GitHub Rewrites Copilot Core in Rust with Copilot

GitHub rewrote Copilot's core—800,000+ lines—in Rust using its own agents. Analysis: what this means for control, MCP, and model selection in business.

  • What happened
  • What the Rust rewrite proves
  • What lies behind the words “agents wrote most of the code”
  • Control catches up with capability

What happened

  1. GitHub announced that the agent engine powering Copilot CLI, the Copilot application, and the Copilot SDK was rewritten from TypeScript/Node.js/V8 to Rust—more than 800,000 lines of production code.

  2. Copilot performed the rewrite itself: agents wrote most of the code.

  3. At the same time, a batch of ecosystem changes was released: automatic closure of code review comments, enterprise-level allowlists for MCP servers, access to Claude Opus 5 in Copilot, and the transition of GitHub MCP Server to a new protocol.

  4. Each of these events is routine on its own.

  5. Together, they show that AI tools in development have moved from the demo phase to the infrastructure phase, where they face production-level requirements.

What the Rust rewrite proves

  1. Companies have used LLMs for years to autocomplete lines and create small patches, while keeping the core of their systems—anything that cannot be broken without harming thousands of users—outside the agents’ reach.

  2. The logic is clear: an agent that confuses types or loses context during a long task is unacceptable in a runtime serving millions of requests. GitHub removed this limitation in its own most critical component.

  3. The agent runtime is what every call from Copilot CLI, the application, and the SDK passes through. Rust was chosen for a reason: the language catches memory-ownership errors and data races at compile time, requiring a level of code discipline that is difficult to fake.

  4. Rewriting 800,000+ lines from TypeScript to Rust while keeping the runtime operational was a task that, just two years ago, would have been assigned only to a senior team for several quarters.

What lies behind the words “agents wrote most of the code”

This is where the principle applies TTU - time to use: the value of a tool is not how intelligent it is on a benchmark, but how much time passes from task definition to a working result. GitHub got a working Rust runtime through a process built around the model: planning, breaking work into subtasks, review cycles, and reverting failed attempts.

This is simple is not easy: the end result looks like “press a button, get Rust”

, but in reality it means months of engineering work on the harness, tests, and validation process that make agent output production-ready.

Assess where AI can deliver impact in your process

Control catches up with capability

Alongside the rewrite, GitHub strengthened the governance layer

Auto-resolution in Copilot code review now closes its own comments when a developer makes a change and writes smart commit messages; Lite-mode reviews are now handled by an ensemble of agents instead of a single process. Enterprise administrators also received `allowedMcpServers` and `deniedMcpServers` in managed settings—a centralized allowlist/denylist of MCP servers for the entire organization rather than manual configuration by each developer.

This is a direct consequence of scale: as soon as an agent writes production code rather than suggestions, the question becomes “which MCP servers is the agent authorized to trust”

stops being theoretical

Access management is becoming part of perimeter security, not an IDE setting. In our work on projects with LLM & Security Gateway, this is exactly where clients ask us to define which models, tools, and data are visible to the agent before it is granted commit access.

The model and protocol move beyond the experimental phase

Claude Opus 5 is available in Copilot Pro+, Max, Business, and Enterprise as a model for long, multi-step coding tasks involving planning and tool use. This makes model selection for a specific task class an operational decision: a short edit requires one model, while a multi-hour agent session requires another. Meanwhile, GitHub MCP Server moved to a new version of the MCP protocol: it is sessionless, and parameters are passed through HTTP headers instead of batch parsing.

A protocol that is just over a year old has already received a stateless revision for industrial workloads—a sign that MCP is becoming a lasting standard for integrating agents with tools.

What This Means for Business

For an executive budgeting for AI in development, the Copilot rewrite provides a concrete benchmark: agent tools can already take responsibility for code that cannot be fixed manually at 3 a.m. The condition is a harness around the model: a review process, an allowlist of tools, and model selection by task class.

Companies that are adopting Anthropic Claude, MCP, and AI-native development without this process layer will see more incidents. Results—or you are out of the game: GitHub demonstrated the result on its own critical code. The question for everyone else is whether they have a process that can make this safe.

Discuss the article: GitHub rewrote Copilot’s core in Rust…

Enter your email or phone number so we can get back to you.

Send via: