Todos los artículos

The Real Lesson From GitHub's PR Ads Debacle

31 de marzo de 2026

#AI#Software Engineering#GitHub#Devops#cybersecurity
The Real Lesson From GitHub's PR Ads Debacle

On Monday morning, a developer named Zach Manson opened a pull request and found something unexpected: Copilot had inserted an ad for Raycast into his PR — not a PR Copilot created, but his own. A coworker had mentioned Copilot in the thread to fix a typo. That was enough for Copilot to decide it had write access to Manson's PR description.

11,400 PRs got the same treatment before GitHub killed the feature that afternoon.

This would be bad enough as a one-off. But it follows a pattern. GitHub also recently switched Copilot training to opt-out — even for paid accounts! Paying customers now have to actively go disable their code being used as training data. That's two decisions in rapid succession where GitHub leadership chose to take first and ask later. The PR ads got rolled back because the backlash was immediate and public. The training default change? Still in place.

That's two decisions in rapid succession where GitHub leadership chose to take first and ask later.

The community reaction was telling. Developers were angry — but not primarily about the ads. Manson's own framing said it plainly: "Initially I thought there was some kind of training data poisoning or novel prompt injection." His first instinct was security incident. Full stop. That's the signal.

When your agent acts without permission, it looks like a breach.

GitHub Copilot had a reasonable feature for PRs it creates. Copilot creates the PR, Copilot adds tips. Clear ownership, clear authority. The logic break happened when Copilot gained the ability to act on any PR it's mentioned in. Nobody updated the authority model to match the expanded capability.

The agent got new powers. The boundaries stayed the same.

This is a design challenge in AI-native systems: capability and authority are not the same thing. Your agent can technically do a lot of things. What it's authorized to do — and in whose name — is a completely separate question that requires explicit architecture decisions.

Most teams I talk with are deep in capability. They're integrating agents into pipelines, giving them file access, hooking them into APIs, letting them write code and open PRs. The tooling is maturing fast. Anthropic just launched Claude Cowork — give it your filesystem, queue up tasks, let it work in parallel while you're doing something else. The capability story has never been stronger.

The authority model is usually an afterthought. (See some of my recent writings on jai and other sandboxing tools.)

The Trust Deficit Is Cumulative

GitHub fixed this in half a day. But the 11,400 developers who found ads in their PRs now have a different relationship with Copilot. Trust erodes fast and rebuilds slowly. One poorly scoped agent action creates a shadow of suspicion over every future agent action — including legitimate, useful ones.

GitHub fixed this in half a day. But the 11,400 developers who found ads in their PRs now have a different relationship with Copilot. Trust erodes fast and rebuilds slowly.

And this is where GitHub leadership needs a hard look in the mirror. Developers understood that intuitively, even if they couldn't articulate it clearly. PR ads, opt-out training defaults, assumed consent on paid accounts — these are executive decisions. Someone in leadership signed off on each one. Someone at GitHub is consistently choosing to extract value from the developer base rather than earn permission first. That approach has a shelf life.

The Bottom Line

We're in a moment where AI tooling is shipping faster than the mental models for governing it. Every engineering leader needs to be asking "what can this do?" and "what has this been authorized to do, in whose name, and with what audit trail?"

Capability without authority architecture is how you get ads in your PRs. Or worse.

GitHub leadership: developers are watching. Every default you flip to opt-out, every agent boundary you expand without consent, every assumption that the installed base will just absorb the change — it all compounds. The goodwill GitHub spent twenty years building is not an infinite resource. Stop treating it like one.