Cursor iOS App Brings Remote Control to Cloud Agents: The Governance Surface Every AI Operator Must Configure

Cursor's native iOS app introduces mobile Remote Control for cloud agents, creating a new approval surface that AI operators and routing teams need to govern deliberately.

TheRouter Newsroomvia Cursor
Abstract illustration of a mobile device connected to a cloud agent routing layer

Cursor's iOS app is now in public beta on all paid plans, and the headline feature isn't the mobile UI — it's Remote Control: the ability to direct agents running on your desktop or in cloud VMs entirely from your phone, complete with push notifications, PR review, and merge actions.

For AI engineering teams that route model requests through a gateway, this changes the operational picture in ways that aren't obvious from the launch announcement.

What changed

Cursor for iOS ships three distinct agent-lifecycle modes:

  1. Cloud agents — launch an agent against a repo from scratch in an isolated VM; the agent picks any frontier model you specify and runs until the task is complete or needs input.
  2. Remote Control — your desktop Cursor session receives instructions from the phone app while your machine stays running. A "keep awake" toggle prevents your laptop from sleeping.
  3. Local-to-cloud handoff — move an in-progress local session to a cloud VM to keep it running with the laptop lid closed, and move it back for local testing before merging.

Enterprise admins on Teams and Enterprise plans must explicitly enable Remote Control from the Cursor Dashboard. For everyone else, it is on by default.

Why it matters for AI engineering teams

The approval flow just became async and mobile

Previously, every human-in-the-loop approval for an agent task happened at the desk, in the IDE. With Remote Control, a developer can approve file edits, bash commands, or PR merges from their phone lock screen via Live Activities.

This sounds like a convenience feature. It is also a new attack surface: if a phone is compromised or a push notification is spoofed, an approval that modifies production code can happen without anyone sitting at a terminal. Teams that rely on interactive approval gates need to explicitly decide whether Remote Control is an acceptable approval channel.

Model selection shifts to the mobile session initiator

When a developer launches a cloud agent from the iOS app, they select the model at launch time. If your team uses a gateway to enforce model allowlists — for cost control, compliance, or capability gating — that enforcement must work at the API level, not just in the desktop app.

Cursor supports any frontier model in cloud agents. If you route through a self-hosted or managed AI gateway, verify that your model allowlist policies apply to Cursor's cloud agent API calls, not just to the desktop app's configuration. The mobile app does not inherit the desktop app's per-workspace model settings.

Cost accounting becomes multi-surface

Cloud agent tokens in Cursor are billed per-session through Cursor's own billing. But for teams routing Cursor to their own provider key through a gateway (e.g., using BYOK), token consumption may appear across sessions initiated from desktop, web, and iOS with different session identifiers.

If your billing reconciliation reads user_id or session_id from request headers to attribute costs, test that the mobile-initiated sessions produce the expected attribution fields before your team starts using iOS at scale.

The router/operator angle

Model policy enforcement must be API-level. If your team's AI routing gateway enforces model allowlists, cost caps, or usage quotas, the iOS app is a new origination point for those requests. Policies that rely on desktop IDE context will not transfer. Ensure gateway enforcement is provider-side, not client-side.

Remote Control is an enterprise admin decision. On Teams and Enterprise plans, the Cursor Dashboard exposes a Remote Control toggle per org. Treat this like any other remote-execution permission: document your org's policy on whether mobile approvals are permitted for production-touching agents, and disable it by default if your compliance posture requires in-person review for code changes.

Push notification approval cadence matters for long-running agents. Cloud agents can run for hours. If the agent hits an ambiguous decision and sends a push notification, but the developer is asleep, the agent pauses. If you run time-sensitive agent workflows (e.g., incident remediation), know the default pause behavior before deploying mobile-initiated sessions to production.

Composer 2.5 discount through July 5. Cursor is running a 75% discount on Composer 2.5 runs in the mobile app through July 5, 2026. If your team routes Cursor to a shared model budget, this promotion could spike usage from mobile users exploring the new app.

What to watch

  • Whether Cursor adds per-model approval gating in the mobile app (currently absent).
  • Enterprise audit logging for mobile-initiated sessions — currently the Cursor changelog does not confirm whether Remote Control sessions appear separately in org audit logs.
  • Android release timeline (iOS beta is live; Android not yet announced).
  • How Cursor's cloud agent token billing interacts with BYOK gateway routing once the mobile session originates outside the desktop client environment.

Related resources

For teams managing model routing and governance for Cursor deployments, see:

Help & contact