GitHub Copilot Is Going Local. Does That Mean Your Code Stays on Your PC?
Microsoft’s local Copilot plans raise a practical question: what stays on your computer? Here’s how offline mode, model endpoints and sandbox permissions differ.

You choose a local AI model, open a private project and assume the code stays on your laptop. It is a reasonable assumption—and one worth checking before you hand over the repository.
Microsoft’s October 7 announcement brings local models into the GitHub Copilot story, with automatic local/cloud routing planned by the end of the month. The important question for developers is what happens after the model starts answering. Reading a file, installing a package and calling a remote service are separate actions with separate permissions.
Local inference describes where the model runs. It does not, by itself, describe everything the assistant can access or send.
What Microsoft actually announced
In its local-model announcement, Microsoft describes automatic routing and explicit model selection across Copilot’s app, CLI and VS Code. Its on-device MAI Code 1.1 Flash implementation targets hardware including NVIDIA RTX Spark Windows PCs.
The reported footprint is substantial: 53GB for the quantized model, with peak memory usage of 75.5GB at 256k context in Microsoft’s measurements. Those are vendor results, not our tests or a universal minimum specification. The announcement also distinguishes a local model from an entirely offline session.
For the hardware side, our Surface Laptop Ultra explainer covers the memory proposition. Here, the more useful question is how to check where your work goes.
Three questions to ask before sharing a repository
Where is the model? Identify the selected provider and endpoint. A model’s name is not enough: the same family can be offered through different services. If your requirement is on-device processing, an automatic routing option needs closer inspection than a fixed, verified local endpoint.
What can the tools reach? Think about the job you assigned. A request to explain an existing function might need only file reads. A request to update dependencies may require downloads, installation scripts and changes to a lockfile. Those tasks deserve different permissions, even when the model is identical.
What does the surrounding application contact? Model calls are only one possible connection. Account services, telemetry and integrations need their own configuration review. Treat a claim of offline operation as something to verify across the complete workflow.
Copilot CLI has an explicit offline mode—with a condition
GitHub’s CLI authentication documentation describes COPILOT_OFFLINE=true. It says this mode prevents contact with GitHub’s servers, skips GitHub authentication and disables telemetry. Requests to the configured model provider remain possible.
That last point matters. A remote provider is still remote, even when the CLI is in offline mode. GitHub says a fully isolated setup requires a local provider or one inside the same isolated environment. This setting is documented for the CLI; do not assume it configures the desktop app or VS Code.
If you have already configured a supported local provider, the environment setting in PowerShell is:
$env:COPILOT_OFFLINE = "true"
copilot
This is an offline-mode switch, not a complete installation recipe. It does not download a model, select the right endpoint or configure every tool the agent may run. Check your provider configuration first. For a simpler introduction to models on your own computer, see our Ollama beginner’s guide.
A sandbox is a permission boundary, not an unplugged cable
Microsoft’s Execution Containers announcement describes policies enforced outside the agent’s control. These can restrict files, network destinations and other resources. Different containment backends offer different levels of isolation.
It also distinguishes enforcement from observation: MXC’s Permissive mode records activity that a policy would reject while allowing it to proceed. Learning mode blocks ungranted operations and records them. A log of attempted access is therefore not, on its own, proof that access was prevented.
The distinction is practical. Imagine asking an assistant to review ten fictional customer records. You want an explanation, not an upload. A policy that records an outgoing request would help you investigate afterward; a policy that blocks the destination could prevent that request. Decide which behavior the task requires before running it.
Five settings worth checking in the Copilot app
GitHub’s sandbox configuration guide says app and CLI settings are separate. For the app, review these controls:
- Enable the sandbox. Under Settings, select the project and turn on Sandbox new sessions. GitHub documents it as off by default unless enterprise policy requires it.
- Inspect folder access. Review writable, read-only and denied locations. Keep unrelated personal files outside the task’s permitted scope.
- Check both network controls. The app’s outbound-internet and local-network settings are on by default. Disable only what the task can work without; a local model endpoint or development server may need local connectivity.
- Review credentials. Git and GitHub CLI authentication are available inside the sandbox by default. A read-only explanation usually does not need authority to push changes.
- Start a new session after changes. GitHub says policy changes require a new or restarted session. A saved configuration summary does not prove that the sandbox is running.
A small check before a big project
Use a disposable folder with invented data for your first run. Give the assistant one narrow task, such as explaining a short function and suggesting a test. Record the selected endpoint, enabled integrations and permissions. Review the resulting file changes and available connection logs.
Then compare the outcome with your intended boundaries. Did it ask for access it did not need? Did a tool fail because the network was blocked? Solve that specific requirement instead of granting access to the whole computer. A successful trial is useful evidence about that setup, not a guarantee about every future task.
Quick answers
Does selecting a local model automatically make Copilot offline?
No. Check the client’s network behavior, provider endpoint and tool permissions separately.
Does offline mode make AI-generated code correct?
No. Code still needs review and appropriate tests. Privacy controls and correctness checks solve different problems.
Reporting note: Sources were checked October 8, 2026. This is a documentation-based explainer, not a hands-on test of Microsoft’s new hardware or local Copilot rollout. The checklist and fictional test scenario are The Bot Post’s editorial recommendations.
About the author
UbedullaFounder & Editor
Founder and editor of The Bot Post, covering AI news and technology.


