GitHub Copilot's new "Default policy for new features" and the October 22 cutover
GitHub announced the change in its changelog on September 24. It describes a new global default policy for generally available Copilot features and supported client capabilities, in both enterprise and organization Copilot settings. For the first 28 days you can set the policy, but it does not change what users can access. The policy takes effect on October 22.
The setting is on the AI Controls page, under the Copilot subpage, labeled "Default policy for new features." There are three options:
| Setting | Current eligible features | Future eligible features |
|---|---|---|
| Enabled | Available to users by default | Available to users by default |
| Disabled | Remain unavailable | Require administrator approval |
| Let organizations decide | Organization admins choose | Organization admins choose |
The table only covers features whose policy is Unconfigured. On October 22, eligible GA features and capabilities left Unconfigured will follow the global default you chose. GitHub also says it will not override a feature you have explicitly enabled or disabled.
The wording of the Disabled option is worth reading closely. GitHub says current eligible features "will remain unavailable." That implies an Unconfigured GA feature is generally off today. If so, choosing Enabled switches those features on for your users on October 22. This is our reading of the changelog text, not a separate statement from GitHub, but it points to the real task: go through the backlog of Unconfigured policies before the date arrives.
Which Copilot policies the default covers: Features & clients, Code Review and MCP
The policy does not reach every Copilot toggle. According to the changelog, it applies to eligible features managed on the enterprise's Features & clients page, plus two policies that live elsewhere: the Copilot Code Review policy on the Agents page, and the MCP servers in Copilot policy.
Those two additions carry real weight. Code review changes how pull requests get feedback. MCP (Model Context Protocol) servers let Copilot connect to outside tools and data sources, which is the sort of capability security teams usually want to approve on purpose. If either one sits at Unconfigured in your enterprise, its state on October 22 depends on the global default.
Preview features are outside the policy. GitHub says previews stay opt-in. If you opted into a preview and it later becomes generally available, your earlier choice carries over. A preview therefore won't switch on just because the global default is Enabled. When a preview reaches GA, though, and nobody configured it, it falls under the default like any other Unconfigured GA feature.
GitHub says its default-availability documentation lists which features are eligible and which are exceptions. We could not independently confirm that list. If a particular control matters to your compliance posture, check how it is labeled on your own Features & clients page and don't assume it is covered.
How enterprise and organization settings interact
The new default follows the same hierarchy as other Copilot policies. GitHub's policy documentation says that in an enterprise, policies are set at the enterprise level first. For most policies, enterprise admins can explicitly enable or disable a policy, or let organizations decide. As an exception, for Copilot cloud agent, enterprises can select exactly which organizations receive access.
The "Let organizations decide" option passes that choice down. Organization administrators then pick whether eligible features are on or off. That suits enterprises made up of organizations with different risk profiles. One government administrator made this point in GitHub Community feedback on the earlier model policy. The admin runs more than 40 organizations under an NIH enterprise, some belonging to agencies with their own security posture, and asked GitHub to let organizations run as self-sufficient as possible.
Delegating adds work in each organization. If the enterprise chooses Let organizations decide, every organization owner needs to review their own Unconfigured features before October 22. Otherwise the outcome for each organization depends on what its admins did or didn't do. GitHub's policy documentation also describes a separate Policies for enterprise-assigned users setting that controls how "Let organizations decide" policies resolve for users who get Copilot from the enterprise directly. Enterprises that assign seats that way should check it as well.
The Copilot model policy already showed how this rollout works
This is the second time GitHub has used this approach in about two months. On July 29, it announced a global default enablement policy for generally available Copilot models on Business and Enterprise plans. The goal was to stop admins having to turn on each new model by hand: models that become generally available will now be on by default. The rollout had the same shape. For the next 28 days, this policy is configurable but has no effect on model availability — nothing changes for your users yet.
GitHub's advice then was blunt. If you're happy with models being available by default, no action is needed. If you'd rather manually approve each model, set the policy to disabled before August 26. Enforcement arrived on August 26 as a staged rollout, not a single switch. Starting today, we're gradually rolling out enforcement of the policy through September 1, so it will take effect at different times for different enterprises.
