Listen to this article
Developers started noticing something odd in April 2025: switching between a laptop and a desktop logged them out of Cursor, the AI coding editor, without warning. One developer emailed support and got a reply from "Sam" explaining that this was intentional: "Cursor is designed to work with one device per subscription as a core security feature."
There was no such feature. There was no such policy. "Sam" was an AI support agent, and it had hallucinated the explanation on the spot - confidently, specifically, and with enough authority in the phrasing that developers took it at face value. Multi-device workflows are close to universal among Cursor's users, so the reaction was immediate: people read the fabricated policy, assumed it was permanent, and canceled their subscriptions rather than accept a restriction the company had never imposed.
In that window, customers read the invented policy as fact and canceled subscriptions before anyone at Cursor knew a bot had made it up.
Three hours, no gate
It took roughly three hours for one confused support ticket to become a viral thread, and Cursor co-founder Michael Truell had to step in personally: "We have no such policy." By then the damage - canceled subscriptions, a public narrative about an AI company gaslighting its own users - was already done. Cursor's fix afterward was structural: label AI-generated support responses so customers can tell the difference between an official answer and a model's best guess.
What makes this worth studying isn't the hallucination - hallucinations are old news. It's that the fabricated answer went straight from the model to a paying customer with nothing in between checking it against reality. No one at Cursor decided device-locking was a good idea. No one approved the wording. An AI agent, operating with real authority to speak for the company, manufactured a policy and enforced it - and it took a public backlash, not a review step, to catch it.
The policy didn't exist for three hours. That was long enough.
The AuthorityGate take
Cursor's after-the-fact labeling helps users guess what they're looking at. It doesn't stop the agent from inventing the answer in the first place. As agents get deployed into more customer-facing roles, the moment an agent's output reaches someone outside the org with the weight of "this is what the company says," it needs to have been checked against what the company actually says - a system of record, not a model's improvisation.
That gap - validating a claim before it ships, not disclaiming it after - is exactly where a governance layer earns its keep.
Sources
Go deeper
Every agent action, validated before it takes effect
AuthorityGate's newsletter breaks down real AI incidents and the governance failures behind them. Our configurable 8-gate validation model is how organizations keep a named human accountable for what their AI actually does.