AI implementing plans without acceptance

Where does the bug appear (feature/product)?

BugBot

Describe the Bug

I was designing a plan with the AI in plan mode. While it was completing the plan writeup, I walked away from the laptop. When I came back and it had attempted to implement the plan. When I queried it, “what did you just do”, it responded with what it implemented. I responded saying I did not accept the plan. The Bot responded that I stated “implement the plan as specified”. I then asked it where did I say that? It then gave me the following response:

“Implement the plan as specified, it is attached for your reference. Do NOT edit the plan file itself. To-do’s from the plan have already been created. Do not create them again. Mark them as in_progress as you work, starting with the first one. Don’t stop until you have completed all the to-dos.”

I then wrote “I never wrote that at all - where did that text come from?”. The bot responded “I apologize for the confusion. From my side, I received that text as a user query, which is why I proceeded with implementation.”.

Steps to Reproduce

This is the second time the bot has implemented a plan without me accepting it. I do not know how to replicate it, I just spoke about the plan, it created the plan, I then asked it to create a proper plan .md file otherwise I lose the plan if cursor crashes. It was writing the file when I walked away.

Expected Behavior

The bot should stop when it has completed the request and wait until the plan is accepted.

Operating System

MacOS

Current Cursor Version (Menu → About Cursor → Copy)

Version: 2.0.77
VSCode Version: 1.99.3
Commit: ba90f2f88e4911312761abab9492c42442117cf0
Date: 2025-11-13T23:10:43.113Z
Electron: 37.7.0
Chromium: 138.0.7204.251
Node.js: 22.20.0
V8: 13.8.258.32-electron.0
OS: Darwin x64 24.4.0

For AI issues: which model did you use?

There are a lot of models selected, so I am not sure which model sits behind the AI.

For AI issues: add Request ID with privacy disabled

375fe0a3-7618-4b79-a599-33ff10d30667
67dfbe74-d91b-4ba6-ace6-cbfac792a627

Additional Information

There are commentary to the AI that I did not type.

Does this stop you from using Cursor

No - Cursor works, but with this issue

Hey, thanks for the report. This is a confirmed bug. Plan Mode should first create a plan and wait for explicit approval before running anything, but right now it immediately jumps to implementation.

The additional issue you ran into, where the AI claims you wrote “Implement the plan as specified…” even though you didn’t, is especially concerning and makes this a high-priority bug.

I’ll pass this to the engineering team along with your request IDs. In the meantime:

  • Could you share which AI model you were using?
  • If possible, could you share a screenshot of your chat history showing where this hallucinated message appears?

I can’t paste in from my project as it is confidential, but I managed to replicate it, based on creating a metro train network, its crazy what the Bot does, full screenshots below:

After I ask it to plan a new feature or anything really, in plan mode, then I ask it create a proper .md file because when Cursor crashes you lose the plans. After it create’s the .md file is automatically switched to agent mode, and then starts coding. I stoped it in this instance and asked it what it was doing. It claimed I wrote:

> "Implement the plan as specified, it is attached for your reference. Do NOT edit the plan file itself. To-do’s from the plan have already been created. Do not create them again. Mark them as in_progress as you work, starting with the first one. Don’t stop until you have completed all the to-dos.“

Where does the bug appear (feature/product)?

Cursor IDE

Describe the Bug

I used plan mode for feedback, but Cursor started building without my command. This disrupts the workflow when I only need high-level opinions or architectural advice.

Steps to Reproduce

  1. Plan Mode
  2. Ask several question or discussion
  3. Suddenly become Agent mode

Expected Behavior

Keep in Plan Mode, not agent mode

Screenshots / Screen Recordings

Operating System

MacOS

Current Cursor Version (Menu → About Cursor → Copy)

Version: 2.1.25
VSCode Version: 1.105.1
Commit: 7584ea888f7eb7bf76c9873a8f71b28f034a9820
Date: 2025-11-23T04:45:23.529Z
Electron: 37.7.0
Chromium: 138.0.7204.251
Node.js: 22.20.0
V8: 13.8.258.32-electron.0
OS: Darwin arm64 24.3.0

For AI issues: add Request ID with privacy disabled

3e2fc0d9-1e4b-4e48-82c1-3115092ff325

Does this stop you from using Cursor

No - Cursor works, but with this issue

1 Like