
Models expire, workers move inside: AI coding tools shipping Aug. 28–Sep. 4
A practical scan of Aug. 28–Sep. 4 releases across Copilot, Cursor, Claude Code, Kiro, and Devin, with the policy, execution, and budget checks each change calls for.
The qualifying releases in this issue fall between August 28 and September 4, 2026. The cutoff is 10:00 a.m. Pacific on September 4. GitHub Copilot changed its model catalog, approval path, and enterprise controls; Cursor moved agent execution into customer-managed machines; Claude Code tightened several session boundaries; Kiro synchronized cloud configuration across surfaces; and Devin turned code scans into recurring work.
Engineering leads can scan the table first, then use the review action attached to each release to decide whether the change belongs in a pilot, a policy review, or a budget model.
The week in one view
| Tool and release | Date | What changed | Why it matters | First review action |
|---|---|---|---|---|
| GitHub Copilot: model lifecycle | Sep. 1–3 | Gemini 3.8 Flash and Claude Fable 5.1 became available. GitHub also announced October 2 deprecations for Gemini 3.5 Flash, Gemini 3.6 Flash, Kimi K2.7 Code, and Claude Opus 4.7. 123 | Teams must test replacements before a hard retirement date, while availability and retention policies differ by model. | Inventory model use and set an owner for the October 2 migration. |
| GitHub Copilot: review approvals | Sep. 1 | Copilot code review can submit an approval when an administrator enables it. The feature is off by default and can be controlled at enterprise, organization, and repository levels. 4 | An AI assessment can enter the repository’s required-approval path, which changes the separation between automated review and merge authority. | Enable it only on selected repositories and test path restrictions and dismissal after new commits. |
| GitHub Copilot: enterprise model and billing controls | Aug. 31–Sep. 3 | Enterprise-managed settings can assign a default model, billing organizations now determine model access for users with multiple Team seats, and Business/Enterprise signups are reopening with upfront seat charges for credit-card and PayPal customers. 567 | Model choice, policy ownership, and seat cash flow now meet in the same administrative path. | Review inherited defaults, the "Usage billed to" organization, and the October 1 billing change. |
| Cursor self-hosted machines | Sep. 2 | Cloud Agents can run tool calls on machines inside a team’s network. Cursor supports personal machines and pooled workers, including capacity that connects and disconnects as work arrives. 8 | Code, build outputs, and secrets can remain on internal machines while the team still uses a cloud-agent workflow. | Test a non-sensitive repository with secrets, build artifacts, worker ownership, and reconnect behavior. |
| Claude Code 2.1.251–2.1.260 | Aug. 28–Sep. 3 | The releases added model-switch hooks, spend visibility, managed MCP servers, unattended permission controls, a restricted mode, a Fable 5.1 default, and changes to plugins, runners, Remote Control, and diff workflows. 9 | A version upgrade changes the permission and session lifecycle, not just the command-line interface. | Canary the range with managed settings, MCP, restricted mode, Remote Control, and a self-hosted runner. |
| Kiro 1.0.437 and cloud sessions | Sep. 1–3 | Cloud configuration and synced Powers appeared in the IDE, while Kiro Web and cloud sessions became generally available on paid plans. Cloud sessions can continue after a local disconnect and resume from another surface. 1011 | Configuration, agent execution, and session ownership can cross the IDE, CLI, browser, and mobile surfaces. | Test configuration precedence, administrator enablement, and cross-device resume on a disposable repository. |
| Devin code scans | Aug. 28–Sep. 2 | Devin added a cleanup scan type, a /scan command, scan agents for Automations, severity thresholds that require validation, scan history with profile and cost, and richer MCP approval cards. 12 | A one-off review can become scheduled background work with a visible cost and an explicit approval boundary for connected tools. | Schedule one low-risk scan and review finding thresholds, repeat triggers, and MCP scopes before broad rollout. |
GitHub Copilot: model changes now come with a retirement date
GitHub Copilot added Gemini 3.8 Flash on September 3. The model is available to Pro, Pro+, Max, Business, and Enterprise users, with a gradual rollout across Visual Studio Code, Visual Studio, Copilot CLI, cloud agent, Copilot app, JetBrains IDEs, Xcode, and Eclipse. GitHub says the model will use introductory provider pricing under usage-based billing through December 31, 2026. Enterprise and Business administrators can control access through the Copilot model policy. 1
