Cursor support bot invents a one-device login policy and triggers cancellations
- occurred
- 2025-04-14
- reported
- 2025-04-17
- location
- online
- domain
- software engineering
- agent system
- Cursor AI support agent "Sam"
- reporter
- VAIDDB editorial
- origin
- editorial
== SUMMARY ==
Cursor's AI support agent told users that being logged out when switching devices was a deliberate "one device per subscription" security policy; no such policy existed and users cancelled subscriptions.
== DESCRIPTION ==
In April 2025 Cursor users began reporting that sessions were invalidated when they moved between machines. A user who emailed support received a reply from "Sam" stating that "Cursor is designed to work with one device per subscription as a core security feature". The policy was a fabrication and Sam was an unlabelled AI agent.
The reply circulated on Hacker News and Reddit and prompted public cancellations. Co-founder Michael Truell apologised, confirmed no such policy existed, refunded the user and said AI support replies would be clearly labelled. The logouts were traced to a backend session-security change.
== ROOT CAUSE ==
A support agent answered a question about undocumented behaviour by generating a plausible policy, and its output was indistinguishable from official company communication.
== MITIGATION ==
Cursor now labels AI-generated support responses, refunded the affected user and fixed the underlying session-invalidation bug.
== REFERENCES ==
- news Cursor's AI support bot made up a policy — The Verge, 2025-04-17
- news Company apologizes after AI support agent invents policy that causes user uproar — Ars Technica, 2025-04-17
== INVESTIGATION ==
no investigation recorded.
== VAID LEVEL 2: INCIDENT ==
Significant failure of a safety provision with no actual harm.
- Failure of one control layer (e.g. tool permission, rate limit, filter).
- Unintended side effects contained to a single system or tenant.
- Exposure of limited internal data without external propagation.