GitHub Copilot Global Model Policy reaches GA, giving enterprise admins control over which AI models their organization can use
The global model policy GitHub announced for Copilot in July moved into active enforcement on August 26, 2026. Admins who have not explicitly configured individual model availability may now find that previously untouched models have flipped to accessible for their users.
What happened
Per the GitHub Changelog, GitHub began a gradual rollout of enforcement for its Global Model Policy on August 26, covering Copilot Business and Copilot Enterprise plans. Full enforcement lands by September 1, with timing varying across organizations during that window.
The core mechanic: previously unconfigured generally available models now switch to a "Delegate to default policy" state and inherit the org-wide policy setting. Because the default policy is "enabled," those models become available to Copilot users unless an admin explicitly changed the org-level toggle to "disabled."
Admins who had already made deliberate per-model choices are unaffected. GitHub stated it preserves all explicit decisions, so a model an admin previously turned off stays off regardless of the global policy setting.
Two categories of models are excluded from default enablement no matter what the global policy says: open-weight models (GitHub cited DeepSeek and Kimi K2 as examples) and models not covered by GitHub's data retention agreement (GitHub cited Fable 5 as an example). Those remain disabled unless an admin explicitly enables each one.
After enforcement, each model in the settings interface shows one of four states: Enabled (explicit on), Disabled (explicit off), Delegate to enterprise teams or organizations (inherited from a parent level), or Delegate to default policy (follows the org-wide toggle).
Why it matters
Enterprise admins who assumed no action was needed may find Copilot users can now reach models they had not reviewed. The practical step before September 1 is to open Copilot Business or Enterprise settings and confirm that every model's displayed state reflects an intentional choice rather than a policy inheritance.
For organizations with data governance requirements or vendor-approval processes tied to specific AI providers, an inherited "enabled" state on a frontier model they had not formally approved is the exposure to close. The exclusion of open-weight models from default enablement is the more conservative default: organizations that want DeepSeek or Kimi K2 available to developers must make that decision explicitly.
The policy also changes onboarding behavior for new generally available models GitHub ships in the future. Any newly released GA model (excluding open-weight and non-data-retention-covered models) will automatically inherit the org's global policy rather than defaulting to disabled, which was the prior behavior.
Context
GitHub announced the Global Model Policy framework in July 2026. The enforcement launch ships alongside two other Copilot governance updates from the same week: MCP allowlists went live on August 6 and the Copilot app Customize Tab reached general availability on August 25. The three features together give enterprise teams layered controls over which AI models run in Copilot, which MCP servers are accessible, and which extensions appear in the Customize tab.
Looking ahead, GitHub said it is evaluating a further change: eliminating the "Delegate to default policy" state entirely and requiring admins to make an explicit on or off decision for every model. If that change ships, the implicit inheritance behavior would no longer be an option.
What to watch next
GitHub is collecting feedback on the proposed removal of implicit delegation through a GitHub Community discussion. Organizations with formal AI vendor approval workflows should monitor that thread, as eliminating the implicit state would require a one-time audit and explicit configuration of every Copilot model in their settings.
Sources
- Global model policy generally available: GitHub Changelog, August 26, 2026