The release arrives beside a deadline. GitHub will deprecate Gemini 3.5 Flash, Gemini 3.6 Flash, Kimi K2.7 Code, and Claude Opus 4.7 across Copilot Chat, inline edits, ask and agent modes, and code completions on October 2. GitHub lists Gemini 3.8 Flash, Kimi K3, and Claude Opus 5 as suggested alternatives. Business and Enterprise administrators may need to enable those alternatives in their model policies. 3
Claude Fable 5.1 became generally available in Copilot on September 1 for Pro+, Max, Business, and Enterprise users. The model is selectable across the Copilot app, CLI, coding agent, web and mobile surfaces, and supported IDEs. GitHub says the model is billed at provider list pricing under usage-based billing. Business and Enterprise administrators must enable its policy, and the policy acknowledges Anthropic’s data-retention requirement. GitHub also describes a time-bound zero-data-retention exemption for eligible enterprises while Anthropic rolls out Enterprise Frontier Safeguards. 2
The migration task has three separate checks. First, find every workflow that names a retiring model instead of relying on a model label that may silently move. Second, test the suggested replacement in the client and plan that will run it. Third, verify data-retention and model-policy settings for teams that handle regulated or proprietary code. A model swap that passes a coding benchmark can still fail an organization’s policy review.
Copilot can now approve a pull request
Copilot code review gained a public-preview approval path on September 1. Every Copilot review now includes an approval assessment in its overview comment. When an administrator enables approvals, Copilot can submit an approval that counts toward the repository’s required-approval rule. New commits dismiss that approval in the same way they dismiss a human approval. Enterprise, organization, and repository administrators can control the feature, and repository administrators can restrict the file paths Copilot may approve. 4
The first pilot should keep the approval separate from an unrestricted merge path. Use a repository with a narrow file allowlist, create a pull request that needs a new commit after review, and check whether the approval disappears. Then test who owns the final merge requirement when Copilot’s assessment says a pull request is ready.
The administrator now owns more of the model path
Enterprise-managed settings can set a preferred default model for new Copilot conversations. An enterprise can also mark the model setting as overridable and assign different defaults through team mappings. The feature is generally available in the Copilot app, Copilot CLI, and Visual Studio Code for Business and Enterprise. 5
GitHub also changed model access for Team users who hold seats in more than one organization. The organization paying for usage now determines the available models. The relevant organization appears under "Usage billed to" in the Copilot features page. Users whose access comes entirely through an enterprise are unaffected by this particular change. 6
The administrative test is to compare three views of the same developer: the enterprise default, the team mapping, and the billing organization. A model that appears in one organization’s policy may disappear when another organization pays for usage. Teams should record the intended default and the billing owner as separate fields in their rollout checklist.
GitHub is also gradually reopening Copilot Business and Enterprise signups for customers paying by credit card or PayPal. New seat assignments require payment before access. Existing customers will receive an upfront charge for assigned seats at the start of the next billing cycle, including October 1, 2026. Included usage may be prorated, and additional payment may be required after the included allowance is exhausted. GitHub says plan pricing and seat proration are unchanged. 7
Procurement should model assigned seats and usage separately. The base seat price does not describe the full bill for a team that uses agentic workflows heavily.
Cursor: self-hosted workers move execution into the team’s network
Cursor’s September 2 release adds self-hosted machines to Cloud Agents. A self-hosted machine keeps the agent’s tool execution inside the organization’s network. Cursor says the codebase, build outputs, and secrets can stay on internal machines while the agent handles tool calls through that worker. Cursor supports a personal machine connection and team pools of workers. Pools can grow as workers connect, shrink as they disconnect, and hibernate idle machines until they reconnect. 8
The feature leaves the team with two separate boundaries to test. The worker controls where commands, files, and secrets are handled. Cursor still controls the cloud-agent session and the surrounding product workflow. A self-hosted worker therefore changes the execution location without removing the need to review session permissions, outbound connections, logs, and source-control access.

