Since June 2025, a frontier lab withdrawing or restricting model access affecting a named coding tool or peer lab has gone from unthinkable to documented fact — four times, by our count of the dated instances we could confirm. Anthropic limited Windsurf’s direct Claude access, revoked OpenAI’s API access, and technically blocked subscription OAuth tokens used outside Claude Code. Now OpenAI has notified SpaceX, Cursor’s new owner, that it intends to wind down Cursor’s access to OpenAI models.
If your team ships software with an AI coding tool — Cursor, Windsurf, Claude Code, Copilot, or one of the smaller harnesses — these events are your supply chain. The model behind your tool is provisioned under a contract between two other companies, and that contract can end on a schedule you do not control. What happened to Windsurf’s users in June 2025 took effect in under five days, by Windsurf’s own account.
This page is a ledger, not a narrative. It logs the dated instances with the action taken, the notice given, and the outcome. It also does two things most coverage skips: it separates the one peer-lab dispute from the downstream-tool cutoffs so the rows cannot be conflated, and it quotes — verbatim — what five major labs’ published terms actually say about assignment, change of control, and competing products. Candidates that did not survive verification are listed too, with the reasons they failed.
- 01This is a class of event, not a one-off.Four dated instances since June 2025 of a frontier lab withdrawing or restricting model access affecting a named coding tool or peer lab: Windsurf (June 2025), OpenAI (July 2025), OpenCode and other harnesses (January 2026), and Cursor (August 2026).
- 02The verb matters — these are four different actions.Anthropic limited Windsurf’s direct access, revoked OpenAI’s API access with an explicit benchmarking exception, and technically blocked subscription OAuth tokens while leaving API keys untouched. OpenAI has notified intent to wind down Cursor’s access — nothing has been cut off yet as of August 28, 2026.
- 03One row is a different shape from the others.The July 2025 dispute is a lab restricting a peer lab’s own internal API usage — not a downstream tool that integrates models being cut off. The ledger labels the two groups separately so a reader citing one row cannot mistake it for the other.
- 04OpenAI’s published terms never say ‘change of control.’The phrase appears only in OpenAI’s blog describing its custom, non-public Cursor contract. The published Business Terms key assignment to ‘a successor to substantially all’ assets or business — a materially different formulation. The custom deal and the public terms are different documents.
- 05Treat model supply as vendor risk you can score.Notice periods in these instances ranged from under five days (vendor-stated) to 76 days (a stated contract maximum). Portability across harnesses, API-key rather than subscription-auth integrations, and a written fallback plan are the practical hedges.
01 — The LedgerThe dated instances we could confirm.
First, definitions. A supply cutoff, as this ledger uses the term, is a lab-initiated withdrawal or restriction of model access — not a tool switching vendors by choice, and not an outage. The rows split into two labelled groups because the events are not the same shape. In the first group, a lab restricts a downstream tool — a product that integrates the lab’s models and serves them to its own users. In the second, a lab restricts a peer lab’s own internal API usage — a competitor as a customer, not a reseller. Citing a row from one group as if it belonged to the other is the most common error in coverage of these events.
