Who controls the routing layer
17 August 2026 · 5 min read
An acquisition does not change a single line of code.
Bloomberg reported on 16 August that Stripe is acquiring OpenRouter for more than $7 billion. The Wall Street Journal had reported talks in July. Stripe has confirmed nothing: a spokesperson said the company "does not comment on rumors or speculation." Everything here rests on "reported". The deal may close, change shape, or evaporate. The question it raises does none of those things.
A gateway sits in the path of the prompt
OpenRouter's CEO has described the product as "the equivalent of Stripe for AI", a single access point for different model providers. Take the description at face value, because it describes every AI gateway on the market. An application sends a request to the gateway. The gateway forwards it to a model provider and returns the completion. To do that job, it has to see the request. Prompts, outputs and metadata pass through the routing layer by design. That is not a flaw in any particular product. It is what routing means.
Which is why "who controls the routing layer" is not a corporate finance question. It is a data protection question. OpenRouter reports 8 million users. Each of them has a request path that runs through one company, and the ownership of that company is, reportedly, about to change.
What an acquisition actually changes
The morning after a closing, the software is identical. Same endpoints, same keys, same latency, same dashboard. What changes is the entity in control of the processor: who sets its policies, who directs its roadmap, and, decisive for a European controller, which state can compel it. Jurisdiction follows ownership. A processor whose parent sits in another country can fall within reach of that country's disclosure laws no matter where the servers stand.
Whether this particular deal would move any data across a jurisdictional line is not knowable from the outside, and it is not the point. The point is that a change of control can move the legal position of your data without a migration, without a deploy, without a single commit. In May 2026 OpenRouter raised a $113 million Series B at a $1.3 billion valuation from Sequoia, Andreessen Horowitz, Menlo Ventures and Alphabet's CapitalG. Three months later the reported buyer is a payments company. Whatever you concluded about a vendor's ownership during procurement has a shelf life, and you do not get to set it.
This is not a sub-processor change
The GDPR has a mechanism for the event everyone plans for. Article 28(2) says a processor may not engage another processor without the controller's authorisation, and that under a general written authorisation the processor must inform the controller of intended additions or replacements, giving the controller the opportunity to object. Data processing agreements implement this with notice periods and objection windows. It is routine plumbing.
A change of control over the processor itself is a different event. No sub-processor is added. None is replaced. The legal entity that signed your DPA can be exactly the same entity the day after closing, with the same registration number, under entirely new ownership. Article 28(2) does not speak to that, and most DPAs do not either. If the contract is silent, notice is a courtesy.
Where the event is addressed at all, it usually lives in the assignment clause of the master agreement rather than in the DPA, and it is common for assignment clauses to permit transfer in connection with a merger or sale without customer consent. How any of this reads in your specific contracts is a question for your counsel, not for a vendor's blog.
Open your DPA
Three questions, answerable in fifteen minutes with documents you already signed:
- Does a change of control over the processor trigger notice to you? Search for "change of control", "assignment" and "merger", in the DPA and in the master agreement it hangs off.
- If notice exists, what does it buy you? A right to object, to terminate, to export and delete? Or just an email?
- Can you establish, today, the parent jurisdiction of every company in your processing chain, and is that record dated, so you would notice when it changes?
Most contracts fail the first question. Almost all fail the second. If yours do, that is worth knowing before a Saturday news alert, not after.
What survives an acquisition
Akumi is registered in the Netherlands, KvK 98356623, and a business like ours can change hands like any other. Our residency enforcement lives in code and fails closed, and none of that would stop an acquisition, because code cannot bind a cap table.
That is the honest end of the argument. Any vendor can be acquired. The people who own a company today are a fact about today. The only thing a customer holds across a change of control is what was written down before it: the notice obligations, the objection rights, the exit terms, the dated record of who processes what and under which parent. If the Stripe and OpenRouter report teaches anything, it is that the org chart is not in your contract. Everything you can rely on is.