Cursor lists support for cloud-agent execution on infrastructure including AWS Lambda, Coder, Cloudflare, Daytona, Modal, Namespace, Vercel, and E2B. Self-hosted workers support computer use on Linux and Mac. The release also describes team pools as queues that are independent of a single repository. 8
A first pilot should use a non-sensitive repository. Run a build that produces a known artifact, ask the agent to read a test secret, disconnect a worker during a session, and reconnect it. The results should answer four questions: which machine ran each tool call, where the generated files remained, who could claim an idle worker, and what happened when the worker disappeared.
Claude Code: the upgrade changes the whole session lifecycle
Claude Code shipped versions 2.1.251 through 2.1.260 between August 28 and September 3. The changelog is a sequence of dated entries rather than one feature launch, but several changes belong in the same upgrade review because they affect model choice, permissions, plugins, runners, and remote sessions. 9
Version 2.1.251 added
PreModelSwitch and PostModelSwitch hooks, a spend-limit bar in /usage, a rate_limits.spend_limit status-line field, and per-session prompt-cache information in /cost. The release also changed the default model for seat-based Enterprise subscriptions to Opus 5 and made CLAUDE_CODE_SUBAGENT_MODEL a default rather than a forced model for every subagent. 9Version 2.1.257 added Claude Fable 5.1 as the default Fable model, with a 1-million-token context window. It also added a containment-escape rule for cloud metadata credentials, egress evasion, and cross-tenant reach; a one-time prompt before the first file read outside the working directory; session-only effort control; and a forced subagent-model environment variable. 9
Version 2.1.259 added managed HTTP and SSE MCP servers,
--permission-prompts none for unattended headless hosts, JSON output for plugin validation, and GitLab merge-request recognition for glab mr commands. The same release changed how allowedMcpServers applies to user-added servers and made Claude Code refuse to start when a managed-settings source cannot be parsed. 9Version 2.1.260 added a fullscreen
/diff panel, /reload-plugins for headless sessions, and a text form of /advisor for desktop, Remote Control, and headless sessions. It also fixed permission rules for parenthesized paths, plugin marketplace installs, invalid Remote Control model picks, and self-hosted runner shutdown behavior. 9The canary should follow a session from start to shutdown. Pin a model, switch models through the new hooks, connect a managed MCP server, run with restricted permissions, install a managed plugin, resume the session remotely, and stop a self-hosted runner. A startup check will miss the changes that matter during a long session: cache behavior, credentials, permission prompts, plugin trust, and recovery after disconnects.
Kiro: cloud configuration follows the agent across surfaces
Kiro IDE version 1.0.437, dated September 1, added cloud configuration behavior, synced Powers, and reliability fixes for Agent Focus. When cloud configuration is enabled for an account, personal Steering, custom agents, Skills, Powers, and Hooks become available from their usual IDE surfaces. Cloud-managed Steering, Skills, and Hooks open as read-only previews with an "Edit in web" action. Synced Powers appear in the installed list, where users can try the bundled Skills and MCP configuration. 10
Kiro also announced general availability for Kiro Web and cloud sessions on September 3. The paid-plan feature is available in US East (N. Virginia), uses shared credits without a separate cloud-compute charge, and supports SSO through AWS IAM Identity Center, Okta, or Microsoft Entra ID. Administrators can enable Kiro Web and cloud sessions with a single console toggle. 11
A cloud session runs Kiro’s agent harness in a managed sandbox instead of on the developer’s machine. The session continues after a local disconnect and can resume from a browser, IDE, CLI, mobile device, or another computer. Kiro describes use cases that include implementation, refactors, dependency migrations, browser reproduction with Playwright, and pull or merge requests across GitHub and GitLab. 11
The new operating question is configuration precedence. Kiro says project configuration travels with the repository, while local files take precedence where local and cloud configuration overlap. The IDE shows which items are managed in Kiro Web, but the editing path for cloud-managed items moves to the web surface. 1011
Test the same repository from the IDE, CLI, and web. Change one instruction locally and one in cloud configuration, then observe which instruction reaches the agent. The test should also cover an administrator disabling the feature and a developer resuming a session from another device.
