AI Dev Pulse–2026-09-26

At a glance

  • Claude Code v2.1.283 can allow models only at the exact versions you list, block specific models with deniedModels, and audit stale prompting with /doctor prompt-audit.
  • GitHub's enterprise AI controls page now validates Copilot managed settings and names the file and JSON path behind each error.
  • Copilot usage metrics now time three pull request review stages, and agentic autofix reads and stores Copilot Memory.
  • Google Cloud API Gateway can serve MCP from your OpenAPI 3.x spec in preview, but discovery stays open until you secure it with a JWT.

Saturday is a consolidation day rather than a launch day, because this week’s models are already in the pickers and no new model shipped overnight. What did land is the machinery that decides which models a developer can reach and whether the policy saying so actually applies, so the useful weekend work is checking that your controls say what you think they say.

Treat today as the day you pin the Claude Code model list to exact versions, prove every policy file parses before you trust it, and start collecting review-stage metrics while there is still a before picture to capture.

Top Stories

Claude Code v2.1.283: new models stay blocked until you list them

Practical dev impact: Claude Code v2.1.283 (25 Sep, 5:50 PM ET) adds the managed setting availableModelsMatch, and with the value "exact" each availableModels entry allows only the model version it names, so a new release stays blocked until someone approves it on purpose instead of reaching developers the day it ships. The companion deniedModels setting blocks specific models outright, so a shop can keep a broad allowlist and still carve out the one model it has not cleared. The new /doctor prompt-audit command looks for prompting habits written for older models, and gateway operators get an x-claude-code-prompt-id header, a mantle upstream and an opt-in load_test_mode, alongside a batch of MCP and plugin fixes. For change control, managed sandbox settings with an invalid value now fail closed instead of being ignored, and the Windows PowerShell tool can no longer delete drive roots. The default that moved is permission mode, since interactive sessions on third-party providers or with telemetry off now start in auto mode when no permission mode is configured, so set one explicitly if your team relies on prompts. Pin laptops and images to v2.1.283 and decide whether "exact" belongs in managed settings before the next model lands.

Copilot gets a settings validator, review-stage timing and autofix with memory

Practical dev impact: GitHub’s 25 Sep changelog adds a Copilot settings validation section to the enterprise AI controls page that checks your managed settings and team mapping files and reports each error with the affected file and JSON path. A file that does not parse is a policy that is not enforced, and the fix loop is short, since you commit the correction to the default branch of your .github-private repository and read the validator again. The usage metrics API also gained a pull_request_review_times array on repos-1-day rows, with median and p90 times for three review stages between ready for review and merge. Only human reviews count, there is no backfill before 21 September, and a quiet day returns an empty array rather than a zero, so the baseline exists only if you start collecting it now. Agentic autofix now reads and stores Copilot Memory as well, so the fix patterns it creates can inform Copilot code review and cloud agent, and both features remain in public preview. Clear the validator to zero this weekend, schedule a daily download of the repos-1-day report, and have someone own the autofix memories.

Google Cloud API Gateway turns your OpenAPI spec into an MCP server

Practical dev impact: Google’s 24 Sep post puts API Gateway in public preview as a remote MCP server, so instead of running a separate server that duplicates your routing, auth and quotas, you annotate the OpenAPI spec you already deploy and the gateway serves MCP on the /mcp path. It requires OpenAPI 3.x, so a 2.0 spec has to migrate first, operations that return HTTP 204 are not exposed, a gateway tops out at 1,000 tools, and MCP and model routing cannot share one API config. The limit to fix before production is discovery, because tools/list is open by default and API keys cannot secure it, which means anyone who finds the URL can read your tool list until you put a JWT on that method. Start with one low-risk read endpoint.

Microsoft Copilot Code and Copilot in Slack and Teams: agent work from outside the IDE

Practical dev impact: Microsoft’s 25 Sep announcement adds Code to the Copilot app, a sandboxed experience powered by the same underlying technology as GitHub Copilot that can be hosted in your tenant, together with a Copilot Managed Runtime in preview, a Frontier rollout at the end of the month and usage-based billing. Microsoft says developers keep using GitHub Copilot, but code will start arriving from people who never open a repo, and engineering inherits the ownership questions. GitHub’s public preview of Copilot in Slack and Teams also added per-thread model switching, a duplicate-issue check, a link back to the source conversation and, in Slack, safer repository switching, with usage billed against existing Copilot entitlements. Ask your Microsoft 365 admins who owns what gets built in Code, and if Copilot runs in your Slack, set default owners and repositories so its work lands where reviewers look.

What did not move, so you do not chase it

Practical dev impact: Codex v0.157.1 posted overnight (9:02 PM ET, 25 Sep), but its release notes say the highlights could not be determined, so there is nothing to act on. Gemini CLI stable is still v0.61.0 from 23 Sep while v0.62.0 exists only as a preview alongside nightlies, so CI should stay on stable, and Cursor’s changelog has nothing newer than its 23 Sep Rollouts and Security Review entry. In CI, GitHub Actions workflow run queries now report “2,500+” past 2,500 matches, with pagination up to 1,000 items, so scripts that trust the count should add a date range.

Practical Impact Analysis

The through-line is that the week’s model choices are made, and what remains is making sure the rules around them hold. A Claude Code allowlist that is not pinned to exact versions can admit the next release before anyone approves it, while a Copilot managed settings file with one malformed entry can quietly fail to apply, so both of today’s controls exist to close the gap between the policy you wrote and the policy that runs. Exact matching and the validator belong in the same hour, because each turns a silent failure into something you can see.

