Some weeks in this industry are about capability. This was not one of them. Almost everything that shipped between 3 and 8 August was a control: a policy, a limit, a permission, or a measurement.
That is a more interesting signal than another model release. Vendors build governance features when their customers have moved from experimenting to depending, and the shape of the controls tells you which failures are now common enough to be worth building against.
Wednesday 6 August — three at once
GitHub shipped three things on the same day, and they are unrelated on the surface and closely related underneath.
- Kimi K3 became available in Copilot across Pro, Pro+, Max, Business and Enterprise and every surface from VS Code to GitHub Mobile — off by default for Business and Enterprise, and billed by usage at $3 per million input tokens, $15 per million output, $0.30 per million cached input
- MCP allowlists reached general availability in enterprise managed settings: `allowedMcpServers` and `deniedMcpServers` in `copilot/managed-settings.json`, matched by URL, local command or label, enforced today on the Copilot app, the Copilot CLI and VS Code, and failing closed
- Organizations can now cap how many open pull requests a user without write access may have at once, set once under Organization Settings > Moderation Tools > Interaction Limits
Friday 7 August — review, apps, and a dashboard that talks about money
GitHub's Friday batch was about what happens after the code is written.
- Copilot code review effort levels went GA with two levels, Lite and Balanced, renamed from Low and Medium — selectable per review or as an organization default, and now recorded on the pull request itself
- Enterprise owners can install public third-party GitHub Apps on the enterprise account; those installations reach the enterprise account but not the organizations or repositories inside it, and apps holding the enterprise-organization installation permissions cannot be installed across enterprise boundaries
- The Copilot impact dashboard gained a potential return on investment section, with cost per developer per month derived from actual AI credit consumption and a salary selector for modelling — GitHub is explicit that these are estimates, not payroll data
Anthropic: a safety system, retuned in public
Also on 7 August, Anthropic published an update to Claude Fable 5's biology safeguards. Fable 5 had launched with almost all biology queries blocked because of dual-use concerns; the update cuts biology-related fallbacks — silent routing to a weaker model — by roughly 85% across its product surfaces.
The stated targets are everyday cases: interpreting lab results, understanding symptoms, learning biology, and clinical work by healthcare professionals. The policy has not changed; the calibration has.
The pattern underneath
Read those together and one theme runs through all of them: somebody has to be accountable for what an agent did, and until this week the tooling for that was thin.
An MCP allowlist answers "what could it reach". A recorded effort level answers "how carefully was this checked". A PR cap answers "how much attention can one contributor consume". An ROI section answers "what did this cost, against what". A published false-positive reduction answers "how often is the safety layer wrong". Every one of those is a question you only ask about a system you already depend on.
The capability race has not stopped — Kimi K3 makes five model vendors inside one Copilot subscription, ten days after Grok 4.5 made it four. But capability is now the easy part to buy, and the constraint has moved to whether an organization can say, afterwards, what happened and why.
What to do with this week
If you only act on one thing, make it the MCP inventory. It is the item with the widest gap between "how much access exists" and "how much anybody has written down", and the allowlist is useless until you know what is running.
- Enable — or deliberately decline — the Kimi K3 policy rather than leaving it unanswered, and read the token pricing before you make it a default
- Inventory your MCP servers, then write the allowlist; remember it does not reach JetBrains or non-Copilot agents yet
- Set Lite as your code review default and inherit Balanced only where mistakes are expensive
- Look at the ROI section, and treat the salary selector as a modelling input rather than a finding