日本語 ← Back to home
AI Tools

GitHub Copilot App and CLI Now Respect Content Exclusions

On September 2, 2026, GitHub made content exclusions generally available in the Copilot app and Copilot CLI. Exclusion policies set by enterprise, organization and repository administrators are respected when the tools s

Article ID: TC-0035 Published:

On September 2, 2026, GitHub made content exclusions generally available in the Copilot app and Copilot CLI. Exclusion policies set by enterprise, organization and repository administrators are respected when the tools select context.

This matters because AI coding agents may examine many files while working on a task. Preventing selected files from being used as context helps teams apply existing governance policies to agent workflows.

WHAT CHANGED: GitHub made content exclusions generally available for the Copilot app and CLI. Coding agents can inspect several files while working on a task, so the context they receive matters. The change extends administrator-defined exclusions to these additional workflows rather than introducing a new way to restrict repository access.

CONTEXT EXCLUSION VERSUS ACCESS CONTROL: A content exclusion policy prevents selected material from being used as Copilot context. It does not remove a file from the repository or change whether an authorized developer can read it. Organizations should distinguish controls over information supplied to AI from controls over human and application access.

CONSISTENCY ACROSS INTERFACES: Developers may interact with Copilot through an application or a command-line workflow. The user interface differs, but the underlying information governance requirements remain. Supporting exclusions in both places makes it easier to apply a consistent organizational policy.

DECIDING WHAT TO EXCLUDE: Confidential design documents, restricted implementations and files subject to contractual limits may warrant protection. Excluding too much material can also deprive an agent of context needed to make a correct change. Teams should identify their actual information risks rather than treat every file identically.

ADMINISTRATIVE RESPONSIBILITY: Policies can be managed at enterprise, organization and repository levels. Teams need to understand which settings apply to a project and who is responsible for maintaining them. Clear ownership reduces confusion when multiple groups contribute to the same codebase.

AGENT WORKFLOWS: A coding agent may inspect related files beyond the one a developer explicitly mentions. When exclusions remove relevant context, suggestions may become incomplete or require additional human guidance. Generated changes still need testing and review, including checks for missing dependencies or assumptions.

NOT A SECRET-MANAGEMENT SOLUTION: If an API key or password has been committed, excluding its file from Copilot context does not resolve the underlying exposure. Credentials may need to be revoked or rotated, and repository history may require separate handling. Dedicated secret scanning and secure storage remain important.

COMPLEMENTARY PERMISSIONS: Restricting AI context does not determine who can clone or browse a repository. Organizations handling sensitive code should combine exclusions with repository permissions, review processes and appropriate auditing. Each control addresses a different route through which information may be exposed.

TESTING THE CONFIGURATION: Administrators can begin with a controlled repository and verify that expected exclusions are respected in both the app and CLI. They should document the policy, notify developers and provide a way to report unexpected behavior. Configuration changes deserve periodic review.

ELIGIBILITY: GitHub identifies Copilot Business and Copilot Enterprise as the relevant offerings. Teams should not assume identical policy controls exist in every individual subscription. Current requirements and administrative settings should be checked in official documentation.

THE PRODUCTIVITY TRADE-OFF: Protecting more files can reduce the context available to the model. Developers may have to provide permitted explanations or perform additional manual checks. Organizations should measure both information protection and the impact on task completion and review effort.

WHAT TO WATCH: As AI coding tools move from autocomplete toward multi-file agent tasks, governance of context becomes increasingly important. Content exclusion is a useful layer, but it cannot replace access controls, secret management or security review. Effective protection requires these measures to work together.

The capability is available to Copilot Business and Enterprise customers. Content exclusion is one layer of protection, not a substitute for access controls, secret management and security reviews.

Source

GitHub Changelog ↗