Models get rented. Harnesses get owned.
The article argues that agentic harnesses — not models — are where durable value accumulates, because every completed task deposits a permission, a workflow, a credential, or a piece of context that compounds and raises switching cost, while frontier models keep depreciating as capability diffuses downward. It traces five already-completed moves (Cursor renting Anthropic's intelligence, Anthropic launching Claude Code, Cursor's harness being stranded, SpaceX acquiring Cursor, SpaceX/Cursor shipping Grok Bot) that assembled a vertically integrated model+harness stack at SpaceX, ironically funded in part by Anthropic's own Colossus compute-rental payments, and names four signals for judging whether that integrated harness actually captures the professional-agent account from Anthropic.
Every figure below is reported as already-settled fact in the source article — the deals were signed, the products shipped, the capital moved. Only the outcome is presented as hypothesis.
Disclosed through SpaceX's IPO filing; potentially running toward 2029.
The scale of Anthropic's compute commitment to a company that now owns a competing harness.
Five already-completed moves the article traces, in order, from Cursor renting Anthropic's intelligence to SpaceX/Cursor shipping Grok Bot on an integrated stack. The article is explicit that the setup is fact and only the outcome — whether the sixth, still-open move actually captures the account — is hypothesis.
Across 2024 and 2025, Cursor became one of the clearest examples of a pure agentic harness. It did not own frontier intelligence. It owned the environment where developers applied that intelligence. Software engineers lived inside Cursor. The product embedded AI directly into the place where code was written, edited, understood, and shipped. But Cursor had no frontier model of its own. The intelligence underneath the experience was rented through APIs. And for the hardest coding problems, developers disproportionately reached for Claude. Cursor therefore served them Claude. The arrangement…
In May 2025, Anthropic moved up the stack. Within days, it released coding-focused models, changed the API economics supporting its largest customer, and launched Claude Code: Anthropic's own developer harness running Claude directly inside the terminal, with no Cursor in the middle. Strategically, the logic was straightforward. If the harness is where customer value accumulates, leaving that layer permanently to an intermediary makes little sense. Anthropic had the model. Now it wanted the account. Claude Code quickly became one of the strongest products in developer tooling.
A harness without its own model faces a specific problem once its model supplier launches a competing harness. Its strategic dependency becomes visible. At that point, there are essentially two exits. The first is differentiation: build a harness so specialized and valuable that the model provider cannot easily replicate it. The second is integration: attach the harness to a company that owns a model, removing the dependency altogether. Cursor's direction began appearing in its talent flows before it appeared in corporate structure. Several senior product engineers moved to xAI.
The natural strategic home for a stranded harness is a company that already owns the missing layers. By 2026, SpaceX fit that profile. Musk had folded xAI into SpaceX, creating what was effectively a vertically integrated AI infrastructure company with access to a frontier model, massive compute infrastructure, capital, distribution, and public-market currency. The relationship with Cursor developed in stages. In April 2026, SpaceX signed Cursor to provide the computer environment where its agents would operate. That was the technology relationship. Then came ownership. In June, shortly after…
On August 11, 2026, SpaceX and Cursor launched Grok Bot. The important thing is what the product represents. This is not simply another chatbot interface. Each agent runs inside its own persistent cloud computer with access to a browser, file system, and terminal. You create an agent, assign a role, connect the relevant tools, and delegate work: inbox management, outreach, recruiting, bug fixing, research, operations. The agent can authenticate into software, perform tasks, retain context, and return when human approval is required. Multiple agents can run simultaneously. One can even operate…
In May 2026, Anthropic signed an agreement to rent the full capacity of SpaceX's Colossus data-center cluster (later extended to a second site) because demand for Claude was growing faster than available infrastructure. The Colossus infrastructure was originally built by xAI for xAI's own ambitions; xAI is now inside SpaceX. So the company receiving Anthropic's compute payments is also the company that subsequently acquired Cursor and launched a competing agentic platform on top of it — Anthropic is paying billions for infrastructure whose economics partly strengthen the vertically integrated company building a competing model-and-harness stack. Anthropic chose to focus its ownership around the model and the application layer; SpaceX chose to integrate compute, model, harness, and distribution. When those architectures collide, the renter can end up funding the integrator.
