The control was a habit
A vendor's claim about its own model that an outsider can check, model choice moving inside a product, and a permission prompt measured at 13.6 per cent.
How we organise
Checking whether a model was trained from scratch
A published pipeline reads the architecture fields and the tokenizer a vendor already ships. Where the shape matches an open-weight base exactly, the authors treat that as strong evidence the architecture was adopted rather than designed. The weights check does not work, so those two files carry the evidence.
We tell a client that a checkable claim left unchecked is a decision. Building on somebody else’s base is legitimate and common, and it prices differently from work a vendor says was its own. It also inherits a dependency the vendor does not control. The check needs nobody’s cooperation.
How we build
How Cursor’s router picks a model for each turn
The choice is learned from production traffic rather than from benchmark scores. Moving on counts as a positive signal and correcting the agent as a negative one. One configuration is reported running above Fable-level satisfaction at 68 per cent lower cost.
Our position is that model choice has stopped being a standard and become a runtime decision somebody else makes. A named model in an architecture document was a crude control, but it was written where anyone could read it. The router probably chooses better, and it is retrained on traffic the buyer cannot see.
How we assure
Anthropic measures the permission prompt
A dangerous command was swapped into one prompt for each of 1,053 paid testers. They caught it 13.6 per cent of the time. The classifier that replaces the prompt blocked the same command 89 per cent of the time. Users approve 97 per cent of prompts and reject 39 per cent of plans.
We judge oversight by the shape of the question put to the person. A prompt arrives mid-work, one command at a time, with no view of what the agent is doing. A plan arrives first and reads as a decision, which is why it gets argued with. Most policy written since 2024 rests on the prompt.