The model policy also showed what shipped as the default. When it took effect, models nobody had configured changed to "Delegate to default policy," and if your policy is enabled — which is the default — those models will become available to your users. GitHub also carved out stricter defaults for riskier cases: open-weight models and any models that require data retention are disabled by default.
The new feature changelog does not say which of the three options is preselected, and it gives no staggered rollout window after October 22. Based on the model policy, the safe assumption is that Enabled is the starting value. Open the setting and check what your tenant shows. Don't assume a neutral or off position.
These are two separate policies. The model policy lives in model settings and has been enforced since the end of August. The new policy covers features and client capabilities and starts on October 22. Setting one does not set the other.
Copilot's autumn policy changes add up
The feature default arrives in a busy season for Copilot admins, and some of the other changes also push things toward on-by-default. In an August 28 changelog, GitHub said that no earlier than September 28th, 2026, GitHub will relaunch Copilot Chat on github.com, Copilot Chat in GitHub Mobile, and GitHub Copilot cloud agent as a single, unified Copilot experience. The separate policies for these experiences will be replaced by a single policy. This unified Copilot experience will be enabled by default after launch. The same announcement said chat data will be retained for the life of the account instead of 28 days, which may matter to compliance teams.
The model default is also already changing outcomes. GitHub plans to deprecate a set of Copilot models on October 19. In that notice it said that under default model enablement, the suggested alternatives are automatically enabled for Copilot Enterprise and Copilot Business customers unless an administrator has turned off the global default or explicitly disabled the model. In other words, models are now reaching users because of a default, with no one approving them one at a time.
Billing is changing in the same weeks. For customers paying by credit card or PayPal, GitHub says all new Copilot Business and Enterprise seat assignments will need payment for each seat before users get access, with the change reaching existing customers starting October 1, 2026. The feature default doesn't touch billing directly. But the admins who handle seats and invoices are often the same people who own AI Controls, and October is heavy for them.
What this means for you
The choice here is whether your organization wants GitHub's new GA Copilot features to arrive on their own or only after someone approves them. Make that choice before October 22 so GitHub's default doesn't make it for you.
Teams that already let developers use most Copilot capabilities can probably keep Enabled and spend a few minutes checking for anything that should stay off. Regulated organizations should decide more carefully. So should anyone who reviews AI tooling individually, and any enterprise where MCP server access or automated code review needs sign-off. For them, Disabled keeps current Unconfigured features off and sends future features to an approval queue. Let organizations decide fits enterprises that already delegate Copilot governance, as long as each organization's admins know they now own the decision.
Sort out explicit exceptions whichever option you choose. Explicit enable and disable decisions survive October 22, so they are the lasting way to lock in a setting. An enterprise that picks Enabled can still explicitly disable MCP servers. An enterprise that picks Disabled can explicitly enable code review.
- Open AI Controls, then Copilot, find "Default policy for new features," and note which option is selected now. Assume it may be Enabled, since that was GitHub's default for the equivalent model policy.
- Review every policy marked Unconfigured on the Features & clients page, along with the Copilot Code Review policy on the Agents page and the MCP servers in Copilot policy. These are the controls whose behavior will change.
- Explicitly enable or disable any feature whose state must not depend on the global default. GitHub says explicit choices won't be overridden.
- If you choose Let organizations decide, tell organization owners they need to set their own defaults and review their Unconfigured features before October 22.
- Don't confuse this setting with the Copilot model default. The model default has been enforced since late August and is configured separately in model settings.
- Previews stay opt-in, but a preview that becomes GA without anyone configuring it will follow the default. Keep this in mind for preview features you haven't opted into yet.
With this policy, GitHub has moved to a model where Copilot capabilities that reach GA also reach users by default unless an administrator sets something else. That now applies to models, to the unified Copilot chat experience, and from October 22 to features and client capabilities. The one-time setting is not much work. The ongoing change is that each future GA feature will arrive according to that one setting, so admins who want to approve features individually need to choose Disabled or set explicit decisions before October 22.