GitHub Copilot’s September 4 wave: GPT-6 Astra GA, Agent Merge preview, and how to govern the new model lanes
On September 4, 2026 GitHub made GPT-6 Astra generally available in Copilot and published a weekly release that expands Fable 5.1 and Gemini 3.8 Flash access while putting Agent Merge into public preview. This guide covers what changed and how enterprises should enable the new agentic coding lanes.
In this post (8 sections)
Introduction
Model launches only become operational when they land in the tools developers already use. September 4 moved GPT-6 Astra from OpenAI’s platform story into GitHub Copilot’s day-to-day coding surfaces, while VS Code’s Agent Merge preview pushed agents further into the merge-ready pull request loop. That combination changes both capability and governance.
This guide is for platform engineering, AppSec, and engineering managers who own Copilot policy. Primary sources: GPT-6 Astra in Copilot and Copilot weekly releases. Pair with GPT-6 Astra Critical cyber routing.
What GitHub shipped on September 4
GPT-6 Astra in Copilot
- Positioned for long-horizon autonomous coding and agentic tasks.
- Available to Copilot Pro+, Max, Business, and Enterprise (not the base Copilot plan).
- Surfaces include VS Code, Visual Studio, JetBrains, Xcode, Eclipse, Copilot CLI, coding agent, github.com, Copilot app, and Mobile.
- Gradual rollout; Business/Enterprise model policy can disable Astra or turn off automatic new-model enablement.
- Billed at provider list pricing under usage-based billing.
Weekly Copilot and VS Code agent updates
- Claude Fable 5.1 available to Pro+, Max, Business, and Enterprise.
- Gemini 3.8 Flash rolling out to Pro through Enterprise.
- Content exclusions honored in Copilot app and CLI for agentic workflows.
- Copilot harness generally available in JetBrains.
- Agent Merge public preview in VS Code 1.136: resolve review feedback, failed checks, and merge conflicts.
- Experimental multi-root workspaces and chat-session hierarchy for agent attention management.
Why Astra-in-Copilot is a governance event
OpenAI classifies GPT-6 Astra at Critical cybersecurity capability under its Preparedness Framework. GitHub’s Copilot changelog does not invent a separate cyber gate, so enterprise control must come from Copilot model policy, repository permissions, content exclusions, and sandbox discipline. Treating Astra like any other model picker option is the wrong default.
How to place Astra, Fable, and Flash on one Copilot board
| Lane | Model | Suggested use |
|---|---|---|
| Premium long-horizon | GPT-6 Astra | Hard multi-step coding agents; admin-gated |
| Claude planner/coding | Claude Fable 5.1 | Long-running Claude-quality coding where Copilot hosts Claude |
| High-volume worker | Gemini 3.8 Flash | Faster cheaper iteration and broad Pro+ coverage |
| Merge assistant | Agent Merge preview | PR cleanup under human review, not silent production merges |
Developer implications
- Expect model-picker fragmentation during gradual rollout. Document which SKU is approved per team.
- Use content exclusions before enabling agentic Copilot app/CLI workflows on sensitive paths.
- Pilot Agent Merge on low-risk PRs first; keep humans accountable for final merge.
- Measure steps-to-done and human edit rate, not only acceptance rate, when comparing Astra to prior Copilot models.
Business implications
- Usage-based Astra traffic can move Copilot spend quickly toward frontier list prices.
- Admin model policy is now a first-class security control, not a convenience setting.
- JetBrains harness GA reduces IDE fragmentation for enterprises standardized outside VS Code.
- Agent Merge increases throughput and also increases the blast radius of incorrect automated PR edits.
Enablement checklist
- 01Freeze default model enablementTurn off automatic new-model enablement in Copilot Business/Enterprise until the review finishes.
- 02Decide Astra eligibilityLimit Astra to a named pilot group with Critical-cyber awareness and repository allowlists.
- 03Confirm exclusions and secrets hygieneVerify content exclusions cover Copilot app, CLI, and coding agent paths.
- 04Pilot Agent Merge separatelyRun on non-critical repositories with required human approval before merge.
- 05Publish the lane boardDocument when to use Astra vs Fable 5.1 vs Gemini 3.8 Flash, including cost owners.
Conclusion
September 4 moved frontier agentic coding deeper into GitHub Copilot. Astra raises capability and cyber stakes. Agent Merge pushes agents into the last mile of pull requests. Enterprises that combine model-policy gates, content exclusions, and explicit lane ownership will capture the productivity gain without turning Copilot into an uncontrolled Critical-cyber endpoint.
Sources: github.blog ; github.blog
Agentic AI patterns, delivered Thursdays
What I am shipping, watching, and pruning out of client stacks each week. One email. No fluff.