Seventy-four percent said losing their primary AI vendor would disrupt daily operations or leave them unable to function; 6 percent said they could walk away cleanly.10

That gap between believed and demonstrated portability is where the second-order risk lives, and it compounds in a consolidating market. Consider what happened to the escape hatches during a single month. In mid-June 2026, Cursor acqui-hired Continue, an open-source coding assistant with roughly 34,000 GitHub stars that had built its identity on bring-your-own-model flexibility and worked across VS Code, JetBrains, and the terminal. The product was retired, the repository went read-only, and hosted customer data was deleted after a July 15 export deadline. The Apache-licensed code remains forkable, but the team that maintained it does not.11 The same week, SpaceX announced its agreement to acquire Cursor—which placed Continue’s former codebase under an ownership chain running through Cursor to SpaceX.
Cursor had previously acquired Supermaven and Graphite. Windsurf passed through a collapsed OpenAI deal, a licensing arrangement that moved its leadership to Google, and an acquisition of the remaining business by Cognition, ending as a rebranded product in someone else’s family. The pattern is not that consolidation is happening; consolidation always happens. The pattern is that the alternatives an enterprise would list in a contingency plan are being removed at roughly the same rate the plan would need to be executed.
Price is the other half of the mechanism, and it is set by arithmetic the customer never sees. An acquirer that pays roughly fifteen times revenue is underwriting a growth curve, and growth curves that steep are not delivered by seat expansion alone. Reported annualized revenue figures for Cursor in mid-2026 vary by source between roughly $2 billion and $4 billion; Morgan Stanley’s published estimates run to $8 billion by year-end and about $33 billion by 2030, which are projections rather than company guidance.12

Adjacent markets show what the far end of this looks like once switching costs have fully hardened. Following Broadcom’s acquisition of VMware, the elimination of perpetual licensing, mandatory bundling, and raised core minimums produced renewal increases that licensing advisors have commonly reported in the triple digits, with AT&T litigating over a reported 1,050 percent increase.13 The virtualization market is not the AI tooling market, and a coding assistant is far easier to replace than a hypervisor estate. But the mechanism transfers cleanly: acquirers reprice when the customer’s alternative is expensive, and the customer’s alternative gets more expensive the longer the platform sits at the center of the workflow.
Not every analyst reads the transaction as a risk event, and the optimistic case deserves a fair hearing. Arnal Dayaratna, research vice president for software development at IDC, argued that Cursor’s binding constraint was access to GPUs, and that SpaceX resolves it decisively.3 Shashi Bellamkonda of Info-Tech Research Group noted that a tool carrying heavy inference costs could plausibly deliver better performance at a lower price under an owner that operates its own data centers.3 Cursor’s own statement on closing emphasized exactly this, citing access to the largest GPU fleet in the world as the reason its models would become both stronger and more economical.2 That is a coherent thesis, and enterprises may well end up better served. The governance point is orthogonal: an outcome that depends entirely on the acquirer’s goodwill is an outcome you have not underwritten.
Where the Industry Hedged Its Own Bet
The most useful signal is not what vendors say about acquisitions. It is where they have chosen to place infrastructure they cannot easily take back.
In December 2025, Anthropic donated the Model Context Protocol to the Agentic AI Foundation, a directed fund under the Linux Foundation co-founded with Block and OpenAI and supported by Google, Microsoft, AWS, Cloudflare, and Bloomberg. OpenAI contributed AGENTS.md, adopted by more than 60,000 open-source projects and by agent tooling across the competitive field, and Block contributed its goose framework.14 The stated purpose was vendor-neutral governance under the same stewardship model that carries Kubernetes and PyTorch.
Read that as competitors independently concluding that the integration layer is too important to leave in any single company’s ownership. For an enterprise, the implication is practical rather than philosophical: portability now lives at the interface, not in the product. Tool configuration expressed in an open convention, context wired through a standardized protocol, and model calls routed through a gateway the enterprise controls are all assets that survive an acquisition. A workflow built entirely inside one vendor’s proprietary surface is not.
It is also worth noting that ownership stability guarantees nothing about term stability, and the clearest illustration comes from the least-acquired vendor in the category. On June 1, 2026, GitHub moved every Copilot plan from request-based to usage-based billing, replacing premium request units with AI Credits metered on token consumption. Base subscription prices held, but what those prices include changed; annual Pro and Pro+ plans are being retired rather than renewed, model multipliers increased for annual subscribers mid-term, and the previous fallback to a cheaper model after exhausting an allowance is gone.15 No change of control was required. Microsoft has owned GitHub since 2018. The economics of a development platform shifted anyway, because the underlying cost structure of agentic workloads made the old model untenable.
| Assurance | Typical basis in an AI tooling agreement | Behavior at a change of control |
|---|---|---|
| Data retention and training exclusion | Often a product setting or policy page | Modifiable via terms update unless contractual and assignable |
| Model choice and availability | Third-party agreements the customer never sees | Governed by the model provider’s competitive terms |
| Subprocessor list and affiliate access | Disclosed, sometimes with notice rights | Notice may be preserved; the right to exit on notice often is not |
| Pricing and included allowances | Fixed for the current term | Repriced at renewal against your switching cost |
| Security certifications | SOC 2 / ISO scope statements | Valid until scope is redefined under new entity structure |
| Roadmap and product continuity | Rarely contractual | Fully at acquirer discretion, including brand retirement |
Underwriting the Next Change of Control
The instinct after an event like this is to rip out the tool. That is usually the wrong move—a reactive migration converts a manageable governance gap into a certain productivity loss, and the current owner has given no indication of degrading the product. The better response is to fix the class of exposure rather than the instance, because the next acquisition is already being negotiated somewhere.
