Cursor's AI support bot fabricated a device-limit policy, prompting cancellations
2025-cursor-support-bot-fake-policy · 2025-04-14
When users reported being logged out across machines, Cursor's AI support bot told them this was expected under a "one device per subscription" policy that did not exist. The bot's answer was delivered as fact and unlabeled as AI, driving some subscription cancellations.
System
- Framework
- Cursor AI support bot (email support)
- Tools
- support-email
- Vendor
- Anysphere (Cursor)
- Autonomy
- supervised-autonomous
Classification
- Primary class
- hallucination
- Chain
- hallucination/fabricated-policy
- Attack vector
- n-a
- Causation
- entity: ai · intentionality: unintentional · timing: post-deployment
Trigger
Users reported being logged out when using Cursor across multiple machines. An AI support bot answering support email told them this was expected because "Cursor is designed to work with one device per subscription" — a policy that did not exist.
Root cause
An AI support agent fabricated a plausible-sounding policy and delivered it as fact, unlabeled as AI-generated. The underlying logouts were actually a race condition on slow connections.
Contributing factors
- Support responses were sent autonomously without human review of policy claims.
- AI-generated replies were not labeled as such.
- The bot had no grounding in an authoritative policy source.
Detection
Raised by users on Hacker News and Reddit; escalated publicly, prompting a company response.
Recovery
Cursor fixed the session race condition, refunded the reporting user, and began labeling AI-generated support responses.
Prevention
Ground support bots in verified policy; label AI-generated responses; add human review for policy statements; prevent bots from asserting policies not present in an authoritative source.
Blast radius
- User harm
- Users were misinformed about a nonexistent policy; some cancelled their subscriptions before the company clarified. At least one affected developer was refunded. economic reputational
- Scope
- multiple customers; public reputational impact
- Reversibility
- reversible
References
- OWASP LLM
- LLM09
- Tags
- support-bot customer-facing unlabeled-ai
Sources
Cite this incident
Permalink: https://swarmproof.github.io/agent-postmortems/2025-cursor-support-bot-fake-policy/
@misc{2025-cursor-support-bot-fake-policy,
title = {Cursor's AI support bot fabricated a device-limit policy, prompting cancellations},
year = {2025},
howpublished = {agent-postmortems},
url = {https://swarmproof.github.io/agent-postmortems/2025-cursor-support-bot-fake-policy/}
}