Skip to main content
News

AI That Writes Code Needs Boundaries: GitHub Adds a Sandbox for Coding Agents, and Google Stops Selling Gemini Code Assist

In the first week of October 2026, GitHub let organisations limit what AI coding agents can reach on developer machines and control spending on AI code review, while Google stopped selling Gemini Code Assist Standard and Enterprise. What businesses with in-house or outsourced developers should ask.

10 Oct 20265 minGitHub Changelog
AI Coding AgentGitHub CopilotGemini Code AssistSoftware SecurityAI GovernanceSoftware Development

Say your company hires a software team, or has its own IT team that has started using an AI coding agent to write and fix code. That agent can run commands on a developer's machine, read files and reach the internet.

The question is what it can see. Database passwords, cloud access keys, or another client's code sitting on the same machine?

In the first week of October 2026, two of the largest vendors made changes that bear directly on that question.

GitHub lets organisations limit what coding agents can reach

On 7 October 2026, GitHub made local sandboxing generally available in Copilot CLI, the GitHub Copilot app and VS Code sessions using Agent Host. It works on Windows, macOS and Linux and is included with Copilot at no additional cost.

The sandbox controls what commands run by the agent can do:

  • which files and folders they can read or change
  • whether they can reach the internet or local networks
  • whether they can use Git and GitHub CLI credentials
  • how far they can reach local services such as MCP servers, where supported

For organisations, the key point is that enterprise administrators can require sandboxing for everyone and set policies developers cannot weaken. Control no longer depends on each person being careful.

Organisations can now control AI code-review spending

The next day, 8 October, GitHub added an option for organisations to pay for Copilot code review instead of using each member's quota. It requires AI Credits paid usage, and a budget can be set.

A second setting blocks review requests made with a Copilot licence from outside the organisation, such as a developer's personal licence. That helps when outside contractors work on company code: the owner knows the code goes through accounts the organisation controls.

A local model is not automatically private

GitHub also let Copilot CLI, from version 1.0.94-0, discover models running locally through Ollama. GitHub is clear that choosing a local model does not turn on offline mode and does not disable telemetry. If a remote provider is still configured, prompts and code context can still go out over the network.

Organisations choosing local models to protect their code need to check the settings themselves, rather than assume "local" means safe.

Google stops selling Gemini Code Assist for organisations

From 9 October 2026, Google no longer sells new Gemini Code Assist Standard or Enterprise subscriptions. Existing customers keep their service until the end of their contract:

  • licences can be added until 31 January 2027
  • annual plans can auto-renew until 31 January 2027
  • monthly plans can renew until 31 December 2027

Google says agentic coding will be available through Antigravity, included in Gemini Enterprise, and recommends planning the move before the final renewal.

The lesson goes beyond Google. Developer AI tools change names, bundles and prices quickly. Teams that tie their workflows or client proposals to a single product need to review those commitments regularly.

Questions to ask your developers or vendor

Whether you have an in-house team or an outside vendor, this week's news gives you questions you can ask today.

  1. Which AI coding agents does the team use, and are they used on our code?
  2. How far can an agent reach files, credentials, the network or production systems, and who decides?
  3. Is that policy enforced at the organisation level, or left to each developer?
  4. Does our code go through accounts the organisation controls, or through someone's personal licence?
  5. If a tool vendor changes its bundle or stops selling, what is the plan?
  6. Is pay-per-use AI spending budgeted, and does someone own it?

A team that answers every question clearly is using AI under control. A vague answer is a reason to ask more.

What Enersys does

We have built and run business software for 14 years. If your organisation is setting a policy for using AI on company code and data, or wants a second opinion on whether your developers use AI with enough control, talk to the Enersys team.

Sources

"Empowering Innovation,
Transforming Futures."

Contact us to make your project a reality.