SecondSourceJudgment rebuilt from primary sources
Product & chips · Sep 3, 2026

Cursor now keeps an agent's tool execution entirely inside your own network.

Product moves · This week (published September 2)

From the Sep 3, 2026 daily brief

The biggest enterprise obstacle to agentic coding tools has always been whether source code and secrets leave the company network. Cursor shipped self-hosted machines on September 2: model inference stays in the cloud, and tool execution moves wholly onto the customer's own machines, with code, build outputs and secrets staying internal while the agent issues tool calls locally. It plugs into a customer's existing sandbox infrastructure (eight named, including AWS Lambda, Cloudflare, Modal, Vercel and E2B) and supports shared machine pools for a team plus idle sleep (Cursor changelog, 09-02). The shift is in the method: this solves the data-boundary problem with architecture instead of contract language. Read with item 2 of today's main line, there are two gates keeping agents out of production — failure rate is one, the data boundary is the other, and this is a structural answer to the second. ⚠️ A pure feature announcement, with no adoption figures and no performance figures, so we pass no judgment on how well it works.

Subscribe free — first issue lands tomorrow morning

Just an email address, unsubscribe anytime. This is the only thing we ask of you.

More in this section