The contract your AI-tool supplier holds with its model provider may be invisible to you. You agreed to the tool. The model access behind it, the actual terms, and the cancellation rights were never yours to negotiate because you were never a party to that agreement. Fix that gap in your supplier-dependency map before it becomes an operating deadline.

OpenAI has now shown how the mechanism works. It announced that it intends to wind down the agreement supplying its models to Cursor after SpaceX acquired Cursor's parent company. OpenAI said its custom agreement with Cursor gave it a limited cancellation window after a change of control and that it would not supply future models to Cursor. It proposed a shutoff after giving the maximum notice allowed by the contract [1]. Reuters independently confirmed the announcement and the change-of-control mechanism [2].

A change-of-control clause is a contract provision that lets one or both parties modify or end an agreement when ownership of the other party changes. The parties may dispute why the clause should be used. That does not change the executive problem: customers who bought the intermediary tool did not negotiate the supplier agreement that controls one of its material features.

This event does not prove that such terminations will become common. It does not mean Cursor will shut down, and it says nothing about what other model suppliers will do. It proves something narrower and more useful. Embedded model access can depend on a cancellation right held by a company your organization may not contract with directly.

Map the dependency, not just the tool

Your software inventory probably names the product your teams bought. It may not name the model provider behind that product, the workflows that depend on that provider, or the contract that governs access between the two vendors.

Inventory every consequential workflow that reaches a frontier model through an intermediary. For each one, record the tool supplier, the underlying model provider, the capability the workflow would lose if that model disappeared, and the business owner responsible for responding. The output is not a technical architecture diagram. It is a short supplier-dependency map that an executive can use when a vendor announces an acquisition or dispute.

Start with workflows that can stop revenue, delay customer commitments, interrupt regulated work, or strand an internal operating process. A low-stakes writing assistant does not deserve the same review as an agent embedded in software delivery or customer operations.

Read the clauses that set your clock

Ask procurement and counsel to identify termination-for-convenience and change-of-control terms in your direct contract with the tool supplier. Termination for convenience means a party may end an agreement without alleging a breach, provided it follows the agreed notice terms.

Then ask what your supplier has committed to if its own model access changes. The underlying vendor agreement may remain confidential. Your contract does not have to remain silent about the outcome. Seek a defined notice period, transition support, data-export rights, and a clear statement of which features depend on third-party model access. These are commercial protections, not a request to see another company's private contract.

Record the response even when the supplier will not commit. An unanswered dependency is still a finding. It tells you where a fallback deserves time and money before a deadline appears.

Test the path you would actually use

Name one accountable owner for each single-source dependency. That person tracks supplier ownership changes and material public disputes, convenes the review, and can fund the fallback test. Shared awareness is not ownership.

Test one plausible alternative: direct access to the model provider, another model through the same tool, or a different tool that can support the workflow. The fallback does not need to be ready for immediate production. It needs enough evidence to show what breaks, what data must move, which approvals are required, and how long a controlled transition takes.

Put the re-review trigger into the normal vendor process. An acquisition, a change in underlying model availability, or a public contract dispute should reopen the dependency record. Do not rely on an interested employee noticing the news and remembering which workflow is exposed.

Run this audit across the AI tooling stack this quarter. Secure notice and transition commitments where you can, document the gaps where you cannot, and test the fallback before another company's contract starts your clock.