| Date | Action | What happened | Notice given | Outcome | Source |
|---|---|---|---|---|---|
| Lab → downstream tool — a supplier restricting a product that integrates its models | |||||
| June 3, 2025 (reported; action taken in the preceding days) | Anthropic → Windsurf | Limited Windsurf’s direct first-party access to Claude 3.7 Sonnet and Claude 3.5 Sonnet — described by TechCrunch as cutting off nearly all direct capacity. Windsurf had also been denied direct access to Claude 4 at its May 2025 launch. | Under 5 days, per Windsurf | Windsurf pivoted to third-party inference providers. OpenAI’s reported ~$3B acquisition of Windsurf collapsed in July 2025; Google licensed Windsurf’s technology for $2.4B and hired its founders; Cognition AI acquired the remaining company. | TechCrunch; CNBC |
| January 9, 2026 (technical block); policy language clarified February 19–20, 2026 | Anthropic → OpenCode (named) and other third-party harnesses | Technically blocked Claude Free/Pro/Max subscription OAuth tokens from being used outside the official Claude Code CLI and Claude.ai. The Claude API key path was not touched by this action. | Minimal or no advance notice reported | OpenCode users saw an authorization error; the maintainers merged a change removing the Anthropic OAuth plugin (reported mid-March 2026). | The Register |
| August 28, 2026 | OpenAI → Cursor (Anysphere; acquired by SpaceX in a $60B all-stock deal that closed August 14, 2026) | Notified intent to wind down the contract supplying OpenAI models to Cursor, with a proposed shutoff date of November 12, 2026. OpenAI describes the basis as a cancellation right in a custom, non-public contract triggered by a change of control. Nothing has been cut off as of this date. | 76 days — stated by OpenAI as the maximum its contract provides | Open as of August 28, 2026. | OpenAI blog |
| Lab → peer lab — a supplier restricting a competitor’s own internal API usage | |||||
| July 29, 2025 (action); reported August 1–4, 2025 | Anthropic → OpenAI (as an API customer, not a resold product) | Revoked OpenAI’s organization-level access to the Claude API, citing a terms-of-service violation, while stating it would keep providing access for benchmarking and safety evaluations. | Not stated in reporting; framed as immediate | OpenAI publicly noted its own API remained available to Anthropic; GPT-5 launched shortly after, as previously scheduled. | PYMNTS, citing Wired |
One more boundary worth naming: a lab retiring its own model IDs on a published schedule is a related but separate discipline — that calendar lives in our model deprecation and API sunset guide. This ledger only logs a lab restricting someone else’s access.
02 — MechanismsFour different levers, not one repeated story.
Aggregator coverage tends to compress these events into one headline — a lab “bans” a tool. The record shows four distinct mechanisms, and the differences are what a procurement or engineering lead actually needs to plan around. Three of the four were Anthropic actions, taken between June 2025 and February 2026, and each used a different lever than the one before it.
Capacity limiting
Anthropic limited direct first-party API capacity rather than invoking a contract clause publicly. The tool kept running on third-party inference — degraded supply, not a shutoff.
Terms-of-service revocation
Anthropic revoked organization-level API access citing its use-restrictions clause, while keeping an explicit exception for benchmarking and safety evaluations. A clause in the published terms, invoked.
Technical enforcement
A server-side block on subscription OAuth tokens used outside the official clients. No contract needed to change — the API-key path stayed open throughout.
Change-of-control cancellation
OpenAI has notified intent to end the deal, citing a cancellation window in a custom contract that it says a change of control opens. A 76-day notice with a proposed shutoff date — announced, not yet executed.
The pattern worth registering: only one of the four levers — the July 2025 revocation — was a publicly published contract clause being enforced as written. One was supply allocation with no clause cited, one was purely technical, and the newest one lives in a custom agreement the public has never seen. Reading a lab’s published terms tells you some of your exposure, not the whole of it — which is exactly why the second table in this post quotes what the published documents do and do not contain.
03 — June 2025Windsurf: limited access, under five days’ notice.
The first confirmed instance in this ledger. In early June 2025, Anthropic limited Windsurf’s direct first-party access to Claude 3.7 Sonnet and Claude 3.5 Sonnet — TechCrunch described the move as cutting off nearly all of Windsurf’s direct capacity. Windsurf said it received less than five days’ notice, a figure worth treating as vendor-stated since Anthropic never published its own timeline. Windsurf had already been denied direct access to Claude 4 at that model’s May 2025 launch, forcing a bring-your-own-key workaround for its users.
The context was an acquisition. OpenAI was reportedly in talks to buy Windsurf for roughly $3 billion, and Anthropic’s co-founder and Chief Science Officer Jared Kaplan addressed the decision directly — framing it as capacity triage toward customers with a future, with the acquisition rumor as subtext. Windsurf CEO Varun Mohan said publicly: “We have been very clear to Anthropic that this is not our desire — we wanted to pay them for the full capacity.”