SpaceX data-center cluster (more than 300 megawatts, more than 220,000 GPUs, near Memphis) originally built by xAI, now rented in full by Anthropic under a roughly $1.25 billion/month, ~$45 billion-scale agreement (subject to mutual 90-day cancellation) disclosed through SpaceX's IPO filing.
SpaceX increasingly operates across almost the entire chain: energy and data-center infrastructure at the physical layer, hyperscaler-scale compute at Layer 5, a frontier model at Layer 6, the developer environment at Layer 6.5, the agentic harness at Layer 7, and distribution through Starlink and X. Anthropic owns the frontier model and important harnesses, but rents significant portions of the infrastructure underneath them — from a company increasingly positioned to compete one layer above. The key difference is not the number of layers owned; it is the ability to coordinate them.
Nothing about the outcome is predetermined: the stack has been assembled, but market capture still has to happen. Four signals matter most.
Watch where workloads actually go. If Grok Bot's hidden routing layer begins shifting meaningful developer activity away from external frontier models toward Grok, the integration thesis is working. Cursor's existing user base is probably the earliest place that shift would become visible.
Claude Code does not need to own every model interaction. It needs to remain indispensable enough that users do not move their workflows elsewhere. If persistent cloud agents become the new baseline, the question becomes whether Anthropic can reproduce that architecture fast enough without weakening its existing advantage.
Anthropic's SpaceX agreement includes a 90-day cancellation mechanism. If Anthropic secures equivalent compute from infrastructure providers that are not simultaneously competitors, the financial loop described above weakens substantially.
Agentic harnesses require something more valuable than benchmark leadership: permission. They hold credentials, access systems, touch corporate data, and execute actions. Enterprises must trust the operator behind the harness. Vertical integration can buy infrastructure, models, distribution, and software. It cannot automatically buy institutional trust.
A distillation of Kingsley Uyi Idehen's perspective, applied here to argue that the article's own thesis — harnesses compound value that models cannot — is demonstrated most cleanly by a harness that never rents its accumulated context to a single vendor's runtime in the first place: agent-rdf-memory, OpenLink's RDF-based agent memory harness (arm:this), already reused across Claude Code, Codex, OpenCode, and Grok CLI sessions in this same repository, and already scored layer-by-layer in a prior companion document (stack:).
The article's mental model 'Models Get Rented, Harnesses Get Owned' implies a harness should be defensible precisely because its accumulated deposits do not depend on any one model's continued availability. Yet every harness the article examines — Cursor, Claude Code, Grok Bot — is still owned by exactly one vendor's stack, meaning a supplier-side decision (Anthropic's May 2025 move, SpaceX's June 2026 acquisition) can strand or re-arm the whole harness overnight. agent-rdf-memory is architected against that exact failure mode: it is a Turtle-based memory and behavioral-contract harness retrieved by a mandatory session-start protocol that has already been run, unmodified, underneath Claude Code (Anthropic), Codex (OpenAI), OpenCode (multiple model backends), and Grok CLI (xAI) — the same four vendor families the article maps onto Layers 6 and 6.5 of the AI stack. A prior companion document already scored agent-rdf-memory layer-by-layer against an 11-layer 'Agent Engineering Stack'; 8 of those layers (stack:layerTools, stack:layerPolicy, stack:layerMemory, stack:layerSkills, stack:layerObservability, stack:layerIdentity, stack:layerContext, stack:layerOrchestration) map directly onto this article's own 8-term harness definition, reused below rather than re-described.
The article defines a harness as 'integrations, permissions, memory, workflows, task history, credentials, context, and orchestration.' All eight terms map onto stack layers already scored (Fully Implemented or Partially Covered) in agent-rdf-memory-stack-alignment-inline-links — reused here by IRI via the stack: prefix rather than re-described.
scripts/ and load_memory.py — data-access tooling; the broader tool/API surface (curl, MCP) belongs to the host harness rather than this repo.
preferences.ttl — a queryable behavioral contract of 200+ HowToSteps, many implemented as hard blocking gates that fail closed, with a public/private split enforcing the data boundary for credentials and personal paths.
This IS the repo's core purpose: episodic memory in sessions/, semantic memory in entities/, and long-term behavioral memory in preferences.ttl, indexed by index.ttl.
howto/ is a skill library: 40+ reusable, independently-specified behavioral modules, each documented with I/O contracts and gates, reused by whichever model runtime is active.
sessions/*.ttl is the trace log — a durable, dated, model-tagged, environment-tagged per-session record, indexed by index.ttl — so task history persists across a change of model or agent environment.
core.ttl carries both agent identity (a schema:SoftwareApplication template filled at runtime) and user identity (schema:Person with owl:sameAs across platforms), plus dedicated WebID/verification and credential-location rules.
