Skip to content

September ‘26 enterprise roundup

In case you missed it…

September 2026 edition of the GitHub Monthly Enterprise Roundup (MER)

Published via GitHub Executive Insights | Authored by Dave Burnison

AI-assisted development is rapidly becoming agentic engineering—and this roundup helps enterprise leaders and developers turn that shift into measurable, governed results. The central theme is GitHub’s Agentic Engineering System: a practical operating model for deciding where agents should accelerate work, where human judgment remains essential, and how shared knowledge, guardrails, and outcome-based measurement can prevent faster code generation from simply scaling defects, rework, and risk. This edition connects that strategy to concrete capabilities across the software lifecycle. Explore Project HydraFusion (research project) and Copilot’s expanding agent, app, CLI, SDK, IDE, and collaboration experiences to see how teams can orchestrate models and parallel work more efficiently.

Whether you lead an engineering organization or build software every day, use this roundup to prioritize three actions:

  • Establish an agentic engineering operating model

  • Measure adoption by outcomes rather than output

  • Embed automated quality, security, and human approval into every AI-assisted workflow.

The result is not merely more code—it is a more productive engineering system capable of delivering higher-quality, more secure software at enterprise scale.

The MER is designed for everyone involved in enterprise software development, so it intentionally covers a broad range of topics. You do not need to read it from beginning to end—scan the sections that match how you use GitHub, then explore the links most relevant to your work. Because readers often skip entire sections, some links appear more than once when they apply to multiple areas, such as Code Security and CI/CD. No single person is expected to follow every link, but across a team, each resource may be valuable to someone. Share the full MER with your colleagues, or send them the individual links that best fit their roles.

Want to get notified of when the next MER is available? Go to GitHub Enterprise on LinkedIn and click on the "Follow" button. In addition to MER notifications you'll be notified when other enterprise focused content becomes available.

Events

While GitHub hosts our own marquee events like Universe and Galaxy each year, you will also find GitHub participating in other industry events. Here is the latest news about upcoming conferences.

  • 📅 GitHub Universe (October 28–29 / San Francisco, CA) - In-person & virtual. GitHub’s flagship developer event uniting humans, agents, and the world’s code to build what’s next. GitHub Universe 2026 returns to Fort Mason Center in San Francisco on October 28–29, bringing together builders, security practitioners, and technical leaders for two days focused on navigating the shift from AI-powered code generation to fully agentic workflows.

  • 📢 Your guide to GitHub Universe 2026 is here: The schedule just launched! – This schedule highlights the conversations, case studies, and emerging trends that are likely to influence developer tooling and workflows over the next several years. Explore interactive workshops, community talks, demos, and panels.

  • 📅 Spend Smarter: Optimizing Copilot Tokens Without Slowing Builders (October 7, 9:00 AM — 9:45 AM PDT) - More AI usage shouldn't mean runaway costs or throttled developers. This demo session is for the people accountable for both. We'll break down real consumption patterns, how to match the right model to the right task, and where token waste hides. Then we'll show you how to set smart guardrails and measure the value you're actually getting.

  • 📅 Building for the Frontier Firm: What's Next for GitHub + AI (December 17, 11:00 AM — 12:00 PM PDT) - Look ahead at the future of agentic development. This session positions GitHub as the engineering layer for the “Frontier Firm” — where business users surface needs, builders create autonomous agents and applications, and security teams validate trust before production. You’ll explore the product roadmap, innovations from GitHub Next, and how GitHub + Microsoft together enable end‑to‑end AI transformation.

  • 📅 Upcoming GitHub events, webinars & developer conferences - Skim through all upcoming events including webinars and regional events.

GitHub Platform

The team at GitHub is incredibly passionate about our work. We read every email, social post, support ticket, and we take it all to heart. We are committed to improving availability, increasing resilience, scaling for the future of software development, and communicating more transparently along the way.

General Platform Updates

  • 📢 GitHub availability report: August 2026 - August 2026 exposed several hard scaling limits inside GitHub’s platform, including outages that impacted GitHub Actions, Pull Requests, Issues, APIs, authentication, and Copilot services. For enterprise engineering leaders, this report provides unusually detailed insight into where GitHub’s availability risks currently lie, what architectural investments (Azure migration, database modernization, capacity management, overload protection, and monitoring improvements) are underway, and how GitHub is addressing the operational challenges created by rapid platform growth.

  • 📢 GitHub availability report: July 2026 - Beyond the incident list, GitHub’s engineering leadership provides a detailed look at the architectural changes GitHub is making to reduce dependence on shared infrastructure, accelerate its migration to Azure, improve service isolation, and increase resilience against regional failures. For enterprise engineering leaders, the key takeaway is that GitHub has now crossed a major milestone with more than half of monolith read traffic running from Azure, critical authentication and repository services moving off shared bottlenecks, and a clear roadmap toward surviving datacenter or regional failures. The post offers a candid assessment of recent reliability challenges, including a major Actions outage, while explaining the investments and operational changes that will directly affect the stability, scalability, and risk profile of the platforms your developers depend on every day.

  • 📢 The August 17 outage and the work ahead - GitHub’s CTO provides a candid postmortem of the August 17 outage, explaining that the failure was driven by capacity limits amid explosive platform growth rather than a bad deployment, and outlining the concrete engineering investments underway to prevent similar incidents. The post is especially relevant for enterprise software leaders because it offers a rare look at how one of the world’s largest developer platforms is addressing scale, resilience, architectural bottlenecks, and operational maturity while platform demand has more than doubled in only a few months.

