On August 26, 2026, GitHub Copilot Business and Enterprise will change how generally available but unconfigured models are offered. They will automatically follow a new global policy that is enabled by default. An organization that changes nothing may therefore expose newly released models without approving each one manually.
GitHub wants to shorten the delay between model availability and adoption. That is convenient for a small team. For an enterprise governed by residency, retention, cost or intellectual-property rules, however, the absence of a choice becomes a technical choice.
The short answer
| Question | Answer |
|---|---|
| When does the policy take effect? | August 26, 2026. |
| Which models are affected? | Eligible GA models left unconfigured. |
| Are explicit choices overwritten? | No. Explicitly enabled or disabled models keep their state. |
| Are open-weight models enabled automatically? | No. GitHub excludes open-weight models from this mechanism. |
| What should a cautious administrator do? | Select a global default and define exceptions before August 26. |
“Inherits default” replaces indecision
Until now, a new model could remain unconfigured until an administrator intervened. Under the new rule, that state becomes inherits default. When the global policy is enabled, the model becomes available; when it is disabled, the model stays blocked.
The benefit is consistency. An innovation-friendly organization no longer has to open every model manually. A regulated organization can set the default to disabled and maintain an allowlist. In both cases, the setting also applies to eligible models released later.
Explicit decisions take precedence. Individually disabling a model prevents inherited enablement even when the global default is permissive. This hierarchy supports a simple baseline plus documented exceptions.
Not every model follows the rule
GitHub excludes preview models, open-weight models and models outside its data-retention agreement. Environments restricted to data-resident or FedRAMP-compliant models keep those constraints as well.
These exclusions prevent a generic setting from bypassing major contractual boundaries. They do not remove the need for review. A covered model can still have a different price, quality level, context window or behavior from the one an enterprise validated.
The real issue is change governance
Multiple models let developers choose between speed, reasoning depth and context size. They also make outputs less uniform. Two people may receive different suggestions on the same repository, and changing a model can alter AI-credit use or how code reaches a provider.
A durable policy answers four questions: which providers are approved, what data may leave the workstation, which budgets are acceptable and how quality is measured. The model list is only the implementation of those decisions.
GitHub recommends a generally permissive posture with critical exceptions blocked. An enterprise can reasonably choose the opposite. The right default depends on required control, not a universal preference.
A five-step check before August 26
Open Copilot settings at enterprise and organization level. Identify models that are explicitly enabled, disabled or optional. Choose the Default availability for released models value, then document exceptions.
Review data-processing and residency requirements with security and legal teams. Pair the model policy with AI-credit budgets: opening more models without spending limits can create a financial surprise even when compliance is sound.
After the policy takes effect, verify the effective list through a representative user account. Inheritance between enterprise and organization levels can produce a different result from what one settings screen suggests.
Local tools and custom keys need separate controls
Organizations allowing user-provided models or custom provider keys must govern that channel separately. GitHub-hosted model policy does not automatically cover a local model, IDE extension, CLI or MCP server.
Developer workstations now combine several control planes: GitHub account, editor configuration, extensions, command-line tools and external connections. The inventory must cover all of them, or strict Copilot settings will leave an unmonitored parallel route.
The August 26 change is not a vulnerability; it is a new operational default. Teams that set a clear policy gain simplicity. Teams that leave the state implicit may discover later that a model became available because nobody explicitly rejected it.




Join the discussion
Comments
Loading comments…