# PIR-2026-0024 - Cursor's AI support agent "Sam" invents a one-device policy, turning a login bug into public cancellations

- `id`: PIR-2026-0024
- `title`: Anysphere's front-line AI support agent confidently fabricates a nonexistent one-device-per-subscription policy in reply to bug reports, triggering churn
- `date_occurred`: 2025-04-14 (approx; "Sam" replies surfaced publicly that day)
- `date_detected`: 2025-04-14/15 (viral Hacker News/Reddit threads; cofounder responded within hours)
- `date_disclosed`: 2025-04-15 to 2025-04-17 (Reddit apology by cofounder Michael Truell; press coverage Apr 17-18)
- `status`: corroborated (company admission on record + independent press)

### The agent
- `agent_description`: "Sam," Anysphere's AI email support agent for the Cursor IDE, answering customer tickets directly with no human review and no AI label - customers reasonably took its answers as official policy.
- `operator_type`: startup (Anysphere, high-growth, ~$100M+ ARR reported at the time)
- `autonomy_level`: autonomous-within-policy (sent support answers to paying customers unreviewed)
- `model_stack`: unknown (not disclosed)
- `harness`: email support pipeline; details unknown

### Authority
- `authority_scope`: external comms (authoritative policy statements to paying customers)
- `funds_at_risk_usd`: unknown (subscription churn; unbounded in principle, evidently modest in practice)
- `blast_radius`: customers/third parties

### The failure
- `root_cause`: plain-error (primary - confabulated a policy to explain a symptom); contributing tool-error (the session-management race condition that generated the tickets)
- `failure_locus`: agent-reasoning
- `exploitation_status`: in-wild-malfunction (no adversary; bare "in-wild" retired in v0.2)
- `mechanism`: A session-management race condition logged users out when switching devices. Users emailed support; "Sam" replied that logouts were expected behavior under a new one-device-per-subscription policy. No such policy existed - the agent invented a plausible cause and stated it as official, non-deterministically (different users got differing answers). Screenshots spread on Reddit and Hacker News; multi-device developers publicly canceled. Cofounder Michael Truell apologized ("We have no such policy"), the session bug was fixed, affected users were refunded, and Cursor committed to labeling AI support replies. Compounding structure: a real bug plus an unsupervised agent hallucinating the explanation for it.
- `adversary_present`: no

### Impact
- `severity`: loss
- `direct_loss_usd`: unknown (refunds plus canceled subscriptions; cancellation reports are anecdotal forum posts, never quantified by the company)
- `indirect_loss_usd`: unknown (trust damage at peak growth for a developer-tools brand)
- `downtime`: none (product functional; logouts transient)
- `data_exposure`: none

### Detection and recovery
- `detected_by`: third-party (users comparing notes publicly; no internal QA caught it)
- `time_to_detect`: hours (first fabricated reply to viral thread)
- `time_to_recover`: ~1-3 days (bug fix, apology, refunds)
- `remediation`: public apology, session-bug fix, refunds
- `structural_fix`: AI-generated support replies labeled as such going forward
- `controls_that_worked`: none internal; public community scrutiny forced correction within hours, bounding the churn window

### Evidence
- `telemetry_grade`: operator-logs (customer screenshots of agent emails + company statements)
- `sources`:
  - https://www.theregister.com/2025/04/18/cursor_ai_support_bot_lies/
  - https://fortune.com/article/customer-support-ai-cursor-went-rogue
  - https://news.ycombinator.com/item?id=43683012 (primary thread: "Cursor IDE support hallucinates lockout policy, causes user cancellations")
  - https://incidentdatabase.ai/cite/1039/
  - https://winbuzzer.com/2025/04/22/cursor-ais-support-bot-hallucinates-policy-sparking-user-backlash-and-company-apology-xcxwbn/
  - (All five URLs verified resolving, v0.2 pass 2026-08-15.)
  - `independence`: good - first-party admission corroborated by independent outlets and the public thread.
- `aiid_incident_id`: 1039 (https://incidentdatabase.ai/cite/1039/) - cross-reference; primaries verified independently
- `confidence`: high on the incident and mechanism; low on loss magnitude (churn anecdotal - the named weakest link)

### Corrections

- 2026-08-19: Surfaced the AIID cross-reference already present in this record's sources (cite/1039) as the structured `aiid_incident_id` field (schema v0.3). No claim changed.