  • 🚢 Refreshed repository pull requests page in public preview - Boolean and nested search, a compact view, status check counts, and unread indicators change how quickly large teams can triage a crowded PR queue — with a few gaps worth knowing first.

  • 🚢 GitHub CLI: Media in issues, pull requests, and comments - The --attach flag in GitHub CLI v2.99.0 lets developers add local images and videos directly to issue, pull request, and comment Markdown, making visual context available without switching to a browser.

  • 🚢 GitHub Changelog - GitHub Platform - Skim through all of the recent GitHub Platform related changes.

GitHub Issues and Projects

Enterprise Management & Governance

We have been listening to our enterprise customers for years. We are excited to share product updates and new guidance to assist those who manage GitHub for hundreds if not thousands of stakeholders. This month's updates demonstrate how we are acting on your feedback to address the issues in multiple areas you face managing GitHub Enterprise at scale not only with new features and capabilities but, with new guidance to properly manage it all in your world.

General

  • 📄 Enterprise administrator documentationCheck out the new documentation landing page for Enterprise administrators. If your organization is scaling GitHub across hundreds or thousands of developers, this is the roadmap for controlling identity, access, security, governance, networking, and platform-wide policies from a single enterprise perspective. It explains the features and decisions that directly impact compliance, developer productivity, GitHub Actions governance, managed users, and enterprise administration, making it essential reading for anyone responsible for platform engineering, DevOps modernization, or GitHub Enterprise strategy.

  • 🚢 New customer portal help.github.com - Support, docs, learning, community, entitlements, and product status now live behind one Copilot-powered search experience that is rolling out gradually over the next few weeks.

  • 🚢 Multiple redirect URIs and token refresh for OAuth apps - Expiring tokens and multiple callback URIs enable safer, more flexible app deployments, but teams should review wildcard redirect matching carefully to avoid exposing authorization codes.

  • 🚢 Automatically migrate branch protection rules to repository rulesets - Repositories can now convert legacy branch protection rules into rulesets in place, lowering the friction of moving to GitHub’s more scalable governance model.

  • 🚢 Rule insights for organizations in public preview - Org-level rule insights give governance teams a single dashboard for bypasses, evaluation trends, and ruleset reporting, reducing manual data collection during audits and investigations.

  • 🚢 Push rules in rulesets now support path exceptions - Governance teams can keep strict file path and file size restrictions in place while exempting only the directories that legitimately need relief, such as a Gradle wrapper JAR, instead of loosening the rule for everyone.

  • 🚢 Rule insights dashboard generally available - Repository and organization dashboards, with CSV export, give compliance teams a single place to see evaluation trends, top bypassers, and drill-downs instead of assembling audit evidence by hand.

  • 🚢 GitHub Apps can now access enterprise billing data - Billing automation and BI pipelines no longer have to depend on one enterprise owner's personal access token, and app installation tokens also carry higher rate limits.

  • 🚢 GitHub billing in India now supports automatic recurring payments - Organizations with India-based billing can now automate recurring payments on saved cards, reducing manual renewal risk and making subscription operations easier to manage.

  • 🚢 Better tools for managing blocked users - Search, filtering, private notes, and clearer block metadata make large moderation lists easier to administer while preserving the context behind organization-level decisions.

  • 🚢 Close all open contributions authored by a blocked user - Moderators can clean up an abusive user's outstanding issues, discussions, and pull requests in a single step from the block dialog rather than closing each item manually.

  • 🚢 Block users directly from security advisories - Organization moderators can act on spam or abuse without leaving the advisory page, keeping the advisory content intact while removing the disruptive participant.

GitHub Copilot & AI

  • 📄 Measure and demonstrate the impact of GitHub Copilot - Understanding whether GitHub Copilot is actually delivering value requires more than tracking license assignments. This guidance shows how to establish adoption baselines, analyze real code generation activity, and correlate usage patterns with engineering outcomes so you can evaluate impact using measurable data rather than anecdotes. For enterprise development leaders, the key value is learning how to connect Copilot adoption metrics with software delivery and engineering performance indicators, making it easier to justify investment, identify teams that need additional enablement, and demonstrate business outcomes from AI-assisted development.

  • 📅 Measuring What Matters: Proving the ROI of AI-Powered Engineering (November 19, 11:00 AM — 12:00 PM PDT) - Quantify the impact of Copilot and agentic workflows. This session helps leaders measure real outcomes — not anecdotes. You’ll explore Copilot Metrics, productivity baselining, adoption patterns that drive sustained value, and how to build a data‑backed business case for scaling AI‑powered engineering across teams.

  • 📚 GitHub's Agentic Engineering System - Successful AI adoption in software engineering is not about generating more code, but about building an operating system for engineering work that balances governance, shared knowledge, and measurable customer value. The post introduces GitHub's Agentic Engineering System (AES), a practical framework for deciding where AI agents can safely accelerate delivery, where human judgment remains essential, and how to avoid scaling rework, defects, and risk alongside productivity. For software leaders and enterprise development teams, this is a blueprint for moving beyond AI experimentation toward sustainable, organization-wide adoption. It provides a structured way to evaluate readiness, define human-versus-agent responsibilities, and measure whether AI is actually improving customer outcomes rather than simply increasing output. Implementation guidance related to this playbook is available in GitHub Well-Architected. Check out 📺 the introductory video (1:37).

  • 🚢 Enterprise managed settings support any default model - Administrators can set enterprise and team-specific default models in managed settings for the Copilot app, CLI, and Visual Studio Code.