“I think it would be odd for us to be selling Claude to OpenAI.”— Jared Kaplan, Co-founder and Chief Science Officer, Anthropic, June 2025
The aftermath reshaped the company. The reported ~$3 billion OpenAI acquisition collapsed around July 11, 2025 — reportedly over Microsoft’s IP-access rights as an OpenAI investor. Within days, Google licensed Windsurf’s technology for $2.4 billion and hired CEO Varun Mohan, co-founder Douglas Chen, and other engineers; Cognition AI, the maker of Devin, then acquired the remaining company, announced July 14, 2025, as reported by CNBC. A supply restriction taken during deal talks preceded — no stronger causal claim than that — one of the stranger corporate unwinding sequences in the AI tooling market to date.
Windsurf’s account
Windsurf says it had less than five days between learning of the restriction and its taking effect. Vendor-stated; Anthropic published no timeline of its own.
OpenAI’s reported bid
OpenAI’s reported acquisition of Windsurf fell apart around July 11, 2025, reportedly over Microsoft’s IP-access rights as an OpenAI investor and partner.
Google’s license + hires
Google licensed Windsurf’s technology and hired its CEO, co-founder, and other engineers. Cognition AI acquired the remaining company days later.
04 — July 2025The peer-lab dispute is not a reseller cutoff.
On July 29, 2025, Anthropic revoked OpenAI’s organization-level access to the Claude API. Before the mechanism, be clear about who this affected: no end users lost a tool. OpenAI was not reselling Claude inside a product — its own technical staff were using Claude Code internally, reportedly ahead of GPT-5’s launch. That makes this the ledger’s one peer-lab row: a supplier restricting a competitor’s direct API usage, a fundamentally different relationship from Windsurf, OpenCode, or Cursor.
Anthropic spokesperson Christopher Nulty’s statement, as reported by Wired and carried by PYMNTS, said Claude Code had “become the go-to choice for coders everywhere,” that OpenAI’s technical staff were using Anthropic’s coding tools ahead of the GPT-5 launch, and that this was “a direct violation of our terms of service.” The operative clause is quoted in full in the terms table below — Anthropic’s use restrictions bar accessing the services to build a competing product, including training competing models.
Two details keep this row honest. First, the revocation carried an explicit exception: Anthropic said it would keep providing OpenAI API access “for the purposes of benchmarking and safety evaluations as is standard practice across the industry” — so “total ban” framings are wrong. Second, OpenAI’s Chief Communications Officer Hannah Wong pointed at the asymmetry: “While we respect Anthropic’s decision to cut off our API access, it’s disappointing considering our API remains available to them.” GPT-5 launched shortly afterward as scheduled.
05 — January 2026OAuth tokens blocked; API keys untouched.
The third Anthropic action is the most misreported, so state what changed and who it affected first. On January 9, 2026, Anthropic deployed a server-side technical block on Claude Free, Pro, and Max subscription OAuth tokens being used outside the official Claude Code CLI and Claude.ai. If you paid for a Claude subscription and pointed a third-party coding harness at it, that stopped working. If you used a Claude API key — the metered developer path — nothing changed. “Anthropic banned Claude API access” is the wrong sentence; the API key path was never touched by this action.
The named affected tool was OpenCode, an open-source coding agent, whose users began seeing an error: “This credential is only authorized for use with Claude Code and cannot be used for other API requests.” The block affected third-party harnesses broadly that authenticated by presenting themselves as the Claude Code client. Per The Register’s reporting, Anthropic engineer Thariq Shihipar said the restriction addressed “unusual traffic patterns” that made it hard for Anthropic to help subscribers debug rate-limit and account issues.
