GitHub Copilot’s default model policy takes effect on August 26

GitHub’s changelog artwork for default Copilot model enablement.GitHub Changelog
GitHub’s changelog artwork for default Copilot model enablement.GitHub Changelog
Tools & Apps

Unconfigured generally available models can now become available automatically to Copilot Business and Enterprise users unless administrators change the default policy.

GitHub’s new model-availability policy takes effect on August 26, 2026 for Copilot Business and Copilot Enterprise. In most affected organizations, generally available models that administrators left unconfigured will inherit an enabled global default and become available without a separate approval for each model.

The change alters the governance baseline for future Copilot model launches. Explicit enable and disable choices remain intact, and several model classes are excluded from automatic enablement.

Key takeaways

  • The policy affects Copilot Business and Copilot Enterprise, not individual subscriptions.
  • Existing and future generally available models marked as unconfigured now inherit the global model-availability policy.
  • The global policy is enabled by default, so unconfigured eligible models can become available automatically.
  • Explicit model decisions are preserved.
  • Open-weight, pre-GA, data-retention-excluded, and incompatible data-residency or FedRAMP models are not automatically enabled.

The August 26 policy change

GitHub announced the transition on July 29 and provided a 28-day configuration window. During that window, administrators could see and change the new Default availability for released models policy, but it did not yet control user access.

From August 26, models without an explicit decision are relabeled from unconfigured to inherits default. If the global policy is enabled, those models become available. If an administrator disables the global policy, inherited models remain unavailable until someone enables them explicitly.

The inherited state is dynamic. Changing the global policy later updates every model that still inherits it, while models with explicit choices remain unchanged.

Which Copilot models follow the default

The policy covers generally available Copilot models that an enterprise or organization has not explicitly configured. It also applies to future GA models, so the operational impact continues beyond today’s migration.

GitHub excludes pre-release models, open-weight models such as DeepSeek and Kimi, and models outside its data-retention agreement. Its documentation also excludes models that conflict with an enterprise’s data-residency or FedRAMP restrictions.

Those exclusions reduce the chance that a model with materially different data handling appears automatically, but administrators still need to decide whether GitHub’s default eligibility rules match their own vendor-review and AI-governance requirements.

What administrators should check now

Organizations that want new eligible models enabled as GitHub releases them can keep the default policy active. Administrators who require a separate security, legal, cost, or quality review for every model should disable it in the enterprise or organization model-policy settings.

A practical review should cover three layers: the global default, explicit decisions for currently available models, and any organization-level inheritance beneath an enterprise policy. Teams using stricter controls for regulated repositories may also need separate organization settings rather than one enterprise-wide decision.

Model access can affect more than model choice. Different models may have different costs, capabilities, geographic availability, and data-processing terms. GitHub’s policy decides availability; it does not replace internal approval, usage monitoring, budget controls, or developer guidance.

The immediate action is to inspect the AI controls page and confirm that the displayed default matches the organization’s intended governance posture. Future Copilot releases will otherwise follow that setting automatically.

Source check

From reading to doing

Try the related loot

Run AI video jobs without holding one HTTP request open

Open loot