  • 🚢 Enterprise-managed settings now support autoUpdate for plugin marketplaces - Approved marketplaces can keep installed plugins current automatically across the Copilot app, Copilot CLI, and VS Code, cutting manual maintenance while still respecting the allowlist admins already enforce. For engineering leaders and enterprise development teams, the takeaway is clear: if you're trying to scale AI adoption beyond a pilot, this article offers a practical playbook for driving organization-wide change, accelerating delivery, and establishing the guardrails needed to do it responsibly.

  • 🚢 Upcoming changes to GitHub Copilot policies and billing - Administrators should prepare for seat prepayment and usage-related billing behavior changes, plus a unified Copilot policy experience and a default code-review effort update that take effect in late September.

  • 🚢 Reopening Copilot Business and Enterprise signups - Credit card and PayPal customers should plan for reopened signups and October billing changes, including upfront charges for assigned seats and payment requirements for new assignments.

  • 🚢 Per-model token breakdown in the usage report - Admins can now see model-by-model token and credit consumption in AI usage reports, making it much easier to explain spend, optimize model choice, and report Copilot costs to stakeholders.

  • 🚢 Add VS Code Agents to Copilot usage metrics - GitHub Copilot usage metrics reports now include generally available metrics for activity in the dedicated VS Code Agents window, helping you measure adoption and engagement across enterprises and organizations. This enables data-backed decisions on adoption, enablement, licensing, and AI engineering impact at scale.

  • 🚢 Set an expiration date for individual user budgets - Automatically retire temporary Copilot Business and Enterprise user-budget overrides on a chosen date or billing-cycle boundary through billing settings or the Budgets REST API.

  • 🚢 Global model policy generally available - Enforcement rolls out gradually through September 1, so Copilot Business and Enterprise admins should review which previously unconfigured models will inherit the default policy and become available to their users.

  • 🚢 Copilot model access update for GitHub Team plans - For users with seats in multiple organizations, model availability now follows the organization billed for their usage, tightening alignment between governance settings and cost ownership.

  • 🚢 Enterprise managed permissions for GitHub Copilot agent operations - Learn how to apply consistent governance, approval controls, and plugin restrictions across AI-assisted development workflows so teams can scale adoption with stronger security, compliance, and operational confidence.

GitHub Enterprise Server

Leadership and Developer Skills

General leadership and developer expertise based on our own experience and the collective experience of our customers and partners. It's time to start diving into how AI is going to work alongside you to make your teams better equipped to work with AI to help your organization create better outcomes not, just more outputs.

  • 📚 GitHub's Agentic Engineering System - Successful AI adoption in software engineering is not about generating more code, but about building an operating system for engineering work that balances governance, shared knowledge, and measurable customer value. The post introduces GitHub's Agentic Engineering System (AES), a practical framework for deciding where AI agents can safely accelerate delivery, where human judgment remains essential, and how to avoid scaling rework, defects, and risk alongside productivity. For software leaders and enterprise development teams, this is a blueprint for moving beyond AI experimentation toward sustainable, organization-wide adoption. It provides a structured way to evaluate readiness, define human-versus-agent responsibilities, and measure whether AI is actually improving customer outcomes rather than simply increasing output. Implementation guidance related to this playbook is available in GitHub Well-Architected. Check out 📺 the introductory video (1:37).

  • 📚 & 📺 Climbing the agentic ladder: From assistance to orchestration (11:09) - Visma shows what happens when AI adoption moves beyond code completion and becomes a new operating model for software delivery. Learn how Visma scaled GitHub Copilot to nearly all of its 4,000 engineers, redefined developer roles around supervising and delegating work to agents, and dramatically accelerated modernization, code review, and feature delivery. As AI removes traditional engineering bottlenecks, the post and video offer software leaders a practical framework for preparing teams to move from individual productivity gains toward orchestrating entire streams of software work.

  • 📚 & 📺 How Docusign scaled AI adoption with champions (6:42) - This case study shows how Docusign achieved 95% GitHub Copilot adoption and nearly 60% AI-assisted code generation in just six months by using a network of AI champions instead of relying on a top-down mandate. It provides concrete examples of productivity gains, including building a major new service in weeks instead of months and creating autonomous coding agents, while also addressing the critical leadership challenges of accountability, developer enablement, and AI governance.

  • 🙋‍♂️ Elevate your learning with 4 new GitHub Skills hands-on exercises - Ready to level up your development game? We’ve just released four new GitHub Skills exercises from June, July, and August designed to help you master the latest in AI-powered workflows and code security with some Hands on Learning!

  • 📢 From coder to orchestrator: How agents shift the role of a developer - The biggest shift in AI-powered software development is not that agents write code, but that developers increasingly own the entire delivery system around that code, designing the workflows, guardrails, reviews, and automation that make AI-generated output trustworthy and repeatable. For engineering leaders and enterprise developers, the key insight is that competitive advantage will come from orchestrating agents within governed delivery pipelines, combining automation with deterministic controls such as testing, security scans, branch protections, and human review. The article provides a practical blueprint for how GitHub Copilot, Actions, and agent-driven workflows fit together, making it essential reading for anyone defining the future operating model of software engineering.

  • 📢 Decoding the new AI lingo: Loops, harnesses, squads, hill climbing, and more - Cut through the rapidly growing vocabulary around agentic AI. This post explains the architectural patterns that are beginning to shape modern software engineering, including loops, harnesses, multi-agent squads, hill climbing, and model openness. Rather than treating these as buzzwords, it shows how they relate to building reliable, scalable AI-powered development workflows, helping engineering leaders and enterprise developers make better decisions about automation, tooling, model strategy, and the future of software teams.