The policy language followed the technical block by about six weeks. Around February 19–20, 2026, Anthropic updated its documentation to state — as reported by The Register — that using OAuth tokens from subscription plans in any other product, tool, or service, including the Agent SDK, is not permitted. We attribute that wording to The Register’s account rather than quoting it as Anthropic’s verbatim current text, since the underlying docs page wording can shift. Anthropic reportedly also sent legal requests, and OpenCode’s maintainers merged a change removing the Anthropic OAuth plugin, reported mid-March 2026.
For teams, this row created a distinction that did not exist before: subscription-auth integrations and API-key integrations now carry different risk profiles. The first runs on consumer terms a lab can technically enforce overnight; the second runs on commercial terms with (some) published assignment and restriction language you can actually read.
06 — August 2026Cursor: notice given, nothing cut off yet.
The newest row, and the reason this ledger exists now. On August 28, 2026, OpenAI published a blog post stating it intends to wind down the contract that supplies OpenAI models to Cursor, with a proposed shutoff date of November 12, 2026. The trigger: SpaceX’s $60 billion all-stock acquisition of Anysphere, Cursor’s maker, which closed August 14, 2026. Precision matters here more than anywhere else in the ledger — nothing has been cut off as of August 28, 2026. This is a notification of intent with a 76-day window, which OpenAI describes as “the maximum notice provided by our contract.”
A change of control — the operative concept — is a contract event where a party’s ownership changes hands, and some agreements let the counterparty renegotiate or cancel when it happens. OpenAI’s stated reason leans on history with the acquirer: “We are making this choice because we cannot be confident that SpaceX will use our technology within our terms of service, based on our experience with Elon Musk’s companies violating contracts.” The post cites Twitter breaking contract terms after Musk’s acquisition and Musk’s admission under oath earlier in 2026 that xAI had violated OpenAI’s terms of service.
“Our custom agreement with Cursor gives us a limited time window to cancel it after a change of control.”— OpenAI, official blog post, August 28, 2026
That sentence contains this post’s most useful finding, unpacked in the terms table below: OpenAI’s published Business Terms never use the phrase “change of control.” The phrase appears only in OpenAI’s characterization of its custom, non-public Cursor contract. What the deal-makers signed and what the public terms say are different documents — and if your own vendor contract is custom, the published terms tell you less than you think.
The event itself is covered in depth in our companion piece on OpenAI’s decision to end Cursor’s model access; the acquisition backdrop is in our coverage of the SpaceX–Anysphere close. This ledger holds the row itself: notified August 28, proposed shutoff November 12, outcome open.
07 — VerificationCandidate rows rejected, with reasons.
A ledger is only as trustworthy as its rejections. Six candidate events came up during research that read, at headline level, like they belonged here — and did not survive verification against the class definition: a dated, confirmed instance of a frontier lab withdrawing or restricting model access affecting a named coding tool or peer lab. Listing them is evidence, not an appendix; it shows where the boundary of the class actually sits.
| Candidate | What the record shows | Why it does not qualify |
|---|---|---|
| OpenAI vs. DeepSeek “distillation” dispute (2025–2026) | An accusation-and-policy story: OpenAI and Microsoft investigating whether DeepSeek trained on OpenAI API outputs; OpenAI lobbying for restrictions on “PRC-produced” models. | No primary source found stating that on a specific date OpenAI revoked DeepSeek’s access to a named product. An accusation is not a dated withdrawal event. |
| Anthropic suspending Belo’s Claude accounts (April 2026) | An Argentine startup’s accounts suspended, reported as a false positive and reversed within roughly 15 hours. | An end-customer account suspension, not a downstream tool reselling model access — and a quickly reversed moderation error, not a withdrawal. |
| Microsoft reducing OpenAI/Anthropic share inside Copilot (2026) | The buyer shifting its own product toward in-house MAI models. | Wrong direction. A downstream buyer choosing to rely less on a lab is not a lab withdrawing access from a tool. |
| Google restricting unrestricted Gemini API keys (June 2026) | A platform-wide security and billing-risk policy change applied to an entire class of API keys. | Not targeted at a named tool; no named affected company found in reporting. |
| Meta enforcing the Llama 700M-MAU license gate | The license clause is real and quoted in the terms table below; no dated primary or first-party report of Meta invoking it against a named company was found. | A clause existing is not an enforcement event. “Not found” is also not proof it has never happened — the claim stops at what this search surfaced. |
| xAI cutting off a named Grok integrator | Isolated developer-forum complaints about rate limits and tier gating, naming no company and stating no competitive rationale. | No dated, named, first-party-confirmed event. Forum complaints do not meet the ledger’s bar. |
One neighboring event class is worth flagging because it gets conflated constantly: outages. When GitHub’s August 2026 incident took Copilot down with it, developers lost their coding tool for hours — but no supplier withdrew anything. That failure mode and its dependency chain are covered in our analysis of the GitHub–Copilot outage. Outages end when the incident ends; the rows in this ledger are decisions.
