Over the last six weeks, several decisions about how AI runs inside mid-sized companies quietly stopped being decisions. Nobody voted on them. No project kicked off. The defaults moved, and the defaults are now the policy.
This is not a complaint about vendors, and it is not an argument for slowing down. Sensible defaults are how software should work. But a default is still a decision, and if you cannot say which ones your company is currently living with, someone else has made them for you.
Everything below is dated and taken from the vendors’ own changelogs and documentation. We fetched each page ourselves rather than working from coverage, and we quote the wording directly, because on this topic the exact sentence is the whole point.
A new frontier model can switch itself on
The clearest example ran over five weeks and finished last week.
On 29 July 2026, GitHub announced that for Copilot Business and Copilot Enterprise, “models that become generally available will now be on by default”, with “a single opt-out control for organizations and enterprises that need stricter governance.” A 28-day grace period followed.
On 26 August, the global model policy went generally available: “Starting today, we’re gradually rolling out enforcement of the policy through September 1, so it will take effect at different times for different enterprises.” Unconfigured models would now “inherit the global policy state.”
On 4 September — three days after that enforcement window closed — OpenAI’s newest frontier model went generally available in Copilot. The changelog states the mechanism plainly: “new models are enabled automatically unless an administrator has turned off the global default or explicitly disables this model.”
Read that in the order it actually happened. The policy was announced, enforcement completed, and then the first frontier model arrived into the new regime. If nobody at your company touched that setting in those five weeks, a new model became available to your developers, and the decision was made by nobody making one.
There is a cost sentence in the same changelog that deserves equal attention: the model “is billed at provider list pricing under usage-based billing.” A capability that enables itself can still reach an invoice.
The exclusion list is the interesting part
What does not flow in automatically tells you more about the policy than what does. GitHub’s documentation lists what stays off regardless of your setting: “Pre-GA models”, “Open weight models”, and “models that are not covered by GitHub’s data retention agreement.”
Strip the product names out and a rule appears. What arrives automatically is what the platform has already settled the data question on. Everything with an open commercial or data-handling question is held back and left to you.
That is a defensible design. It also means the automatic path is quietly doing procurement work on your behalf — and doing it to the platform’s risk appetite, which is not necessarily yours. If you operate under contractual data-residency or retention commitments, the fact that a vendor’s exclusion list happens to align with your obligations today is luck, not control.
You may already own a Copilot, and the account decides which one
The second default is the opposite problem: a capability most companies already pay for and do not use.
Microsoft’s licensing documentation is unambiguous: “Copilot Chat is an AI prompt and response experience that’s automatically included and available to organizations that have an eligible Microsoft 365 subscription.” Web-based chat is “automatically included with an eligible Microsoft 365 subscription at no extra cost.” The eligible list is wide — Microsoft 365 E3, E5 and E7, Business Basic, Standard and Premium, Apps for business and enterprise, and the Office 365 plans.
The paid add-on buys something specific rather than access in general: “work-based chat”, which “shows results that the Microsoft Entra work or school account can access”, plus Copilot inside Word, Excel and PowerPoint. The included tier is primarily web data with limited use of organizational content.
And then there is the detail that decides whether any of it reaches your staff. Microsoft’s guidance tells administrators to “instruct them to sign in with their Microsoft Entra account before accessing Copilot via the Microsoft Copilot app, copilot.cloud.microsoft, Copilot Chat in Edge, or productivity apps.” The entry points for someone signed in with a personal account are different addresses entirely — copilot.microsoft.com among them.
Two near-identical domains. One is the work experience your tenant governs; the other is the consumer product. Nobody in your organization is going to notice which one they landed on, and the difference is not cosmetic — it decides whether the conversation sits inside your tenant’s controls or outside them. If you have ever wondered where your shadow AI usage is, this is one of the doors.
Why documents get refused, and why the published limit does not explain it
The third default is the one that generates the most help-desk traffic and the least understanding: a document that is comfortably under the stated limit and still fails.
Start with what actually happens to the file. OpenAI’s documentation says that for PDFs “the API extracts both text and page images and sends both to the model.” Anthropic’s PDF support page describes each page being processed as an image. That single fact undoes the most common assumption about these failures. A scanned document is not automatically rejected for lacking a text layer — the page is being looked at, not just read.
What actually bites is cost per page and where the ceiling sits. Anthropic’s documentation notes that dense PDFs — “many small-font pages, complex tables, or heavy graphics” — “can fill the context window before reaching the page limit”, and states outright that “requests with large PDFs can also fail before reaching the page limit.” The limits also apply to “the entire request payload”, not to the attachment alone, which is why the same file succeeds in a fresh conversation and fails in a long one.
Then there is the hard stop that has nothing to do with size. The documented requirement is a “standard PDF (no passwords/encryption).” Bank statements, signed contracts and a good share of invoices arrive protected by default. Those are refused, and retrying does not help.
The published number is a ceiling, not a guarantee — and a team that does not know that will read every failure as the tool being broken.
The pattern, and why it matters more than any one item
Three unrelated vendors, three different mechanisms, one shape. In each case the behavior is documented, reasonable, and invisible unless somebody goes looking. And in each case the company that has not looked is running a posture it never chose.
This is the same failure mode we wrote about when AI vendors go down: the problem is rarely the technology, and almost always the assumption nobody wrote down. It is why the question of which model is best keeps having a different answer, and why what an AI agent costs is never just the license.
What to check this month
None of this needs a program. It needs about an hour and someone who knows where to look.
- Find your model-enablement setting and write down its state. For Copilot, that is the default availability policy for released models. The answer “we have never opened it” is a finding, not an embarrassment.
- Decide the exclusion question deliberately. If a model would arrive automatically tomorrow, is that acceptable under your data commitments? If you cannot answer, the policy is currently answering for you.
- Check what your Microsoft 365 subscription already includes before buying anything. A material number of companies are paying to pilot a capability that is already on their tenant.
- Look at which address your people actually use. If staff are signing in with personal accounts, your governance stops at the browser.
- Give the document failures an explanation. “Split it, unlock it, send only the pages you need” converts a recurring complaint into a two-minute habit.
- Put a date on all of it. Every item above changed within six weeks and will change again. An undated answer is already decaying.
Where this leads
The work here is not adopting AI. Most mid-market companies already have more AI capability switched on than they have decisions written down about it. The work is closing that gap, and then keeping it closed as the defaults keep moving underneath.
That is the job we do — building the integrations that make these tools do something specific for a business, and holding the technology decisions for companies that need that judgement without a full-time executive. We do not sell any of the platforms above, which is why we can tell you when the honest answer is that you already own what you were about to buy.
If you want a second opinion on which defaults you are currently living with, that is a short conversation and a useful one.