  • 📅 GitHub Copilot Dev Days (September & October) - Dev Days is a global, in-person community-led initiative taking place from September 1st - October 31st, 2026. Join us at a location near you for a community-led developer event focused on AI-assisted coding with GitHub Copilot. These events brings together developers to explore practical workflows, real-world use cases, and hands-on experiences using GitHub Copilot. Whether you are new to GitHub Copilot or already using it, this event will help you better understand how to apply AI-assisted coding techniques in everyday development.

  • 📅 Trust What You Ship: Governance, Security & Code Quality in the Agentic Era (October 22, 11:00 AM — 12:00 PM PDT) - Ensure every line of code meets enterprise standards — human or agent‑authored. As AI writes more code, trust becomes the differentiator. This session covers how GitHub enforces quality, security, and policy across autonomous workflows. You’ll see how Copilot Code Review (CCR), code scanning, autofix, and secret protection work together to raise merge confidence and safeguard production.

  • 📚 AI Coding Tools | For Beginner & Expert Coders - Explains how AI coding assistants use LLMs and NLP to generate, review, and optimize code, and breaks down concrete benefits for junior developers ramping up as well as experienced engineers scaling their output. It is a useful primer for leaders shaping policies around code quality, review rigor, and training as adoption of these assistants grows across enterprise teams.

  • 📚 Machine Learning (ML) in Software Development - Breaks down how ML differs from generative AI and LLMs, then walks through concrete applications—predictive project timelines, automated code review, and early bug detection—that are reshaping how software gets built and shipped. It is a useful primer for leaders weighing where ML-driven automation can measurably improve delivery predictability and code quality without replacing human oversight.

  • 📚 What is retrieval-augmented generation (RAG)? - Explains how RAG grounds LLM responses in retrieved, up-to-date data to reduce hallucinations, outdated knowledge, and weak domain expertise—the core reliability gaps that block enterprise AI adoption. It is a useful primer for teams evaluating how to build more trustworthy, accurate AI-powered developer and support tools.

  • 📚 What Are Multi-Agent Systems? - Lays out when a single AI agent's perceive-reason-act loop breaks down and multiple specialized agents coordinating through shared protocols become the more reliable architecture. It is a practical framework for engineering leaders deciding how to structure increasingly complex agentic workflows without over- or under-engineering the solution.

  • 📚 What is AI code generation? - Covers how AI code generation tools use LLMs to autocomplete, generate from natural-language prompts, and support chat-driven coding, along with GitHub Copilot productivity research showing gains in developer focus and satisfaction. It is a solid primer for leaders building the business case for AI-assisted development while reinforcing that human review of generated code remains essential.

  • 📚 How to improve code quality with code reviews - Build a review practice that catches defects, security risks, and maintainability concerns before merge while reinforcing organizational standards. The guide details roles, checklists, and review models that improve collaboration and make quality scalable.

  • 📚 What is Open Source Software (OSS)? - Walks through the collaboration, transparency, and decentralization principles behind OSS, then translates them into enterprise considerations such as flexibility, avoiding vendor lock-in, total cost of ownership, and community-driven security response. It also compares the MIT, GPLv2, GPLv3, and Apache 2.0 licenses, which is useful grounding for anyone setting policy on how their organization consumes and contributes to open source.

AI & ML - GitHub Copilot

Recent advancements and feature updates for GitHub Copilot, with a particular focus on the GitHub Copilot cloud agent, GitHub Copilot CLI & SDK and the GitHub Copilot app.

GitHub Copilot cloud agent

  • 📢 Project HydraFusion: Frontier quality via multi-model orchestration - GitHub’s new Project HydraFusion hints at the next evolution of AI-assisted software development: instead of forcing developers to choose the “best” model, As the harness, Copilot dynamically orchestrates multiple models to draft, critique, revise, and escalate work behind the scenes, delivering frontier-level coding quality at significantly lower cost. In GitHub’s benchmark testing, HydraFusion matched or exceeded leading single-model performance while reducing workflow costs by up to 67%, suggesting that future gains in developer productivity may come more from intelligent orchestration than from bigger models alone. If you are evaluating AI coding platforms, agentic workflows, or Copilot ROI, this research preview provides an early look at how multi-model systems could reshape the economics, quality, and scalability of enterprise software engineering. See also:

  • 🌐 Satya Nadella’s comments on LinkedIn - Super excited about HydraFusion in GitHub Copilot, and what it shows about the shift from model selection to model orchestration. By bringing together multiple models to plan, build, critique, and complete coding tasks, it can deliver outcomes at up to 67% lower cost. It’s a great example of the value of a heterogeneous model ecosystem, and how we’re continuing to advance the cost-to-outcome frontier.

  • 📺 Introducing Project HydraFusion: multi-model orchestration in GitHub Copilot (1:33) – Learn from Mario Rodriguez, GitHub Chief Product Officer about Project HydraFusion.

  • 📢 How we make AI coding more cost efficient without sacrificing task quality - This post challenges a common assumption in AI engineering: reducing tokens at the individual tool-call level can actually increase overall cost and latency when agents must redo work, retrieve missing context, or take extra turns. Using data from GitHub Copilot’s agentic coding harness and real-world A/B testing, GitHub shows how smarter orchestration, context preservation, prompt optimization, and workflow design can lower costs while maintaining quality, offering practical lessons for anyone building, evaluating, or governing AI-powered developer tools. For engineering leaders and platform teams, the key takeaway is that AI efficiency should be measured by end-to-end task completion and developer outcomes, not by isolated metrics such as token counts.