08 — The ClausesWhat the published terms actually say.
Most coverage of the Cursor decision treated “change of control” as standard boilerplate. So we pulled the operative documents — each lab’s currently published commercial terms or license — and quoted the assignment and competitor-use language verbatim. Where a clause was not located in the documents reviewed, the cell says so rather than summarizing something unread. Two structural notes first: Meta’s entry is a model-weights license, not an API terms of service, a different kind of instrument from the other four; and a published document is not the same thing as the custom contract a large customer may actually sign.
| Lab | Document reviewed | Assignment / change of control (verbatim) | Competitor-use restriction (verbatim) |
|---|---|---|---|
| OpenAI | Business Terms — May 2025, effective May 1, 2025 | §16.7: “This Agreement cannot be assigned other than as permitted under this Section 16.7 (Assignment). OpenAI may assign this Agreement to an Affiliate without notice or Customer consent. Either Party may assign this Agreement to a successor to substantially all the respective party’s assets or business, provided the assigning party provides at least thirty days prior written notice of the assignment.” Note: the phrase “change of control” does not appear. | §3.3(e): Customer will not, “except for a Permitted Exception, use Output to develop artificial intelligence models that compete with OpenAI’s products and services.” The Permitted Exception is a defined term elsewhere in the agreement; we do not characterize its scope here. |
| Anthropic | Commercial Terms of Service (current version; no effective date stamped on the page) | §M.4: “Neither party may assign its rights or delegate its obligations under these Terms without the other party’s prior written consent, except that Anthropic may assign its rights and delegate its obligations to an affiliate or as part of a sale of all or substantially all its business.” No explicit “change of control” phrase. | §D.4: Customer may not “(a) access the Services to build a competing product or service, including to train competing AI models or resell the Services except as expressly approved by Anthropic; (b) reverse engineer or duplicate the Services; or (c) support any third party’s attempt at any of the conduct restricted in this sentence.” This is the clause invoked against OpenAI in July 2025. |
| Gemini API Additional Terms + Google APIs Terms of Service (last modified Nov 9, 2021) | Not located in the documents reviewed. | Gemini API Additional Terms: “You may not use the Services to develop models that compete with the Services (e.g., Gemini API or Google AI Studio).” | |
| xAI / SpaceXAI | Terms of Service — Enterprise | §13.10 in the version reviewed: “Neither Party may assign this Agreement or any of its rights or obligations hereunder without the advance written consent of the other Party, except that either Party may assign this Agreement and all of its rights and obligations hereunder without such consent to (a) an Affiliate; or (b) a successor entity in connection with a merger, reorganization, acquisition or other transfer of all or substantially all of such Party’s assets or voting securities.” | No equivalent competing-product clause located. The terms do restrict using Output “to train any foundation models, large language models, or other artificial intelligence systems except as may be expressly permitted in an Order Form” — a training restriction, not a resale or competing-product clause. |
| Meta (Llama) | Llama 3.1 Community License — a model-weights license, not an API terms of service | §2 (Additional Commercial Terms): “If, on the Llama 3.1 version release date, the monthly active users of the products or services made available by or for Licensee, or Licensee’s affiliates, is greater than 700 million monthly active users in the preceding calendar month, you must request a license from Meta, which Meta may grant to you in its sole discretion…” — a de facto gate on the largest competitors rather than an assignment clause. No dated enforcement event against a named company was found. | No separate explicit competing-model prohibition located beyond the MAU gate. |
Three things fall out of reading the actual text. First, the two labs that have acted most — OpenAI and Anthropic — both key assignment to a “successor to substantially all” assets or business, not to “change of control”; that phrase exists, on the public record, only in OpenAI’s description of its custom Cursor contract. Second, competitor-use restrictions vary more than the coverage implies: OpenAI and Google restrict competing-model development, Anthropic adds an explicit resale bar, xAI’s enterprise terms carry a training restriction instead, and Meta’s gate is a user threshold on a weights license. Third, an empty cell is information: no explicit assignment clause was located in the Google documents reviewed, and inferring one would be exactly the kind of summarizing this table exists to avoid.
