The Copilot admin console quietly became a governance tool
In the first week of September GitHub gave enterprise admins default models, content exclusions and budget expiry. Your AI policy can finally be enforced where it runs.
Something pleasant happened in the first week of September, and it arrived as four unglamorous changelog entries. GitHub gave Copilot enterprise admins a default model setting, made content exclusions generally available in the app and CLI, and added expiry dates on individual user budgets.
Why I care, and why you should: most AI usage policies I read are enforced nowhere. The policy says "no assistant near the payroll repository," and the enforcement is a hopeful paragraph in the onboarding deck. Exclusions that actually follow the tool into the CLI move that sentence from wish to setting. Same with budgets that expire on a date instead of lingering as a standing tab, a small mercy for whoever reconciles the seat spend in January.
One entry deserves a slower read: Copilot code review can now approve pull requests. It ships disabled by default, which is the correct setting, and I would leave it there until your review policy says out loud what a machine approval means.
The homework is an hour. Open the console, map each policy sentence to a setting, and write down the ones that still have no knob. That list is your actual risk register.