  • 📢 How to bring your software delivery workflow into GitHub with agent apps - Learn about a sampling of the available GitHub Agent Apps that show how development, security, rollout, observability, and product analytics tools can now participate directly inside GitHub workflows, allowing developers to ask questions, trigger actions, and make decisions without switching between multiple SaaS platforms. In this walkthrough, tools such as Amplitude, Endor Labs, LaunchDarkly, and PagerDuty bring their expertise into issues and pull requests, turning GitHub into a coordination layer for both humans and AI agents across the entire SDLC. If you're responsible for developer productivity, platform engineering, or DevOps modernization, this is an early look at how AI agents and GitHub Agent Apps may reduce context switching, streamline software delivery, and make GitHub the operational hub for your engineering ecosystem.

  • 📅 Orchestrating Agentic Workflows: From Idea to Trusted Production (September 24, 11:00 AM — 12:00 PM PDT) - Explore Agentic Workflows, see how GitHub enables fully agentic, multi‑step software delivery. This session shows how autonomous, repo‑native AI agents build, test, and ship code through a governed, enterprise‑grade workflow. You’ll explore how agents open PRs, how automated review ensures quality, and how GitHub Actions deploys safely — all within clear policy boundaries.

  • 📅 GitHub Demo Days (Every two weeks) - GitHub Demo Days are live, interactive sessions built for developers and tech leaders who want to see GitHub in real workflows—not just slides. Every two weeks, we dive into practical use cases and leave plenty of time for Q&As with GitHub solution engineers. Each session is standalone, so you can join the ones that matter most to you. These sessions are kept intentionally small to enable thoughtful conversations. They tend to fill up quickly, so register today to save your spot.

  • 🚢 Agent Plugins 1.0 in VS Code, Copilot CLI, and the Copilot app - Plugin authors can package skills and MCP servers once and reuse them across major agent clients, while enterprises can govern those plugins with the same managed settings they already use for Copilot.

GitHub Copilot Integrations in Slack and Microsoft Teams

  • 📺 GitHub Copilot in Slack and Microsoft Teams | demo | GitHub Checkout (12:45) - Bring GitHub Copilot directly into your daily team communication. In this episode of GitHub Checkout, Andrea Griffiths and Meagan Cojocar demonstrate how Copilot Cloud Agent works inside Slack and Microsoft Teams. Learn how to create issues, review diffs, render live HTML previews, and analyze repository data without leaving your conversation. Admin setup instructions and enterprise policy requirements are also covered.

  • 📄 GitHub Copilot integrations - This hub brings setup guidance for Slack, Microsoft Teams, Jira, Linear, and Azure Boards into one place. Enterprise teams can use it to connect work conversations and project items directly to Copilot cloud agent while retaining context through pull-request delivery.

  • 🚢 Shared agentic work with GitHub Copilot in Microsoft Teams - Teams conversations can launch shared cloud agent sessions that participants steer together, with secure sandbox execution, cross-surface continuation, budget governance, and an optional additional approval for generated pull requests.

  • 🚢 The new GitHub Copilot experience in Slack - Teams can now collaboratively plan, investigate, and delegate coding work from Slack while retaining GitHub permissions, asynchronous handoff across Copilot surfaces, budget controls, and optional extra review for agent-authored pull requests.

GitHub Copilot app

The GitHub app is the only desktop experience for agent-driven development built natively on the GitHub Copilot CLI. Available for customers on paid GitHub Copilot plans for macOS, Windows, and Linux.

  • 📅 Code Generation Got Fast. Shipping Didn’t. (On Demand) - With the GitHub Copilot app, you can move all of your development workflow into one place. Join GitHub product leaders for a live demo and go from issue to merge in one GitHub-native surface. Find out how automations, Agent Merge, and integrations help reduce repetitive engineering work. Plus, learn ways your organization can confidently scale adoption with GitHub governance controls.

  • 📢 How canvases make agentic workflows visible, steerable, and cost-efficient - As enterprises move from simple AI-assisted coding to agentic software development, chat alone is no longer sufficient for governance, traceability, and scale. GitHub Copilot Canvases provide a durable workspace where teams can visualize workflow state, track agent activity, enforce human approval checkpoints, and reduce the hidden costs of context loss and rework, making AI-driven development more auditable and trustworthy. For engineering leaders and platform teams evaluating agentic workflows, this offers a practical blueprint for turning AI experiments into repeatable, governable, and cost-efficient development processes.

  • 🚢 GitHub Copilot app Customize tab is generally available - MCP servers, plugins, skills, and canvases are now discoverable from one place, making it far easier for teams to find and standardize the customizations that connect Copilot to the tools they already use.

  • 🚢 Content exclusions generally available in Copilot app and CLI - Apply content exclusions across the Copilot app and CLI to keep specified repository content out of Copilot interactions.

NOTE: The engine for the GitHub Copilot app is the GitHub Copilot CLI. See the GitHub Copilot CLI & SDK section for more recent news and updates.

GitHub Copilot app for Beginners

Ready to build faster with AI? 🚀 The GitHub Copilot App for Beginners blog series and YouTube playlist are your step-by-step guides to AI pair programming. Learn how to set up the app, prompt with confidence, and turn your ideas into code.

  • 📢 & 📺 Write your first prompt with the GitHub Copilot app (3:14) - This post explains that getting value from the GitHub Copilot app is less about prompt engineering and more about providing the right context, selecting the appropriate model when needed, and iterating naturally in plain language. It shows how Copilot can work directly against repositories or local projects, making it easier for developers and engineering teams to move from ideas to code changes without mastering a complex workflow first. For enterprise teams evaluating agentic development tools, this is a practical guide to reducing adoption friction and helping developers become productive with AI-assisted software engineering faster.

