Skip to content
Innovation & Growth

GitHub's Copilot sandbox lets companies limit what AI agents can reach

GitHub says its boundary can limit files, network and credentials on a developer's machine, whichever model runs

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
GitHub's Copilot sandbox lets companies limit what AI agents can reach
In brief
  • GitHub says local sandboxing for Copilot is generally available in its CLI, app and VS Code Agent Host sessions, with rules for files, network and credentials.
  • GitHub states that the sandbox applies to tool execution whichever model Copilot uses, so choosing a local model is not a substitute for it.
  • Ask your engineering leads which rules are enforced today, whether developers can weaken them, and what the sandbox covers.

A master key or a visitor badge

Giving an AI agent a developer's laptop is like handing a contractor a master key. Every door opens, including ones nobody meant to open. A sandbox trades that key for a visitor badge. The badge opens only the doors on a list.

On October 7, GitHub said local sandboxing for Copilot is generally available. It ships in the Copilot command-line tool, the Copilot app, and VS Code sessions that run on Agent Host. When Copilot starts a program, that program can now run inside a fence, under rules the developer or company sets. The fence limits its reach into files, network, credentials and other system features.

3
Operating systems covered
Source: GitHub changelog (October 7, 2026): Windows, macOS and Linux

How the fence works

GitHub says the feature runs on Microsoft eXecution Container, or MXC. MXC takes one shared policy. It turns that policy into the built-in controls of Windows, macOS or Linux. A company writes its rules once, not three times.

GitHub lists what the rules can do. They can limit which files and folders a command may read or change. They can decide whether a command reaches the internet or the local network. They can also govern use of stored Git and GitHub CLI logins. Local MCP and language servers can sit inside the fence too, where supported. MCP is a standard that lets AI tools connect to other software.

Companies can lock this on. GitHub says managed settings can require the sandbox. Developers then cannot loosen the rules their company enforces. The feature costs nothing extra with Copilot.

3
Copilot surfaces with the sandbox now generally available
Source: GitHub changelog (October 7, 2026): Copilot CLI, Copilot app, VS Code sessions using Agent Host

The model is one question. The tools are another.

Many executive talks about AI and code focus on the model. Which one? Where does it run? GitHub's announcement points elsewhere. It says: "Model execution and tool isolation are separate concerns." The fence applies to tools whichever model Copilot uses.

A second GitHub update that day shows why. From Copilot CLI version 1.0.94-0, the /model command can find models on a running local Ollama instance. Ollama is a tool for running models on your own machine. A developer must still pick a model and confirm it.

Picking a local model leaves two things unchanged, GitHub says. Offline mode stays off, and GitHub telemetry keeps running. Offline mode is a separate switch, set with COPILOT_OFFLINE=true. Even with that switch on, prompts and code context can still go to a remote provider.

1.0.94-0
Copilot CLI version that adds local model discovery
Source: GitHub changelog (October 7, 2026)

So a local model changes where the thinking happens. It does not change what the agent's commands can reach.

This is the lesson for leaders. An agent's risk comes from what it may do on a machine that holds source code and credentials. The sandbox limits that. It is a separate decision from the choice of model.

What the announcement does not say

The changelog is short. It does not say which rules are on by default. It does not explain how a company can check enforcement. It does not say how to review what a sandbox blocked. Support for local MCP and language servers applies "where supported," and the list is not given.

These gaps do not undercut the feature. They are questions to settle before relying on it.

Questions to put to your engineering leads

First, is the sandbox required through managed settings, or left to each developer? Second, what do the file, network and credential rules allow today, and who approved them? Third, which MCP and language servers do developers run, and are they inside the fence? Fourth, if a team adopts local models, has anyone checked what still leaves the machine?

GitHub says the feature lets teams adopt more autonomous agent workflows while keeping clear limits on what Copilot can access. That is GitHub's claim. Your own policy decides whether it holds for your teams.

A visitor badge only helps if someone wrote the list of doors with care.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: GitHub.

Share this insight