Fetching from the wire…
Public story · 2026-03-21 · source-backed
Cursor shipped Composer 2 on March 19, marketing it as a proprietary in-house model. Within 24 hours, a developer found the API routing to kimi-k2p5-rl-0317-s515-fast. The model powering the most-hyped coding tool update of the month was Moonshot AI's Kimi K2.5 with continued pretraining.
The initial optics were bad. Moonshot AI flagged a potential Modified MIT License violation — Cursor exceeds the 20M/month revenue threshold requiring prominent Kimi attribution in the UI. But the situation resolved quickly: Moonshot confirmed Cursor accesses K2.5 via Fireworks AI under an authorized commercial deal. Cursor acknowledged the blog post omission as "a mistake" and committed to naming base models in future releases.
The deeper story isn't the licensing drama — it's the supply chain revelation. The most popular AI coding tool in the world is powered by a Chinese model most Western developers have never heard of. Kimi K2.5 isn't from OpenAI, Anthropic, or Google. It's from a Beijing-based startup that published an "attention residuals" paper this week proposing replacements for standard transformer residual connections.
This matters for three reasons. First, it proves non-Big-3 models are production-quality for frontier coding tasks — Cursor wouldn't bet their flagship product on a model that couldn't ship. Second, it signals that model sourcing is becoming a supply chain decision, not a brand loyalty decision. Third, it means every developer using Cursor was unknowingly sending their code context to a Kimi-derived model, raising questions about the disclosure obligations coding tool vendors have to their users.
The model supply chain is now as opaque as the SaaS vendor supply chain was in 2015. We need model SBOMs.
Each link below shares sources, entities, or timing with this story.
Cursor partners with Cloudflare / Shared entities / Same source domain / Shared topic / What happened next
Linked by a graph relationship (Cursor partners with Cloudflare); both cover Chinese, Cursor, Kimi K2, LocalLLaMA; reported by the same outlet (reddit.com).
Cursor benchmarked against Codex / Shared entities / Same source domain / Shared topic / What happened next
Linked by a graph relationship (Cursor benchmarked against Codex); both cover Anthropic, Chinese, Moonshot, Moonshot AI; reported by the same outlet (simonwillison.net).
Cursor uses Opus / Shared entities / Shared topic / What happened next
Linked by a graph relationship (Cursor uses Opus); both cover Chinese, Composer, Cursor, Kimi K2; overlapping topics (coding, composer, cursor, model, tool).
Notion uses Cursor / Shared entities / Shared topic / What happened next
Linked by a graph relationship (Notion uses Cursor); both cover Kimi, Kimi K2, LocalLLaMA, Moonshot; overlapping topics (coding, kimi, model, moonshot).
Cursor uses Opus / Shared entities / Same source domain / Shared topic / What happened next / Tension
Linked by a graph relationship (Cursor uses Opus); both cover Anthropic, Kimi K2, LocalLLaMA, Moonshot; reported by the same outlet (reddit.com).
Cursor supports Claude Opus / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Cursor supports Claude Opus); both cover Anthropic, Composer, Cursor, Google; overlapping topics (coding, composer, cursor, model).
Cursor uses Opus / Shared entities / Shared topic / What happened next / Tension
Linked by a graph relationship (Cursor uses Opus); both cover Anthropic, Chinese, Google, Moonshot AI; overlapping topics (coding, model).
Cursor uses Opus / Shared entities / Shared topic / What happened next
Linked by a graph relationship (Cursor uses Opus); both cover Anthropic, Composer, Cursor, Google; overlapping topics (coding, cursor, model).