Skip to content
TrustList
News

GitHub will switch on unconfigured Copilot features for Business and Enterprise from 22 October

Editorial

By TrustList Editorial

A new default policy for generally available Copilot features takes effect on 22 October. Unless an admin chooses otherwise, it is Enabled, and every feature left unconfigured, including code review and MCP servers, follows it.

About GitHub will switch on unconfigured Copilot features for Business and Enterprise from 22 October

GitHub will switch on unconfigured Copilot features for Business and Enterprise from 22 October

24 September 2026 — GitHub announced on 24 September 2026 a new "default policy" for generally available GitHub Copilot features in Copilot Business and Copilot Enterprise. The policy starts to apply on 22 October. Until then, administrators can set it without affecting what their users can do. After that date, any eligible feature an administrator has never configured follows whichever default was chosen, and if nobody chooses, the default is Enabled.

Not yet independently verified. This rests on GitHub’s own changelog; the only other write-up found restates it. No independent report of it was found, so every date here comes from the vendor's own page and is only as reliable as that page. We will update this when it can be confirmed, and remove this note.

What changes

The setting sits on the AI Controls page, under the Copilot section, as "Default policy for new features". It has three values:

  • Enabled: generally available features are on for users unless an administrator turns a feature off.
  • Disabled: features stay off, and future ones need to be approved one by one.
  • Let organizations decide: at enterprise level, each organisation sets its own default.

The policy covers the features and client capabilities listed on the enterprise's Copilot features page, and also the Copilot code review policy and the policy for MCP servers in Copilot. MCP servers let Copilot connect to outside tools and data sources, which is why that setting matters to security teams.

GitHub says explicit per-feature choices already made are kept, and that features still in preview remain opt-in. The change is about features that were left in the "Unconfigured" state, which in many organisations is most of them.

Who is affected

Organisations paying for Copilot Business or Copilot Enterprise, at both enterprise and organisation level. It matters most where Copilot was bought for code completion alone and nobody has looked at the policy page since, or where legal, security or procurement agreed to Copilot on the basis of a limited feature set. From 22 October, features added by GitHub would reach developers without a separate decision.

What to do

  • Before 22 October, open the AI Controls page and choose the default deliberately rather than inheriting Enabled.
  • Go through the features list and set each one that matters to you explicitly, especially Copilot code review and MCP servers; explicit choices are not overridden.
  • If Copilot was approved under a data-protection or security review, check whether that review covered the features that would switch on, and record the decision either way.
  • For enterprises with several organisations, decide whether "Let organizations decide" matches how you actually govern tools, or whether one central default is safer.
  • Tell developers what will and will not be available, so a feature appearing or disappearing on 22 October is not reported as a fault.

Sources