Ontology-routed context selection: schema:PromptIntent and schema:RetrievalPolicy classes in ontology.ttl select which topics, howtos, and sessions get loaded into the live context window, so any session — regardless of which model is running it — resolves the same entity instead of re-deriving one.
The mandatory 9-step retrieval protocol IS the orchestration plan: list the folder, read core.ttl, read preferences.ttl, read the private overlay if present, read ontology.ttl, read index.ttl, classify prompt intent, SPARQL-route to context, and fall back to direct file reads if the endpoint is unavailable — a router the operator controls, not one hidden inside a single vendor's product.
Interactive graph visualization derived from the companion RDF. Click nodes to resolve, drag to explore. Graph data embedded from companion RDF at generation time.
Query this knowledge graph on URIBurner. The editor opens on the canonical SAMPLE entity-type summary (DAV named graph). Pick a recipe, edit freely, then run live or copy.
Watch whether Grok Bot's hidden routing layer begins shifting meaningful developer activity away from external frontier models toward Grok — Cursor's existing user base is the earliest place that shift would become visible.
Watch whether Anthropic can reproduce a persistent-cloud-agent architecture fast enough to stay indispensable, without needing to own every model interaction Claude Code touches.
Watch whether Anthropic secures equivalent compute from infrastructure providers that are not simultaneously competitors — doing so would substantially weaken the Colossus financial loop.
Watch whether enterprises extend institutional trust — credential access, system access, corporate-data access, action-execution rights — to the vertically integrated operator, since that trust cannot be bought merely by acquiring infrastructure, models, distribution, and software.
The layer surrounding the model — integrations, permissions, memory, workflows, task history, credentials, context, and orchestration — that turns raw intelligence into a worker that can hold credentials, remember preferences, move across applications, and execute tasks.
Frontier models have brutal, deflationary economics — cheaper models keep becoming good enough, so owning a model means spending billions just to preserve relative advantage. Harnesses move the opposite way: every completed task deposits a permission, workflow, credential, or piece of context that compounds and raises switching cost, so the intelligence layer can be swapped far more easily than the accumulated operating context around it.
(1) Cursor became a pure harness renting Anthropic's intelligence; (2) Anthropic launched Claude Code in May 2025, reaching up to take the harness for itself; (3) Cursor's harness became strategically stranded once its own supplier launched a competing harness; (4) SpaceX supplied first the model, via folding xAI in, then the balance sheet, via a reported $60 billion acquisition of Cursor's parent in June 2026; (5) SpaceX and Cursor shipped Grok Bot on August 11, 2026.
Cursor owned the developer environment but had no frontier model of its own; for the hardest coding problems developers disproportionately reached for Claude, so Cursor served them Claude, becoming Anthropic's single largest API customer while owning the customer relationship Anthropic ultimately wanted.
If the harness is where customer value accumulates, leaving that layer permanently to an intermediary made little sense once Anthropic had the model — Claude Code let Anthropic capture the account directly, at the cost of turning Cursor, its largest customer, into a direct competitor.
A harness without its own model becomes strategically exposed the moment its model supplier launches a competing harness. Cursor's only two exits were differentiating beyond Anthropic's reach or integrating with a company that owns a model — talent flows toward xAI signaled which exit it was taking before any acquisition was announced.
Musk had folded xAI into SpaceX, giving it a frontier model (Grok), massive compute, capital, and distribution — the three assets Cursor lacked. SpaceX first signed Cursor to supply its agents' computer environment (April 2026), then acquired Cursor's parent company outright for a reported $60 billion in an all-stock deal shortly after SpaceX's IPO (June 2026).
A user creates an agent, assigns it a role, connects tools, and delegates work — inbox management, outreach, recruiting, bug fixing, research, operations. Each agent runs in its own persistent cloud computer with a browser, file system, and terminal, can authenticate into software, retain context, run alongside other agents, and return only when human approval is required; one agent can act as a 'chief of staff' coordinating the rest.
