Turning on automatic PR reviews takes one click. Who pays and whose request triggers them is not decided at that moment. GitHub's October 8 Copilot code review change puts both in org admins' hands: billing review costs to the organization instead of burning personal quotas, and blocking AI review requests made with external personal licenses on org repos. AI adoption has moved past personal subscriptions into team billing and access control.
Who pays: from member to organization
The first setting is named Choose how members with a Copilot license are billed. Find it under org settings Copilot > Policies — per current docs, next to Org Settings > Copilot > Code review. Enterprises see it in Enterprise > AI controls > Copilot code review.
Member (default):
billed against the member's own Copilot entitlement
→ review fails when the personal quota runs out
Organization:
billed to the org that owns the repository
→ manual and automatic reviews both land on the org
Enterprise owners get three options:
Member / Organization / Let organizations decide
Two cautions. It changes billing only; it grants no access by itself. And org billing needs AI Credits paid usage enabled for the org. Budgets are optional, but without one there is no ceiling. Member-billed usage stops at the user budget; org-billed usage stops with other AI-credits features when the org, cost-center, or enterprise spending limit is exhausted.
Default attribution helps debugging too. Auto reviews attach to the PR author, manual requests to the requestor. Copilot coding-agent PRs attach to the human co-author first, else directly to the org; other bots and bot-requested reviews attach to the org directly.
For cost intuition: 1 AI credit is $0.01, a Business seat ($19/mo) is 1,900 credits, an Enterprise seat ($39/mo) is 3,900 pooled credits. A typical review runs Lite $0.05–$1, Balanced $0.25–$5, plus a little GitHub Actions time. Balanced became the default on September 28, so check review effort first when last month looks expensive. Like the cost-per-successful-task post argues, judge cost per successful review, not per call.
Locking the door: blocking external licenses
The second setting is Only allow Copilot code review to be triggered by authorized users. Orgs set it in Org Settings > Copilot > Code review; repos in Repo Settings > Copilot > Code review. Default is OFF — anyone with a paid Copilot license can request reviews in repos they can access.
Before (default OFF):
anyone holding a paid license can request a review
After (ON):
requests with an external license (not provided by the owning org/enterprise —
personal or another org's license) do not start reviews
→ Copilot not offered as reviewer, API requests no-op
→ personal-settings auto reviews do not run for unauthorized people
→ but repo/org ruleset auto reviews still run
Personal repos: owner or direct collaborator only
Inheritance: org ON cannot be undone by repo admins (most restrictive wins)
Teams where outside contributors ran AI reviews on org repos with personal Pro will see that path close the moment this turns on. Welcome news for security and cost; advance notice for open-source-style teams borrowing outside hands.
Note that letting unlicensed members use reviews is a separate matter needing two more policies: AI credits paid usage plus allowing members without a license to use Copilot code review on GitHub.com. This release focuses on billing attribution for licensed members and external-license gating.
CodeBridge Mini Lab: permissions, frequency, budget, failure handling
Turn the briefing's action item into an operating spec. When adopting automatic PR reviews, define four things together:
1. Permissions: external-license gate ON/OFF
- if leaning ON: confirm personal-repo exceptions, ruleset auto reviews survive
- test: reviewer visibility for an external account + API no-op
2. Frequency: auto-review scope + effort (Lite vs Balanced)
- keep the Balanced default, or park small repos on Lite?
3. Budget: org, cost-center, user budgets + stop-at-limit
- stopping is OFF by default — decide before overflow
- settle billing attribution (Member vs Organization)
4. Failure handling: who does what on personal-quota or budget exhaustion
- retry owner and notification path for failed reviews
- monitor: Actions metrics filtered on copilot-pull-request-reviewer,
billing reports on workflow_path = dynamic/agents/copilot-pull-request-reviewer
Leave these four boxes empty and AI review stays a "great when it works" feature. The Git primer and the agentic workflows post help place review automation inside the development flow.
Conclusion: the unit of AI review is the org, not the PR
One line to summarize.
Team adoption succeeds on who holds the invoice and the guest list, not on one review's quality.
The era of limping along on personal quotas is over. Teams that pay centrally, filter external requests, and document budgets and failure handling keep AI reviews for years. Open the two org settings today. Where the billing-attribution and external-gate switches sit now tells you your team's AI operating level.
Further reading
- Measuring AI agents by cost per successful task
- Git in practice, safely — primer
- GitHub agentic workflows through queues and ledgers
References
- GitHub Changelog: Copilot code review billing options and controls (Oct 8, 2026)
- GitHub Docs: About code review — usage and billing
- GitHub Docs: Configure Copilot code review
- GitHub Docs: Budgets for usage-based billing
Go deeper with a course
Once you have attached Agent and Plan modes to a real Java and Spring project through implementation and testing, review frequency, budgets, and failure handling design the same way. To use AI coding beyond autocomplete, start here.