
Two changelogs landed on September 25 that make an accidental but useful pair. Claude Code v2.1.283 shipped a set of enterprise controls for restricting which models an organization’s fleet is allowed to run. The same day, GitHub’s own weekly Copilot changelog added four more models to Copilot’s roster: Claude Opus 5.5, GPT-6 Sol, GPT-6 Luna, and Grok 4.7. One release is about narrowing model choice with precision. The other is about maximizing it. Read together, they’re a clean snapshot of where the two products actually differ now that everyone ships everyone else’s frontier models within days of launch.
What Claude Code added#
The headline items in v2.1.283 are two new managed settings aimed squarely at enterprise admins, not individual developers:
deniedModelsblocks specific models outright, even if a broaderavailableModelspolicy would otherwise allow them. An org can permit “any Claude model” in general while still hard-blocking one specific release it hasn’t cleared for a regulated workload.availableModelsMatch: "exact"pins anavailableModelsentry to the exact version it names — a new model release stays blocked by default until an admin explicitly adds it to the list, rather than silently becoming available the moment it ships.
Paired with those is /doctor prompt-audit (also /checkup prompt-audit), which scans a project’s CLAUDE.md files, skills, agents, and commands for prompting patterns written for older models — catching the kind of stale, model-specific instruction that quietly degrades output after a default-model change. And a new x-claude-code-prompt-id gateway hint header lets LLM gateways group every request that serves a single user prompt, useful for cost attribution and observability at fleet scale.
None of this is flashy. All of it is aimed at the same problem: once an organization is running Claude Code across hundreds of engineers, “which model answered this prompt” stops being a developer preference and becomes a compliance and cost-control question. This is a direct continuation of the governance thread this blog has tracked all September — maxEffortLevel capped reasoning depth per org three weeks ago, and scoped allowed_domains narrowed network access per command two weeks before that. deniedModels and exact-version pinning are the same instinct applied to model selection itself. It also arrives three days after Claude Opus 5.5 became the default Opus model in Claude Code (v2.1.280, Sept 22) — exact-match pinning is precisely the tool an admin would reach for if they wanted last week’s default to stay the default a little longer.
What Copilot added#
GitHub’s weekly release runs on a different axis entirely. Four models — Opus 5.5, GPT-6 Sol, GPT-6 Luna, and Grok 4.7 — became selectable across Copilot’s paid tiers (Sol restricted to Pro+/Max/Business/Enterprise; the other three reach as low as base Pro). Alongside the model additions: local sandboxing for the Copilot app agent, limiting file, network, and credential access, now in public preview; JetBrains “assisted approvals,” which auto-approve low-risk tool calls during agent sessions, also in public preview; message editing with automatic file rollback; and VS Code 1.139 adding agent execution inside Dev Containers over SSH, Tunnel, and WSL.
The model additions themselves are unremarkable in isolation — every major coding tool adds new frontier models within a week or two of launch now, and OpenAI’s own GPT-6 Sol and Luna only shipped September 22. What’s more interesting is the sandboxing and assisted-approvals features, because they’re Copilot visibly reaching for the same territory Claude Code staked out months ago: scoped, low-friction permission handling instead of an all-or-nothing approve/deny prompt on every tool call. It’s a real, worth-acknowledging convergence, not a hollow catch-up move — this blog has been consistently critical of IDE-anchored tools’ autonomy ceiling, and it would be dishonest to pretend Copilot standing still.
The actual differentiator has moved#
The old argument for picking a coding agent — “which model does it run” — has almost fully dissolved. Copilot, Cursor, and Claude Code all now offer some version of Opus 5.5, the GPT-6 family, and Grok 4.7 within days of each other. Model access has become a commodity layer that every serious tool has to match, the same pattern this blog has tracked through GitHub’s HydraFusion multi-model router and Copilot’s JetBrains/Ollama governance push.
What doesn’t commoditize as easily is the governance layer wrapped around that access — who gets to run which model, at what reasoning effort, against which network endpoints, with what gets audited afterward. That’s the argument this blog has made about Claude Code’s harness all year, and September’s changelog is a month of evidence for it in miniature: effort caps, domain scoping, and now model pinning, three distinct admin controls shipped inside three weeks, each solving a problem that only shows up once an agent is trusted with real production access. Copilot’s answer to the same pressure is breadth — give every user every model, then start layering permission controls on top, JetBrains-approvals-first. Both are legitimate bets. But “our agent can use GPT-6 now” stopped being news the day every other agent could say the same thing; the fleet-governance controls are where the actual competition is happening now, and that’s the terrain Claude Code got to first.
Sources: Claude Code changelog (v2.1.283, Sept 25, 2026); GitHub Copilot weekly changelog, Sept 25, 2026; OpenAI DevDay 2026 / GPT-6 Sol and Luna launch.