Start with the contract you actually hold. Pull the agreement and find out whether your data-handling commitments are terms with survival language or settings described in documentation, whether assignment to a successor entity triggers any right at all, and whether affiliate access to your code and telemetry is fenced or merely unmentioned. Most teams discover the answer is thinner than the security review assumed. That discovery is worth more than the tool decision it informs.
Then add the clauses that make an ownership change a governed event rather than a surprise. Notice on change of control, with a defined window to terminate without penalty. Subprocessor change notification with a right to object. Data-handling terms that expressly bind successors and assigns. A stated commitment on model availability, or at minimum advance notice before a supported model is withdrawn. None of this is exotic; it is standard third-party risk language that AI procurement has been moving too quickly to insist on.
Architect so the exit is cheap before you need it to be. Route model calls through a gateway your organization operates rather than letting each tool hold its own provider relationships, so a model can be swapped without touching developer workflow. Keep configuration in open conventions and portable formats. Treat the coding interface as replaceable and the surrounding pipeline—review, testing, scanning, deployment—as the durable asset, because that pipeline is where your governance actually executes.
Tier by sensitivity instead of standardizing everywhere. The calculus that makes a single platform attractive across an engineering organization looks different for a repository under export control, a regulated codebase, or a system where source access carries contractual obligations to a customer. Concentration is efficient in the ordinary case and unacceptable in the exceptional one, and most organizations have never drawn the line between them.
Finally, rehearse the migration once, on a real team, with a stopwatch. Eighty-nine percent confidence and 58 percent failure rates cannot both be right. A four-week pilot on a secondary tool costs a fraction of what an unplanned migration costs and replaces an assumption with a number—the only thing that turns a contingency plan into a capability. Continuous evaluation is not disloyalty to a vendor. It is the price of having a choice.
Diligence With an Expiration Date
The security review that approved your development platform was accurate on the day it was signed. It described a company’s policies, incentives, and commitments as they existed at a moment, and each can be reassigned in a single filing. What survives a change of control is what was written down with teeth; what does not survive is everything the buyer merely believed. Cursor’s engineers will keep shipping, SpaceX may well deliver the cheaper and faster product it has promised, and this particular transaction may end up a footnote in a market that consolidated the way markets do. The exposure is not that any of it goes badly. The exposure is that an organization discovered its assurances were unenforceable at the moment it needed to enforce them—and that a due diligence file, unlike a codebase, has no version history to tell you when it stopped being true.
References
- Space Exploration Technologies Corp., Form 8-K, Item 2.01, filed August 14, 2026, U.S. Securities and Exchange Commission; “SpaceX Completes $60 Billion Cursor Acquisition to Expand AI Coding Tools,” Bloomberg, August 14, 2026.
- “SpaceX officially closes its Cursor acquisition,” TechCrunch, August 15, 2026; Cursor (@cursor_ai) announcement, August 14, 2026.
- Evan Schuman, “SpaceX’s Planned $60 Billion Deal for Cursor Raises Questions for CIOs,” InfoWorld, June 16, 2026 (Fortune 500 figure is Cursor’s own claim; comments from Arnal Dayaratna, IDC, and Shashi Bellamkonda, Info-Tech Research Group).
- Sanchit Vir Gogia, chief analyst, Greyhound Research, quoted in Schuman, InfoWorld, June 16, 2026.
- Justin Greis, CEO, Acceligence, quoted in Schuman, InfoWorld, June 16, 2026.
- “Cursor Brand Name May Not Survive SpaceX Acquisition,” PYMNTS, August 2026, reporting The Information.
- “Anthropic Cuts OpenAI’s Claude API Access Over Alleged Terms-of-Service Breach,” reporting Wired, August 2025; statement attributed to Anthropic spokesperson Christopher Nulty.
- “Anthropic cracks down on unauthorized Claude usage by third-party harnesses and rivals,” VentureBeat, January 9, 2026, reporting internal xAI communication first surfaced by Kylie Robison, Core Memory.
- “Higher usage limits for Claude and a compute deal with SpaceX,” Anthropic, May 6, 2026; “New Compute Partnership with Anthropic,” SpaceXAI, May 6, 2026; “Anthropic, SpaceX announce compute deal that includes space development,” CNBC, May 6, 2026.
- “AI vendor loss would disrupt 3 in 4 enterprises,” Zapier, April 2026; survey of 542 U.S. C-level executives and decision-makers conducted via Centiment, January 30–February 6, 2026, margin of error approximately ±4 percent.
- “Cursor quietly acquires Continue, an open-source alternative to GitHub Copilot,” The New Stack, June 22, 2026; Dealroom deal record, June 2026.
- Morgan Stanley estimates attributed to analyst Adam Jonas, as reported August 2026; reported annualized revenue figures as cited in Schuman, InfoWorld, June 16, 2026, and contemporaneous trade reporting, which vary between roughly $2 billion and $4 billion. Forward figures are analyst projections, not company guidance.
- “Broadcom VMware Pricing Report 2026,” Redress Compliance, March 2026; “VMware Cost Trap 2026: IT Teams Examine Alternatives,” CloudMagazin, 2026 (AT&T litigation and reported increase figures). Reported percentages vary by source and customer profile; treat as directional.
- “Linux Foundation Announces the Formation of the Agentic AI Foundation,” The Linux Foundation, December 9, 2025; “Donating the Model Context Protocol and establishing the Agentic AI Foundation,” Anthropic, December 9, 2025; “OpenAI co-founds the Agentic AI Foundation under the Linux Foundation,” OpenAI, December 2025.
- “GitHub Copilot is moving to usage-based billing,” The GitHub Blog, April 2026; “What changed with Copilot billing (legacy),” GitHub Docs, 2026.