  • 📢 & 📺 Managing your work (5:24) - As GitHub Copilot evolves from a coding assistant into a parallel work orchestration tool, the My work pane becomes the control center for managing issues, pull requests, review requests, and agent-driven tasks across repositories. See how to build custom views, organize work at scale, and launch Copilot agent sessions directly from issues and PRs, helping developers and engineering leaders understand how to coordinate multiple streams of AI-assisted work without losing visibility or control. For teams exploring agentic software development, this is a practical look at how GitHub is turning Copilot into a workflow management surface, not just a code generation tool, which can significantly impact developer productivity, triage processes, and day-to-day engineering operations.

  • 📢 & 📺 Automate Dependabot pull request triage (4:12) - Turn one of the most common sources of developer interruption, Dependabot pull request review, into an automated daily workflow that evaluates risk, checks CI status, groups updates, and delivers an actionable summary before engineers start their day. By combining natural-language automation with the ability to continue directly into a Copilot session when deeper investigation is needed, teams can reduce maintenance overhead, accelerate dependency updates, and keep developers focused on higher-value engineering decisions instead of repetitive triage work

  • 📢 & 📺 How to run several agents at once (2:39) - This post highlights a fundamental shift in how developers can work with AI agents: instead of waiting for one task to finish, the GitHub Copilot app lets multiple agent sessions run in parallel, each isolated and maintaining its own context. Rather than acting as a single coding assistant, Copilot becomes a team of concurrent workers handling feature development, testing, reviews, and other tasks simultaneously, allowing developers to focus on decisions and code review instead of task orchestration. For enterprise development teams and engineering leaders, this is an early look at how agentic software engineering can increase throughput without increasing cognitive overhead.

  • 📢 & 📺 Using the diff, terminal, and browser (2:54) – See how the GitHub Copilot app brings the entire AI coding validation loop into a single workspace, letting developers review code diffs, run and test applications, and preview UI changes without switching between editors, terminals, and browsers. For enterprise teams evaluating agentic software development, the key takeaway is that AI-generated code can be reviewed, validated, and iterated on with greater transparency and control, helping developers answer three critical questions before merging code: What changed? Does it run? Does it actually work? For engineering leaders, this is a practical example of how agent-based development can scale safely: reducing context switching while increasing confidence, traceability, and human oversight of AI-generated changes before they reach production.

  • 📺 How to build custom workflows with canvases in the GitHub Copilot app (3:27) - What if you could describe your ideal workspace interface and have an AI agent build it in seconds? In episode 7 of our beginner series, discover how canvases in the GitHub Copilot app create fully customizable, bidirectional surfaces for you and your agents. Learn how to use the /create-canvas skill to build release checklists, kanban boards, and triage surfaces using plain English.

  • 📺 How to teach GitHub Copilot about your codebase (6:05) - Every project has its own conventions, scripts, and code style. In episode 8 of our beginner series, discover how to teach the GitHub Copilot app your specific project standards. Learn how to set up custom instructions in your .github folder, create repeatable skills for testing, assign custom agents, and connect MCP servers like Playwright for browser testing.

GitHub Copilot CLI & SDK

  • 📺 Attach images and videos to issues and PRs with GitHub CLI (4:20) - Need to attach proof of work to automated pull requests and bug reports? The GitHub CLI now includes the --attach flag, making it easy to upload screenshots and videos directly to issues, PRs, and comments from the terminal. Watch how an automated Playwright agent sweeps a site for bugs, captures failure screenshots, and attaches before-and-after evidence to a GitHub pull request. NOTE: This also applies to the GitHub Copilot app.

  • 📺 How to build stacked PRs with the gh-stack skill (6:36) - AI coding agents can generate massive amounts of code, which often leads to huge pull requests that are difficult to review. Using the gh-stack skill and GitHub Copilot, you can automatically break down these massive updates into manageable, stacked PRs. In this video, we walk through installing the gh-stack CLI extension and setting up the skill in your environment. Watch as we use a single prompt to create a three-layer stacked PR for easier code review. NOTE: This also applies to the GitHub Copilot app.

  • 📢 Using the GitHub Copilot SDK for Java - Enterprise Java developers can now embed agentic AI directly into their applications without being locked into a specific framework or AI vendor. GitHub Copilot SDK for Java provides a Java-native, framework-agnostic approach that works with Jakarta EE, Spring, OpenAI, Azure, Anthropic, and other model providers, enabling teams to build AI-powered workflows using familiar patterns like annotations, lambdas, virtual threads, and dependency injection. This post provides a practical, production-oriented path that integrates Copilot-powered agents into enterprise architectures while preserving governance, portability, observability, and developer productivity. It moves the conversation from "AI copilots in the IDE" to "AI agents embedded in business applications," which is a significant shift for enterprise software teams.

  • 🚢 Copilot harness generally available in Copilot for JetBrains - This update highlights a significant step toward more enterprise-ready, agent-driven development in JetBrains IDEs by improving code quality, accelerating access to new capabilities, expanding MCP-based workflows, and strengthening reliability across the GitHub Copilot experience.

  • 🚢 Copilot memory and Ollama in GitHub Copilot for JetBrains - JetBrains users gain persistent memory, local model support through Ollama, and better enterprise controls, which can improve both developer productivity and policy alignment in IDE workflows.

  • 🚢 Enterprise managed settings in GitHub Copilot for JetBrains - Central controls for plugins, MCP servers, OpenTelemetry, and permission modes help enterprises give JetBrains users agent capabilities while enforcing approved integrations, telemetry routing, and safety boundaries.

  • 🚢 GitHub Copilot in Visual Studio — August update - This release adds model effort controls, organization-level custom agents, and git-agent review flows so teams can tune reasoning depth, standardize agent usage, and catch issues before opening pull requests.

