Skip to content

GitHub lets organizations absorb the AI-credit cost of Copilot code review

· by Pondero Newsdesk

The short version

GitHub's October 8 changelog adds an org-level billing toggle for Copilot code review and a setting that blocks reviews requested through an outside Copilot license.

GitHub lets organizations absorb the AI-credit cost of Copilot code review

Copilot code review has billed every automatic review to the developer who opened the pull request since it launched, draining that person's own AI-credit entitlement one review at a time. GitHub changed that on October 8, 2026, adding a setting that moves the bill to the organization instead, per GitHub's changelog.

What happened

GitHub's October 8 changelog entry ships two controls for Copilot code review admins. A new billing choice sits under organization settings, Copilot > Policies: "Member" (the existing default) bills the requesting member's own Copilot entitlement and fails the review outright if that quota is exhausted, while "Organization" bills the org's AI credits instead, per GitHub's changelog. Organization billing requires AI credits paid usage to already be turned on for the org, and admins can optionally cap it with a budget. Separately, a setting called "Only allow Copilot code review to be triggered by authorized users" lets organization owners and repository admins block review requests made with an external Copilot license, meaning a personal license or one issued by a different organization, per GitHub's documentation. Turning it on stops Copilot from appearing as an available reviewer to unauthorized people, blocks API review requests from them, and in personal repositories limits requests to the owner or a direct collaborator.

Organization billing undoes a cost GitHub quietly shifted onto developers

GitHub switched Copilot code review's default effort level from "Lite" to the more expensive "Balanced" tier on September 28, a change Pondero covered when GitHub documented it on October 2. That switch raised the AI credits each automatic review consumes, and because review costs bill to the pull request's author by default, the increase landed as a personal usage bump that an admin could not see centrally, per GitHub's documentation. Now admins get a direct way to move that spend off individual quotas and onto a budget they can actually track, though only after they turn on paid AI-credits usage for the org first. Access control solves a separate problem: without it, a contractor or outside collaborator with a personal Copilot license could keep triggering reviews on company repositories at will. Once an organization owner enables the authorized-users setting at the org level, repository admins cannot turn it back off for an individual repo, per GitHub's changelog, so that decision sits fully with the organization rather than with whoever administers a given repo.

What to watch next

Both controls apply only to Copilot code review for now; GitHub has not said whether similar org-level billing or access settings are coming to other Copilot surfaces, such as the CLI or JetBrains integration. Admins who already enabled automatic review broadly, and absorbed the September cost increase personally, are the likeliest group to flip the new Organization billing toggle first.

Sources