Coder's Agent Relay Brings Cursor's Cloud Agents Behind the Firewall: Self-Hosted Execution for Regulated AI Coding
Coder and SpaceXAI launch Agent Relay, a self-hosted execution layer that runs Cursor Cloud Agents on customer infrastructure — opening regulated enterprises to agentic coding while Cursor keeps the agent loop.
On September 2, 2026, Coder announced Agent Relay, a self-hosted execution environment for cloud coding agents, with SpaceXAI — the parent of Cursor — as its launch partner. The premise is simple and aimed squarely at the most security-conscious organizations on earth: banks, defense agencies, and government institutions can now run Cursor’s cloud agents entirely inside their own infrastructure, while Cursor continues to operate the agent loop, including inference and planning.
The product is currently in private preview with design partners. There is no public pricing, no general availability date, and no named customers in the announcement — but the architectural move it represents deserves attention, because it draws a new boundary line in the debate over where agentic AI should actually run.
What Agent Relay actually does
The split is the key detail. In a standard cloud-agent deployment, the agent’s entire life — planning, tool calls, file edits, command execution — happens on the vendor’s compute. With Agent Relay, each Coder workspace can start a Cursor worker that opens an outbound connection back to Cursor. The model-side work (inference, planning, reasoning) stays with Cursor; the tool-side work (reading code, running builds, touching secrets and internal services) executes inside a Coder workspace running on the customer’s cloud, VPC, or on-premises hardware.
Developers keep the exact Cursor experience they already know across desktop, web, and mobile. Platform teams provision and scale the workspaces the same way they already manage developer environments. Nothing about the product surface changes — only where the sensitive execution happens.
Coder frames the result as an “AI operating layer” with five enforcement properties: data stays inside the boundary; every task sees only what it was granted; only approved models run; every action leaves a record; and spend is capped before it accumulates. It is a compliance pitch expressed as architecture.
Why the deployment model was the blocker
Coder’s diagnosis of the enterprise agentic-coding gap is blunt: enterprises never rejected AI agents — they rejected the deployment model. Developers inside banks and defense agencies want the same tools everyone else has. What kept those tools out was everything that comes after the pilot: where the code runs, who has access to it, what the agent can reach, and what audit trail exists afterward.
Those are infrastructure questions, not model questions. Source code in these environments requires controlled access. Execution environments need governance that prevents data exfiltration. Every action must be auditable. Vendor-hosted tools could satisfy none of those requirements, which meant the organizations with the most to gain from agentic coding were the last ones able to deploy it.
The size of the gap is quantified by Gartner’s projection that 80% of enterprise software engineers will need to upskill for generative AI by 2027. In regulated sectors, security and compliance review — not developer appetite — decides which tools ever reach a developer’s machine. Agent Relay is an attempt to flip that review from a veto into a checklist.
Architecture over trust
Three design choices stand out in how Coder describes the system.
Your perimeter, your rules. Workspaces run on the customer’s infrastructure, and network egress policy is set once by the platform team and enforced uniformly across every workspace — human developer or agent. Code never leaves.
Boundaries by architecture, not by trust. Agent environments are sandboxed, ephemeral, and scoped to a single task. The explicit goal is that a prompt injection pushing an agent toward unauthorized resources gets blocked at the environment layer, not left to the model’s goodwill to refuse. That is a meaningful position: it treats the model as a potentially compromised component rather than a trusted actor.
A complete record. Every run produces a log of what the agent accessed, executed, changed, and was blocked from doing — so compliance reporting for any time window doesn’t have to be reconstructed by hand after the fact.
“Enterprises never rejected AI agents. They rejected the deployment model,” said Rob Whiteley, CEO of Coder. “What has kept this work out of production is everything that comes after the pilot: where the code runs, who has access, what the agent can reach, and what record exists afterward. Those are infrastructure questions, and Coder was built to answer them. Cursor builds a coding experience developers love. We give it the ground to run on inside a bank, an agency, or a defense program.”
Toni Adams, Senior Director of Partnerships at SpaceXAI, framed the partnership from the Cursor side: “Engineering teams want to build with Cursor. Enterprise security policies require that sensitive information not leave its own infrastructure. Coder provides those teams a path to run Cursor inside environments they fully control.”
The DORA wrinkle
Here the story gets genuinely interesting, because European regulation draws a harder line than the marketing does. Under the EU’s Digital Operational Resilience Act (DORA), which has applied since January 17, 2025, a financial entity’s obligations attach to the arrangement with a provider — not to where the code executes.
Because Cursor still runs inference and planning, it remains an ICT third-party provider under DORA no matter where the tool calls happen. Article 30 requires contracts to spell out processing and storage locations, audit rights for the bank and its regulator, subcontracting conditions, and data return and deletion on exit. Article 28 requires a register linking every provider, service, criticality rating, and data location, available to supervisors on request. Critical functions additionally need a tested exit plan covering migration feasibility, notice periods, and transition assistance.
As TNW points out, this is the awkward part of the pitch: self-hosting the execution layer answers the data-residency and audit objections, but the paperwork survives it. The recent history makes the point concrete — OpenAI ended model supply to Cursor after the SpaceXAI acquisition, and documenting exactly that kind of dependency is what Article 30 exists for. None of this makes self-hosting worthless: keeping source code and secrets on bank-controlled machines answers a real objection, and the run-level audit log is a genuine compliance artifact. But it means Agent Relay solves the infrastructure half of regulated agentic coding, not the vendor-risk half.
Context: the consolidation endgame
Agent Relay also lands mid-consolidation. SpaceXAI completed its takeover of Cursor earlier this year, a deal that reshaped the AI coding landscape — Cursor had reached a $29.3 billion valuation and surpassed $3 billion in ARR before the acquisition, and OpenAI’s subsequent model cutoff forced a rapid re-architecture of its model supply. Cursor had shipped its own self-hosted cloud agents option in March 2026; Agent Relay is the enterprise-grade, governance-wrapped version of that idea, delivered through a partner whose entire business is self-hosted development infrastructure.
Coder says SpaceXAI is only the first of several partnerships planned around the same principle: the industry’s best AI coding tools should run inside any organization, on any infrastructure, without the organization giving up control. The integration is designed to extend self-hosted execution to more agent providers over time.
The historical analogy Coder draws is deliberate: when cloud moved infrastructure out of the building, companies stood up platform teams to govern it. AI is forcing the same mandate — with a twist that much of the work is now coming back inside the organization’s own walls.
What to watch
Three questions will decide whether Agent Relay becomes the standard deployment pattern for regulated agentic coding or remains a niche compliance artifact. First, whether the private preview converts to GA with pricing that platform teams can defend. Second, whether the “architecture over trust” claim survives contact with real red teams — ephemeral single-task sandboxes blocking prompt injection at the environment layer is the right design, but the proof will be in adversarial testing. Third, whether Cursor’s continued control of inference satisfies DORA supervisors in practice, or whether pressure builds for a fully air-gapped option. Coder says air-gapped deployment is available where no external access is acceptable — which, if it includes the agent loop, would be the stronger regulatory answer entirely.
For now, the launch marks a real shift: the agentic-coding wars are no longer just about which model writes the best code, but about who gets to control the ground it runs on.
Sources
- [1] https://coder.com/blog/agent-relay-spacexai-launch-partner-cursor-cloud-agents
- [2] https://thenextweb.com/news/coder-agent-relay-cursor-cloud-agents-self-hosted-dora-article-30
- [3] https://cursor.com/blog/self-hosted-cloud-agents
- [4] https://coder.com/blog/introducing-agent-relay-cloud-hosted-agents-self-hosted-execution