  • 🚢 GitHub Copilot in VS Code, August 2026 releases - August updates improve session organization, transcript navigation, and review workflows in long-running agent conversations, helping developers coordinate complex tasks with less context switching.

  • 🚢 Enterprise-managed sandbox in Copilot for JetBrains - This update shows how GitHub is strengthening enterprise governance, developer productivity, and AI-assisted workflows by giving administrators deeper control over Copilot behavior while adding project-wide context, cross-file intelligence, IDE/CLI integration, and improved reliability that can impact large-scale development teams.

GitHub Copilot Code Review

  • 🚢 Copilot code review: Resolution reasons and expanded capabilities - The 300 file and 20,000 line review ceiling is gone, bot- and cloud-agent-authored pull requests now get a full agentic review, and resolution reasons let reviewers signal whether a comment was addressed, rejected, or simply wrong.

  • 🚢 Auto-resolution and analysis updates in Copilot code review - For teams scaling AI-assisted code reviews, this update shows how GitHub is improving review accuracy, reducing manual triage, and creating tighter feedback loops that can help developers spend less time managing comments and more time shipping high-quality code.

  • 🚢 Copilot code review can now approve pull requests - In public preview, administrators can selectively let Copilot approvals count toward merge requirements while retaining path-level controls and automatic dismissal after new commits.

GitHub Copilot - New Models

GitHub Copilot supports multiple AI models, each with different strengths. Some prioritize speed and cost-efficiency, while others are optimized for accuracy, deep reasoning, or multimodal inputs. The right model depends on your task. Key reference documents:

Here are the models that have been recently added to GitHub Copilot and related updates.

Additional GitHub Copilot Updates

  • 🚢 GitHub Copilot weekly releases — September 7 - Jira issues flow into Copilot's canvas, HydraFusion routes work across local, cloud, and compound models automatically, VS Code gains scheduled recurring agent tasks, and JetBrains picks up centrally managed sandbox policies.

  • 🚢 GitHub Copilot weekly releases — August 31 - A single cross-product recap of expanded model choice, new content protections, and Visual Studio Code improvements for managing agent sessions and getting pull requests merge-ready.

  • 🚢 GitHub Copilot weekly releases — August 24 - This roundup captures cross-surface updates including shared team sessions, broader customization options, and tighter controls over how Copilot runs across app, CLI, and IDE workflows.

  • 🚢 GitHub Copilot weekly releases — August 10 - The weekly roundup is the fastest way to catch a cross-product view of new models, portable plugins, and smoother agent workflows that landed across Copilot experiences this week.

  • 🚢 Copilot on web expands conversation controls - The update gives github.com users better conversation history and chat controls, making web-based Copilot sessions easier to manage for people who move between multiple active tasks.

  • 🚢 GitHub Changelog - Copilot - Skim through all of the recent Copilot changes.

Security

Application security with GitHub, ensuring the code that lives in GitHub and the dependencies that go into the solutions you build are secure and do not contain any secrets.

Code Security

Secret Protection

  • 🚢 Block pull requests with exposed secrets from merging - Organizations can now enforce a repository governance check that prevents code from progressing when newly introduced secrets remain unresolved, adding a powerful safety net that closes gaps beyond existing pre-commit protections and helps reduce the risk of credential exposure across the software delivery lifecycle.

Supply Chain Security

Additional Security Updates

  • 📚 What is vulnerability scanning? - Learn how continuous vulnerability scanning combines SAST, DAST, IAST, RASP, and dependency analysis to find risk throughout the SDLC. The guide helps teams choose and integrate tools that support earlier remediation, compliance, and protection of critical assets.

  • 📚 What is application security? - Understand how to embed security across design, development, and deployment rather than leaving it as a final gate. This overview connects proactive AppSec practices, such as code, secret, and dependency scanning, to reduced remediation pressure and stronger compliance.

  • 🙋‍♂️ Elevate your learning with 4 new GitHub Skills hands-on exercises - Ready to level up your development game? We’ve just released four new GitHub Skills exercises from June, July, and August designed to help you master the latest in AI-powered workflows and code security with some Hands on Learning!

  • 🚢 GitHub Advanced Security expands trial availability - More GitHub Enterprise Cloud customers can now start a self-serve GitHub Advanced Security trial to evaluate GitHub Code Security and GitHub Secret Protection. Eligibility has expanded from enterprises with up to 100 licenses to enterprises with up to 300 licenses.

  • 🚢 Credential revocation and deauthorization by token type - Incident responders can now revoke or deauthorize a compromised user’s specific credential type at enterprise or organization scope, limiting disruption while preserving audit records and notifying affected users.

  • 🚢 Control GitHub Actions cache access with cache-mode - Least-privilege cache permissions are now generally available and enforced through reusable workflows, closing a cache-poisoning path that most CI setups leave wide open.

  • 🚢 Block users directly from security advisories - Organization moderators can act on spam or abuse without leaving the advisory page, keeping the advisory content intact while removing the disruptive participant.

  • 🚢 GitHub Changelog - Security - Skim through all of the recent security related changes.

GitHub Code Quality

  • GitHub Code Quality is now available in generally available! It turns every pull request into an opportunity to improve. With in-context findings, one-click Copilot fixes, and reliability and maintainability scores, you spend less time chasing nits and more time building. Check out the documentation to learn more.

  • 🚢 Remediate Code Quality findings with agentic autofix - By enabling developers to hand an entire backlog of code quality issues to Copilot for automated fixing, validation, and pull request creation in a single workflow, this update has the potential to dramatically reduce remediation effort while helping engineering leaders scale code quality improvements across the enterprise.

