Your AI Tool Depends on Someone Else’s Permission
OpenAI reportedly cut Cursor off from its GPT models after SpaceX took the company over. Thousands of businesses use that tool daily, and for them a core capability simply stopped being available. The tool did nothing wrong. Its customers certainly did nothing wrong. A disagreement two levels above them removed something they were relying on, which is a category of risk almost nobody evaluates when they buy software.
The dependency you did not evaluate
When you choose a piece of software you look at the product, the price, the support, and maybe the company's stability. Reasonable list. It has one gap that did not exist five years ago.
Most AI products are not model builders. They are an interface, a workflow, and some genuinely good engineering wrapped around a model that belongs to somebody else. Their right to use that model is a commercial agreement between two companies, neither of which is you, on terms you will never see.
That is your vendor's vendor, and it turns out to be a real point of failure rather than a theoretical one.
Faster than a failure, more permanent than an outage
| Failure type | Warning you get |
|---|---|
| Vendor goes out of business | Months of signals if you are watching |
| Service outage | None, but it comes back |
| Upstream access withdrawn | None, and it may not come back |
The third row is the awkward one. It arrives with the speed of an outage and the permanence of a shutdown, while the vendor stays healthy and keeps billing you. We covered the slower versions in what happens when your vendor gets acquired and what stops when your provider goes down. This is a third shape.
Three questions, one minute
Add these to any AI purchase conversation. They are not confrontational and the answers are genuinely informative.
Whose models do you use? A vendor who will not say is telling you something.
What happens to our service if that access changes? Listen for whether they have considered it at all.
Could you switch providers, how quickly, and would we notice? The best answer is that they already support several, because that means the switch is a configuration change rather than a rebuild.
A vendor with real answers has thought about this and probably built for it. One who finds the question strange has a single point of failure they have never examined, which is now yours as well.
Sort your own tools
You cannot eliminate this exposure, so the work is knowing it. Take your AI tools and put each one in a category: annoying if it disappeared tomorrow, disruptive, or business-stopping.
Most will be annoying, which is fine and requires nothing. For anything in the business-stopping category, know the alternative and have actually run work through it rather than merely bookmarked it. An untested alternative is a sentence in a document, and it fails at the moment you need it.
That is a couple of hours and it is the version of this exercise that fits a small business. The fuller argument for keeping options open is in not marrying one AI model.
Exportable data is your only leverage
One thing to check on every AI tool you use, and it takes five minutes each. Can you get your data out, in a format something else can read?
Not because you plan to leave. Because the ability to leave is the only leverage a small customer has, and it is the difference between switching in a week and being stuck for a year while you rebuild. If the answer is that export produces a file nobody else can use, you have learned something important about the relationship before you needed to know it.
The structural read
A small number of companies build the models almost every AI product depends on. Everyone else rents access on terms that can change, and the businesses buying the products sit two steps removed from that negotiation with no visibility into it.
That is not a reason to avoid AI tools, which would be a strange conclusion given how useful they are. It is a reason to prefer vendors who support more than one model, to keep your data portable, and to know which two or three tools would genuinely hurt. Buying through a layer that abstracts the model, as we described in the AI gateway approach, is one way to make switching a configuration change. Knowing your exposure is the free version, and most businesses have not done that either.
Frequently Asked Questions
What happened?
OpenAI reportedly cut Cursor, a widely used coding tool, off from its GPT models following SpaceX taking over the company. Treat the specifics as reporting on a commercial dispute rather than a settled account. What makes it worth attention is the shape rather than the detail: a tool that thousands of businesses use daily lost a core capability because of a disagreement between two other companies. The tool did nothing wrong. Its customers certainly did nothing wrong. The capability went anyway.
Why does this matter if I do not use that tool?
Because the structure is everywhere. Most AI products you buy are not model builders. They are a useful layer wrapped around somebody else’s model, and their access to that model rests on a commercial agreement you cannot see and are not party to. When you evaluate a vendor you look at their product, their pricing, and their support. You almost never ask whose model is underneath and what happens if that supply is withdrawn, which is the dependency that just failed.
Is this the same as a vendor going out of business?
It is faster and less predictable. A company failing usually gives you signals: funding trouble, staff leaving, support degrading, a slow news cycle you can react to. An upstream access dispute can remove a capability in a day, with no warning, while the vendor is otherwise healthy and still charging you. It is closer to an outage in speed and closer to a shutdown in permanence, which is an awkward combination to plan around and easy to overlook entirely.
What should we actually ask a vendor?
Three questions, and they take a minute. Whose models do you use? What happens to our service if that access changes? And can you switch to another provider, how quickly, and would we notice a difference in quality? A vendor with a real answer has thought about this and probably supports more than one model already. A vendor who finds the question odd has a single point of failure they have not examined, which is now your single point of failure too.
What is the practical protection?
Mostly it is knowing your exposure rather than eliminating it, because you cannot eliminate it. Sort your AI tools by what happens if one disappears tomorrow: annoying, disruptive, or business-stopping. For anything in the last category, know the alternative and have actually tried it rather than merely identified it. Keep your data exportable, since the ability to leave is the only leverage you have. That is a couple of hours of work, and it is the version of this that fits a small business.
Know your AI dependencies before they surprise you
We help Canadian businesses map upstream model dependencies, ask vendors the right questions, and keep switching costs low.
Related Articles
AI Business Plan: What It Gets Right and Badly Wrong
Your Website May Soon Need a Version for Agents
Open Weights Now Come With a Waiting Period
Ajan leads the ChatGPT.ca team: 200+ custom GPT builds and automation projects for 50+ businesses across 20+ industries. Based in Markham, Ontario. PIPEDA-compliant solutions.