09 — ImplicationsTreat model supply as vendor risk.
The four rows do not line up into a single direction of travel — each instance used a different lever than the one before it. One row, Cursor in August 2026, was triggered by a completed ownership change; the other three were not, so treat that as one documented case rather than an established pattern. The notice you get is whatever the paper says: in these instances, from under five days (vendor-stated) to 76 days (a stated contract maximum).
Looking forward, the reasonable projection is not that cutoffs become common — four dated instances in fifteen months is a low base rate — but that the exposure concentrates where relationships are custom and ownership is in motion. If your coding tool is owned by, or being acquired by, a company that competes with its model supplier, the Cursor row is now the template for how that ends: a blog post, a notice period, and a date. Plan for the date, not the blog post.
Put model supply in your vendor-risk review
Who owns your tool, who supplies its models, and do those two compete? Our 50-point vendor assessment template has a section for exactly this dependency chain.
Keep your workflow harness-portable
Skills, prompts, and configs that move between Claude Code, Codex, and Cursor turn a supply cutoff from a migration project into a settings change.
Know which credential path you are on
Subscription OAuth integrations run on consumer terms a lab can technically enforce overnight; API-key integrations run on commercial terms with published language. The January 2026 row only hit the first group.
Ask about assignment clauses, not just SLAs
If your vendor is acquired, the assignment and change-of-control language in its supplier contracts decides what happens to the product you depend on. The published terms are the floor, not the deal.
The practical toolkit already exists. Use the 50-point AI vendor risk assessment to score the relationship before it becomes a ledger row, and the cross-harness skill portability analysis to measure how movable your setup actually is. The procurement framing — why enterprise buyers should treat frontier labs as strategic suppliers rather than utilities — is developed in our enterprise vendor-risk read of the frontier labs. And if you want a second set of senior eyes on your own AI supply chain — which tools, which models, which contracts, which fallbacks — that is the kind of dependency mapping our AI transformation engagements start with.
10 — ConclusionA ledger is only useful if it stays honest.
Four instances, four levers, and clauses worth reading before you need them.
The dated instances we could confirm tell a tighter story than the headlines did. Anthropic limited Windsurf’s direct access, revoked OpenAI’s API access with a benchmarking exception, and technically blocked subscription OAuth tokens while leaving API keys alone. OpenAI has notified intent to wind down Cursor’s access, with a proposed shutoff date. Four verbs, four mechanisms — and one row that is a peer-lab dispute, not a tool losing its supply.
The clause table is the part to bookmark. The published terms of the labs that acted key assignment to “successor to substantially all” language, not to “change of control” — that phrase lives only in OpenAI’s description of a custom contract. Which means the document governing your own tool’s model supply may contain levers the public terms do not show. Read what you signed; ask your vendor what they signed.
We will add rows as dated, confirmable instances emerge, and reject candidates in public when they do not qualify. If the fifteen months covered here are a guide, the next row will not look like the last one — each instance so far has used a different lever. The constant is the direction of the asymmetry: the lab holds the supply, the tool holds the notice period, and the users hold whatever plan they made in advance.