  • 🚢 Track organization Code Quality trends - Organization dashboards now show 7-, 14-, and 30-day finding trends and rank repositories by improvement or deterioration, helping leaders target quality investments where teams need the most support.

  • 🚢 Track GitHub Code Quality enablement changes in the audit log - New audit events identify who enabled, disabled, or reconfigured Code Quality and when, improving governance and helping organizations explain changes to active-committer billing scope.

  • 🚢 Separate GitHub Actions path for GitHub Code Quality - Dedicated workflow and actor identifiers make quality runs easier to distinguish in Actions history and billing reports, though teams must update dashboards or scripts that rely on the previous Code Scanning identifiers.

CI/CD

Continuous Integration & Continuous Deployment with GitHub Actions. If you are involved in managing and authoring GitHub Actions workflows you'll want to dive into these updates to see how were are addressing enterprise needs in the areas of scalability, debugging, security and bringing AI to GitHub Actions with Agentic Workflows and the GitHub Copilot CLI.

Engineering

An inside look at how we’re building the home for all developers. Resources based on our internal experiences.

  • 📢 How to evaluate LLMs before production – There is a hard truth for any team building AI-powered software: strong benchmark scores and offline demos do not guarantee production success. Using GitHub Secret Scanning as a real-world case study, the authors provide a practical framework for evaluating LLM systems against business outcomes, safety guardrails, operational constraints, and production data, showing how disciplined evaluation uncovered risks that aggregate metrics alone would have missed. For enterprise development leaders, the key takeaway is that AI evaluation must become an engineering discipline, not a one-time model test. The lessons on reproducible experiments, production-representative datasets, error analysis, and risk management can help teams avoid costly AI failures while building the evidence needed to confidently move LLM-powered features into production.

  • 📢 & 📺 OpenClaw went viral. Meet the maintainers building and securing it. (46:00) - OpenClaw’s explosive growth shows how AI‑driven contribution models can overwhelm traditional maintainer workflows—and why enterprise teams must rethink how they evaluate trust, review code, and secure their software supply chain. The maintainers reveal concrete lessons on managing agent‑generated pull requests, establishing new trust signals, and hardening dependencies in an era where reputation itself can be an attack surface. If you build or lead enterprise software, this is a real‑world preview of the challenges your own teams will face as AI accelerates contribution velocity beyond human-scale review.

  • 📢 Marketing ops as code: Automating events from planning to follow-up on GitHub - This post shows a practical, end-to-end example of treating business processes the same way developers treat software: capturing work as GitHub Issues, automating it with GitHub Actions, and encoding tribal knowledge as GitHub Copilot skills. Rather than focusing on marketing, it demonstrates a reusable pattern any enterprise team can apply to eliminate repetitive, error-prone workflows using APIs, runbooks, and AI agents while preserving governance, approvals, and security controls. If you're leading software engineering, DevOps, platform, or AI adoption initiatives, this is a compelling blueprint for how "agentic workflows" can turn institutional knowledge into scalable automation without requiring every employee to become a professional developer.

  • 📢 Your alt text passes automated checks. That doesn't mean it's any good. - More than one in four images on the web's most popular pages have alt text that is missing, vague, or duplicated, and conventional scanners pass most of it because they only test that an accessible name exists. GitHub explains how it built a new open source alt text plugin that separates deterministic string checks from an optional model-backed quality review, and why false positives—not missed findings—are what get accessibility tooling switched off.

GitHub Next

GitHub Next investigates the future of software development. We are a team of researchers and engineers at GitHub, exploring things beyond the adjacent possible. We prototype tools and technologies that will change our craft. We identify new approaches to building healthy, productive software engineering teams.

  • 🥼 Chopin - A real-time multiplayer, agentic planning environment - As coding agents make implementation increasingly commoditized, the competitive advantage for software teams is shifting to planning, decision-making, and review. Chopin (prototype) explores a radically different approach: a real-time, multiplayer planning environment where developers, product leaders, and AI agents collaboratively create, debate, research, and document implementation plans with full decision traceability and richer visual communication. For engineering leaders, this offers a glimpse into what post-agent software development may look like: planning as the primary engineering activity, supported by shared AI-assisted workflows rather than isolated "single-player" agent experiences. This research project highlights emerging challenges around collaboration, governance, decision ownership, and auditability that will become increasingly important as AI agents take on more of the coding work.

  • 🥼 WikiKB: a fast, repository-native knowledge base for people and agents - Agent memory that accumulates passively tends to be opaque and muddied across projects, so GitHub Next turned the mostly unused repository wiki into an explicitly curated knowledge base that both humans and agents can read, review in Git history, and query from the CLI, issues, or a skill definition. Indexing and retrieval run locally on the CPU with no LLM provider required, which makes it an interesting option for teams that want durable, auditable project knowledge without shipping content to another service.

  • 🥼 Knowledge Compressor: How far can documentation be compressed without losing its meaning? - GitHub Next’s Knowledge Compressor explores whether technical documentation can be automatically rewritten to use dramatically fewer tokens while still preserving the information AI coding agents need to answer questions accurately. Using an agentic testing approach, the prototype cut documentation size by roughly 50% without significantly reducing usefulness to language models, suggesting organizations may be able to fit more knowledge into AI contexts while lowering inference costs and improving the efficiency of developer workflows.

Legend

This legend represents the icons used above and links each icon to its corresponding resource page. These are the primary sources we review each month when compiling the Monthly Enterprise Roundup. Note that not every resource will appear in every edition.

That’s it for the September '26 edition of the MER. Follow GitHub Enterprise on LinkedIn to see when the next round of key updates become available.

Speakers
Dave Burnison
Dave BurnisonSr. Enterprise Advocate