Anthropic rents the full capacity of SpaceX's Colossus data-center cluster (~300+ MW, 220,000+ GPUs) for roughly $1.25 billion/month, ~$45 billion in total contract value. Colossus was originally built by xAI, which is now part of SpaceX — the same company that subsequently acquired Cursor and shipped the competing Grok Bot harness. Anthropic is effectively helping fund the infrastructure behind its own rival's integrated stack.
Routing share (whether Grok Bot's hidden router shifts workloads toward Grok), harness stickiness (whether Claude Code remains indispensable enough that users don't move elsewhere), the compute relationship (whether Anthropic can replace the SpaceX agreement's 90-day-cancellable capacity with non-competitor infrastructure), and enterprise trust (whether enterprises extend credential and execution trust to the vertically integrated operator).
Once the harness selects the underlying model automatically rather than the user choosing it, model choice stops being a user decision and becomes an infrastructure decision — whoever controls the router can redirect demand across models without the customer consciously switching.
A harness dependent on a single model supplier becomes strategically exposed the moment that supplier launches a competing harness of its own — its only options are to differentiate beyond the supplier's reach, or integrate with a different company that owns a model, removing the dependency.
The article is explicit that only the setup is fact; the migration is hypothesis. Enterprise trust in particular cannot be bought merely by acquiring infrastructure, models, distribution, and software — agentic harnesses hold credentials and execute actions, and that institutional trust has to be earned separately from any deal.
Cursor, Claude Code, and Grok Bot are each owned outright by one vendor's stack, so a supplier-side decision by that vendor can strand or re-arm the whole harness. A platform-agnostic harness keeps its accumulated deposits — memory, workflows, credentials/output-routing, context, task history, orchestration — addressable by any model runtime, so switching the rented model underneath does not strand the owned context above it.
agent-rdf-memory (arm:this) is a Turtle-based memory and behavioral-contract harness — core.ttl, preferences.ttl, ontology.ttl, howto/, entities/, sessions/ — retrieved by the same mandatory session-start protocol underneath Claude Code, Codex, OpenCode, and Grok CLI, the same vendor families the article maps onto Layers 6 and 6.5 of the AI stack. Its deposits compound in the repository, not inside any one vendor's proprietary runtime, so a change of rented model does not strand the accumulated context.
The layer surrounding the model — integrations, permissions, memory, workflows, task history, credentials, context, and orchestration — that turns intelligence into a worker capable of holding credentials, remembering preferences, moving across applications, and executing tasks. Not the model itself.
A company owning and coordinating multiple layers of the AI stack (compute, model, harness, distribution) rather than renting some of them from suppliers — the article's central description of SpaceX's strategy versus Anthropic's rent-compute/own-model-and-application approach.
Intelligence becomes substitutable faster than context, permissions, workflows, and relationships do. The apparently thin wrapper can become the actual value-capture layer because it owns the accumulated operating context.
Model companies spend billions to preserve a moving frontier while capability continuously diffuses downward. Harnesses move in the opposite direction: every completed task adds context, memory, integration, and switching cost. One layer depreciates competitively. The other compounds.
A harness dependent on a model supplier becomes strategically exposed the moment that supplier launches a competing harness. Its options narrow: differentiate beyond the supplier's reach or integrate with a model owner that removes the dependency.
Vertical integration can be strategically correct and still destabilize the ecosystem around you. By capturing more value internally, you can convert customers, partners, and distributors into motivated competitors.
Competitive strategy is partly the choice of which layers you are comfortable renting and which layers you cannot afford to let a rival integrate. A layer that looks commoditized in isolation can become strategically critical once bundled into an end-to-end system.
In vertically entangled markets, supplier and competitor can become the same entity. The renter optimizes for access. The integrator optimizes for control. Eventually, the renter's cost structure can strengthen the economics of the rival stack.
Once the harness selects the model automatically, model choice stops being a user decision and becomes an infrastructure decision. Control the router and you can redirect demand across models without asking the customer to consciously switch.
Power users matter because they hit product ceilings first. When their behavior changes dramatically, it can indicate that a new capability threshold has been crossed. It is not proof of mass adoption, but it is often an early signal of a new workflow becoming economically viable.
An acquisition can transfer technology, distribution, infrastructure, employees, and intellectual property. It cannot instantly transfer the customer's willingness to hand over credentials and autonomous execution rights. In the agentic layer, trust is infrastructure too.