Cursor · Cursor Terms of Service

Auto-Code Execution Risk Assumption

High severity
Share 𝕏 Share in Share 🔒 PDF

What it is

Cursor has a feature that runs AI-generated code automatically without you reviewing it first. If you turn this on, you take on all responsibility for any resulting damage including data loss or security breaches.

Consumer impact (what this means for users)

Enabling auto-code execution means you accept full legal and financial responsibility for any harm caused by AI-generated code running without human review — including system outages, data loss, and security breaches — with no ability to hold Cursor liable.

Cross-platform context

See how other platforms handle Auto-Code Execution Risk Assumption and similar clauses.

Compare across platforms →
Need full compliance memos? See Professional →

Why it matters (compliance & risk perspective)

This clause eliminates Anysphere's liability for potentially catastrophic outcomes — including data loss and security vulnerabilities — that result from automatically executing unreviewed AI-generated code in production or development environments.

View original clause language
The Service may include a feature that automatically executes code Suggestions without manual review or confirmation, and will be clearly labeled accordingly. By enabling this feature, you acknowledge and agree that you are assuming all risks associated with the execution of automatically generated code, including without limitation system outages, software defects, data loss, and security vulnerabilities. YOU ARE SOLELY RESPONSIBLE FOR ANY IMPACT RESULTING FROM USE OF THIS FEATURE, INCLUDING ENSURING APPROPRIATE SAFEGUARDS, TESTING, AND MONITORING ARE IN PLACE.

Institutional analysis (Compliance & legal intelligence)

1. REGULATORY FRAMEWORK: This provision engages general tort liability principles and potentially the EU AI Act (Regulation 2024/1689), which classifies certain automated AI systems as high-risk and imposes obligations on deployers (Articles 26 and 29). For enterprise users, automated code execution without human oversight may conflict with SOC 2 Type II control requirements, ISO 27001 operational controls, and NIST Cybersecurity Framework requirements for change management. If the feature causes a data breach, GDPR Article 33 (72-hour breach notification), CCPA §1798.150 (private right of action for data breach), and state breach notification laws (e.g., NY SHIELD Act, Cal. Civ. Code §1798.82) are engaged. 2.

🔒

Compliance intelligence locked

Regulatory citations, enforcement risk, and due diligence action items.

Watcher $9.99/mo Professional $149/mo

Watcher: regulatory citations. Professional: full compliance memo.

Applicable agencies

  • FTC
    The FTC has jurisdiction over unfair or deceptive practices, including inadequate disclosure of material risks associated with AI features under Section 5 of the FTC Act.
    File a complaint →

Provision details

Document information
Document
Cursor Terms of Service
Entity
Cursor
Document last updated
April 29, 2026
Tracking information
First tracked
April 30, 2026
Last verified
April 30, 2026
Record ID
CA-P-004344
Document ID
CA-D-00453
Evidence Provenance
Source URL
Wayback Machine
SHA-256
43f1d1b81f2bbb689af2a3a9e66bd45d4b0226b8fabfcd5adee69e1049877d90
Verified
✓ Snapshot stored   ✓ Change verified
How to Cite
ConductAtlas Policy Archive
Entity: Cursor | Document: Cursor Terms of Service | Record: CA-P-004344
Captured: 2026-04-30 08:53:33 UTC | SHA-256: 43f1d1b81f2bbb68…
URL: https://conductatlas.com/platform/cursor/cursor-terms-of-service/auto-code-execution-risk-assumption/
Accessed: May 2, 2026
Classification
Severity
High
Categories

Other provisions in this document