The second thread is where agent work comes from. MCP is becoming an annotation in a gateway spec rather than a service someone runs, and code is starting to come out of an office suite, so the things that can call your APIs grow without a new repo appearing. The response is not to block it but to put a JWT on discovery and know who owns what the Managed Runtime hosts.

The review-stage metrics tie it together, because they are the only item today that measures outcomes rather than setting rules. If the agent tooling is paying off, time to first review should shrink, and since there is no backfill, only a download started this weekend gives you a before picture.

Tutorial

Lock the Claude Code model list and prove your policy files parse. About fifteen minutes. Steps first, then one block that needs only bash and jq.

  1. Upgrade Claude Code to v2.1.283 or later on every machine the policy will reach.
  2. Draft the model section of your Claude Code managed settings with the exact versions you approve under availableModels, set "availableModelsMatch": "exact", and list anything you want blocked under deniedModels. In the block below, your-approved-model-id and your-blocked-model-id are placeholders you must replace with real model ids.
  3. Check that the file parses and exact matching is on, then deploy it through your usual managed settings channel.
  4. From a checkout of your .github-private repository, run the same parse check on the Copilot files before you commit, then reload the Agents page on the enterprise AI controls page and confirm Copilot settings validation reports no errors. The block writes claude-models.json into the current directory, so if you run it from .github-private, delete that file or leave it out of your commit.
  5. If you have downloaded a repos-1-day usage report as repos-1-day.json, pull out the review-stage arrays to start your baseline.
  6. Inside Claude Code, run /doctor prompt-audit on the repo you ship most.
bash Tutorial
#!/usr/bin/env bash
# Lock the Claude Code model list, then prove the policy files parse.
set -u

# Review copy of the model section of your Claude Code managed settings.
# Replace both placeholder ids with the exact model versions you approve and block.
cat > claude-models.json <<'JSON'
{
  "availableModels": ["your-approved-model-id"],
  "availableModelsMatch": "exact",
  "deniedModels": ["your-blocked-model-id"]
}
JSON

# Parses, exact matching on, at least one denied model

... click "Show full code" below to expand
▸ Show full code (39 lines)
#!/usr/bin/env bash
# Lock the Claude Code model list, then prove the policy files parse.
set -u

# Review copy of the model section of your Claude Code managed settings.
# Replace both placeholder ids with the exact model versions you approve and block.
cat > claude-models.json <<'JSON'
{
  "availableModels": ["your-approved-model-id"],
  "availableModelsMatch": "exact",
  "deniedModels": ["your-blocked-model-id"]
}
JSON

# Parses, exact matching on, at least one denied model
if grep -q 'your-' claude-models.json; then
  echo "EDIT claude-models.json: replace the placeholder ids first"
elif jq -e '.availableModelsMatch == "exact" and (.deniedModels | length > 0)' claude-models.json >/dev/null; then
  echo "OK   claude-models.json"
else
  echo "FAIL claude-models.json"
fi

# Copilot files: run from a checkout of your .github-private repo
for f in copilot/managed-settings.json copilot/team-mappings.json copilot/teams/*.json; do
  if [ -f "$f" ]; then
    jq empty "$f" && echo "OK   $f parses" || echo "FAIL $f (fix before commit)"
  else
    echo "SKIP $f not found in $(pwd)"
  fi
done

# Optional: review-stage baseline from a downloaded repos-1-day report
if [ -f repos-1-day.json ]; then
  jq -s '[.[] | .. | .pull_request_review_times? // empty] | flatten' repos-1-day.json
fi

# Inside Claude Code (interactive):
#   /doctor prompt-audit

You are done when Claude Code reports v2.1.283, every file prints OK, and the AI controls page shows no validation errors.

Recommended AI prompt

Copy this paragraph into ChatGPT, Claude, Gemini, Grok, or whatever AI you use.

You are a staff engineer helping me run a policy-proofing Saturday for one team. I will paste our Claude Code managed settings, the Copilot settings validation output from our enterprise AI controls page, a sample of the pull_request_review_times array from our repos-1-day usage report, and a note on whether we use Google Cloud API Gateway, Microsoft 365 Copilot, or Copilot in Slack or Teams. Using only what I paste, tell me for Claude Code v2.1.283 which exact model versions to list with availableModelsMatch set to "exact", what belongs in deniedModels, and whether we need an explicit permission mode; for Copilot, which validator errors to fix first by file and JSON path and which of the three review stages looks like our bottleneck; for API Gateway, whether tools/list still needs a JWT and which read endpoint to expose first; and for Microsoft Copilot Code and Copilot in Slack or Teams, the ownership questions to send our admins. Skip Codex v0.157.1, Gemini CLI nightlies and Cursor unless I ask, keep your first reply to that checklist, do not invent settings, endpoints or model ids I did not give you, and wait for my paste before expanding.

Recommended AI prompt

Explore each Top Story in Grok. Links open in a new tab. On phones, the same link may open the Grok app if you have it installed (via your device's normal link handling).

Article: AI Dev Pulse–2026-09-26

Privacy: links open grok.com in your session only. AIDevPulse does not run your prompts through our API.

2 thoughts on “AI Dev Pulse–2026-09-26”

Leave a Comment