- GitHub says local sandboxing for Copilot is generally available in its CLI, app and VS Code Agent Host sessions, with rules for files, network and credentials.
- GitHub states that the sandbox applies to tool execution whichever model Copilot uses, so choosing a local model is not a substitute for it.
- Ask your engineering leads which rules are enforced today, whether developers can weaken them, and what the sandbox covers.
A master key or a visitor badge
Giving an AI agent a developer's laptop is like handing a contractor a master key. Every door opens, including ones nobody meant to open. A sandbox trades that key for a visitor badge. The badge opens only the doors on a list.
On October 7, GitHub said local sandboxing for Copilot is generally available. It ships in the Copilot command-line tool, the Copilot app, and VS Code sessions that run on Agent Host. When Copilot starts a program, that program can now run inside a fence, under rules the developer or company sets. The fence limits its reach into files, network, credentials and other system features.
How the fence works
GitHub says the feature runs on Microsoft eXecution Container, or MXC. MXC takes one shared policy. It turns that policy into the built-in controls of Windows, macOS or Linux. A company writes its rules once, not three times.
GitHub lists what the rules can do. They can limit which files and folders a command may read or change. They can decide whether a command reaches the internet or the local network. They can also govern use of stored Git and GitHub CLI logins. Local MCP and language servers can sit inside the fence too, where supported. MCP is a standard that lets AI tools connect to other software.
Companies can lock this on. GitHub says managed settings can require the sandbox. Developers then cannot loosen the rules their company enforces. The feature costs nothing extra with Copilot.
The model is one question. The tools are another.
Many executive talks about AI and code focus on the model. Which one? Where does it run? GitHub's announcement points elsewhere. It says: "Model execution and tool isolation are separate concerns." The fence applies to tools whichever model Copilot uses.
A second GitHub update that day shows why. From Copilot CLI version 1.0.94-0, the /model command can find models on a running local Ollama instance. Ollama is a tool for running models on your own machine. A developer must still pick a model and confirm it.
Picking a local model leaves two things unchanged, GitHub says. Offline mode stays off, and GitHub telemetry keeps running. Offline mode is a separate switch, set with COPILOT_OFFLINE=true. Even with that switch on, prompts and code context can still go to a remote provider.
So a local model changes where the thinking happens. It does not change what the agent's commands can reach.
This is the lesson for leaders. An agent's risk comes from what it may do on a machine that holds source code and credentials. The sandbox limits that. It is a separate decision from the choice of model.
What the announcement does not say
The changelog is short. It does not say which rules are on by default. It does not explain how a company can check enforcement. It does not say how to review what a sandbox blocked. Support for local MCP and language servers applies "where supported," and the list is not given.
These gaps do not undercut the feature. They are questions to settle before relying on it.
Questions to put to your engineering leads
First, is the sandbox required through managed settings, or left to each developer? Second, what do the file, network and credential rules allow today, and who approved them? Third, which MCP and language servers do developers run, and are they inside the fence? Fourth, if a team adopts local models, has anyone checked what still leaves the machine?
GitHub says the feature lets teams adopt more autonomous agent workflows while keeping clear limits on what Copilot can access. That is GitHub's claim. Your own policy decides whether it holds for your teams.
A visitor badge only helps if someone wrote the list of doors with care.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: GitHub.