Devin: code scans become recurring work
Devin’s August 28 and September 2 release notes add a code-scan path that can run once or on a schedule. The September 2 update adds a cleanup scan type, a
/scan composer command, a code-scan agent type for Automations, and a redesigned findings tab. Scan profiles can set which finding severities require validation, and scan history records each run’s profile and cost. 12The same release window adds richer trigger details for GitLab, Jira, incident.io, and GitHub automations. Devin also warns Slack users outside the session’s organization when their replies cannot reach Devin. The August 28 notes add MCP marketplace entries for Gmail, Google Calendar, Gamma, and Supabase, while approval cards show server identity, source, and resolved scope before installation. 12
A scheduled scan turns code quality work into a resource policy. The important settings are the scan profile, the severity threshold, the trigger, and the person who reviews the finding. Run one cleanup scan against a low-risk repository, record the cost and false-positive rate, and then decide whether a recurring trigger saves enough review time to justify its spend.
Coverage notes
The Windsurf JetBrains plugin changelog still shows version 2.12.27, dated August 17, as its latest dated entry. No dated Windsurf JetBrains release falls inside August 28–September 4. 13
Aider’s official release history currently begins with an undated
main branch section and supplies no date that places a concrete release inside this window. Continue.dev’s accessible releases page still shows June 19 as its latest visible release date. Neither source provides an in-window, date-verifiable release for this issue. 1415Review before next Friday
- Copilot: Assign owners for the October 2 model retirements. Test Gemini 3.8 Flash and Claude Fable 5.1 under the intended plan and data-retention policy. Set explicit enterprise defaults, verify the billing organization for Team users, and model the October 1 seat charge with usage-based spending.
- Cursor: Run a self-hosted-machine canary with a disposable repository. Record the worker identity, secret boundary, build-artifact location, source-control permissions, and reconnect behavior.
- Claude Code: Treat versions 2.1.251–2.1.260 as one operational upgrade. Test model switching, spend limits, managed MCP, restricted mode, plugin confirmation, Remote Control, and runner shutdown.
- Kiro: Decide which Steering, Skills, Hooks, and Powers belong in cloud configuration. Test local-versus-cloud precedence and cross-surface session resume.
- Devin: Run one scheduled cleanup scan. Compare cost, finding severity, validation rate, and the time a human spends triaging the results.
- Windsurf, Aider, and Continue.dev: Keep monitoring their official release surfaces; this window produced no date-verifiable release for those three tools.
The week’s releases connect through a concrete change in pilot design. Model catalogs now carry migration deadlines, agent execution can move into customer infrastructure, and code scans or approvals can run with scheduled or repository-level authority. Capability testing and the policy that surrounds the capability need to be planned together.
Fuentes de referencia
- 1Gemini 3.8 Flash in GitHub Copilot
github.blog
- 2Claude Fable 5.1 in GitHub Copilot
github.blog
- 3Upcoming Copilot model deprecations
github.blog
- 4Copilot code review approvals
github.blog
- 5Enterprise-managed Copilot default models
github.blog
- 6Copilot model access for Team plans
github.blog
- 7
- 8Self-hosted machines in Cursor
cursor.com
- 9Claude Code changelog
code.claude.com
- 10Kiro 1.0.437 cloud configuration
kiro.dev
- 11
- 12Recent Devin updates
devin.ai
- 13Windsurf JetBrains plugin changelog
docs.devin.ai
- 14Aider release history
aider.chat
- 15Continue.dev releases
github.com
Este contenido lo produjo un canal automáticamente. Con una sola frase, Neodrop puede seguir produciendo para ti.
