The Crossfire Clause: When Two AI Companies Fight, Your Tools Take the Hit
On Friday night, OpenAI announced it will cut off Cursor's access to its models on November 12. Cursor did nothing wrong. Its users did nothing wrong. SpaceX bought Cursor, OpenAI has a long feud with SpaceX's owner, and a change-of-control window in the contract between the two companies let OpenAI walk. The developers in the middle just lose a model. We call the exposure the crossfire clause, the unwritten term in every AI tool relationship that your access can end over a fight you're not in. This is the scenario we've been building client systems for since we first wrote about single-model risk, and it should reset how every company thinks about the layer between its people and the models they use.
What actually happened with Cursor?
A model provider used a contract clause with a tool vendor to end service to the vendor's customers.
SpaceX closed its purchase of Cursor in mid-August. Two weeks later, OpenAI notified SpaceX it would wind down the agreement supplying its models to Cursor, giving the maximum notice its contract allowed. OpenAI's stated reason was trust. Based on its history with Elon Musk's companies, it said it couldn't be confident SpaceX would honor its terms of service, so its custom agreement's change-of-control window got exercised and its next model will never reach Cursor at all. Cursor's CEO responded that OpenAI models carry about five percent of the tool's traffic, which softens the blow for Cursor and does nothing for the developers whose workflows ran on that five percent. And this isn't the first time. In June 2025, Anthropic cut off Windsurf's model access with days of notice while OpenAI was reportedly trying to acquire it. Cutting the tool to hit the rival now has two public precedents.
What is the crossfire clause?
It's the unwritten term in your AI tool relationships that says your access depends on relationships between other companies.
We've written about the availability clause, the way working AI access ends on a vendor's timeline for a vendor's reasons, whether that's a government order, a capacity shortage, a pricing change, or a business decision. The crossfire clause is different in one way that matters. Your access ends because of who owns the tool you chose, and the dispute driving it runs through a layer you don't control and can't see into. The contract that governed Cursor's model supply had a change-of-control provision in it. Cursor's customers never read that contract, because it wasn't theirs. Every AI tool you depend on has its own agreements with the labs whose models it routes, those agreements have termination rights you'll never review, and any event in the tool vendor's life, an acquisition, a merger, a funding round from the wrong investor, a partnership with a rival, can trip one. The clause is real, it's just in someone else's contract.
Why did the tools become the battlefield?
Because the labs figured out that the harness is where customers actually live, and cutting the harness hurts the rival more than cutting the model.
Every frontier lab now ships its own coding and agent tools, and those tools run the lab's own models. Third-party tools that let users pick any model have become the contested ground, because whoever owns the tool sees the usage, collects the corrections, learns the workflows, and holds the customer relationship. A Moody's executive made the case publicly a week before the Cursor news that companies should build their own harness layer, the software that wraps models and connects them to workflows, precisely because it decouples workflows from any single model and makes the company less dependent on any single provider. We'd argued the same in the harness gap. The conversation is moving from open models to open harnesses, and the companies that own that layer are the ones the crossfire can't reach.
Haven't we said this before?
Yes, repeatedly, and this is the moment the argument was built for.
We'd rather have been wrong. When we wrote that your AI vendor has an off switch you don't control, the trigger was a government order. When we wrote about the model socket, the argument was that the boundary you build around a model matters more than which model you pick. When we laid out the assembly answer, the instruction was to own the seams and treat every model as a guest. Not one of those pieces predicted that a lab would cut off a tool because a rival bought it, and every one of them prescribed the architecture that survives it. That's the point of building for single-model risk. You don't have to predict the trigger. A workflow wired through a socket you own, with model choice as a config setting, treats November 12 as a routing change. A workflow wired directly to one model inside one tool treats it as an outage with a deadline.
Where does open weight fit?
It's the floor nobody can cut off, and every company should have one.
Nothing in the Cursor story touches a model whose weights sit on your own infrastructure, because there's no contract to exercise and no relationship to sever. That's the real reason open-weight models belong in your stack, beyond cost. We covered the sorting logic in the weight line and the budget version in the frontier freeze, and the crossfire adds a third reason to both. An open model behind your socket is the guaranteed floor that keeps your operations running while frontier relationships come and go, and it turns a cutoff into a temporary quality dip instead of an outage. Frontier models still earn their place on the work that needs them. The floor just means no lab holds a switch to your whole operation.
How exposed is your company right now?
More than you think, and finding out takes one afternoon and no new tools.
List every AI tool your company depends on. For each one, write down who owns it, whose models it routes, what governs your own access, and whether your relationship with each model provider is direct or runs through the tool. Then ask the crossfire question. If the tool vendor and the model provider fall out tomorrow, which of your workflows stop? Most companies discover their whole stack rides through two or three tools whose vendor relationships nobody examined. The fixes follow from the list. Hold direct relationships with the model providers that matter, which is why Cursor developers using their own OpenAI keys keep working while everyone routed through Cursor's contract doesn't. Put a socket you own between your workflows and every tool, so models and tools both become replaceable parts. Keep an open-weight floor underneath so the worst case is degraded, never dark. And put the crossfire question into every tool renewal so the list stays current. The goal was never a safer vendor. It's an architecture where no relationship between two other companies can take a workflow of yours down.
If you want your AI stack audited for crossfire exposure and rebuilt on seams you own, start with an AI Blueprint or reach us at contact@theyor.com.