GitHub posted a changelog entry on 26 August at 22:08 UTC announcing that global model policy for Copilot is generally available. Read as a feature launch, it is unremarkable administrative plumbing. Read as a change in default state across every Copilot Business and Copilot Enterprise tenant, it is worth ten minutes of an administrator's attention this week.
What changes on its own
Models an administrator has explicitly enabled or disabled keep those settings. Every model that was never explicitly configured moves into a new state GitHub calls "delegate to default policy" — described in the post as "a live, dynamic state that always tracks your policy." The consequential sentence is the next one: "If your policy is enabled — which is the default — those models will become available to your users."
What the common framing gets wrong
"Generally available" signals that an optional capability has finished its preview and can now be adopted. That is not what is happening. The capability is being applied, on by default, to tenants that took no action, and it changes which models developers can send code to. The mechanism is also forward-looking: because the delegated state is dynamic rather than a one-time migration, models GitHub adds in future will inherit the same default. An administrator who reads "GA" as "available if we want it" has inverted the direction of the change.
Where the guardrails are
GitHub has drawn the line in a defensible place. Two categories remain disabled by default regardless of the global policy: open-weight models, and models without data-retention agreements in place. That covers the case most enterprise policies actually care about — proprietary source code reaching a provider with no contractual retention commitment. The models flipping on by default are those GitHub has retention terms with.
The rollout window is the practical problem
The change began 26 August and completes by 1 September, and the post is explicit that "it will take effect at different times for different enterprises." An administrator who checks the model list today may see the old state; the same list may differ on Monday. There is no announced per-tenant schedule and no notification when a tenant flips. For organisations that certify their approved-model list for audit purposes, the auditable fact is that the list changed on a date the vendor did not specify in advance.
What to do about it
The action is small and time-boxed: decide whether the global default should be enabled or disabled before 1 September, and set the models you care about explicitly rather than leaving them delegated. Explicit settings survive; delegated ones follow whatever the policy says today and whatever it says after the next model is added.
