Blog

GitHub Copilot code review: how it works and what it costs

GitHub Copilot code review costs up to $5 of AI credits a review, by GitHub's estimate. See which plans include it, how to set it up and how it ranks.

Alex Mercer

GitHub Copilot code review is the AI reviewer built into GitHub, and every paid Copilot plan includes it. Since June 1, 2026, though, each review spends AI credits, plus Actions minutes on private repositories, and GitHub estimates $0.25 to $5 of credits per review at the default effort.

This blog belongs to cubic (cubic.dev), an AI code review tool that competes with Copilot. Every Copilot feature and price below comes from GitHub's or Microsoft's docs, checked October 4, 2026, and we flag our opinions.

Can GitHub Copilot do a code review?

Yes. Copilot Student and every paid plan include it. You request Copilot on a pull request like a human reviewer, or turn on automatic reviews, and it posts line comments with severity labels and suggested fixes you can commit. It can't block a merge.

GitHub Copilot code review

As of October 2026

Plans that include it

Copilot Student, Pro, Pro+, Max, Business and Enterprise. Not Copilot Free.

What a review uses

AI credits at $0.01 each, plus Actions minutes on private repositories

GitHub's estimate per review

$0.05 to $1 of credits at Lite effort, $0.25 to $5 at Balanced, the default

How to start one

Click Request next to Copilot under Reviewers, or run gh pr edit 123 --add-reviewer @copilot

Can it block a merge?

No

Where it works

GitHub, plus Azure Repos in preview. Not GitHub Enterprise Server.

How GitHub Copilot code review works

Copilot code review runs on an agentic architecture. It reads the diff, then calls tools to pull in context from the rest of the repository. Line comments carry a High, Medium or Low severity label and, where possible, a suggested change you can commit in a couple of clicks.

The agent runs on GitHub Actions. It can use agent skills from .github/skills and the repository's MCP servers, read-only. Fix with Copilot (public preview) hands a comment to Copilot's cloud agent to implement.

Are GitHub Copilot code reviews free?

Not on Copilot Free. Code review comes with Copilot Student, free for verified students, and every paid plan from Pro at $10 a month. Each review draws on the plan's AI credits, plus Actions minutes on private repositories. Verified teachers and maintainers of popular open-source projects may get Pro for free.

Prices as of October 2026, from GitHub's plans page and plan docs:

Plan

Price

AI credits included per month

Pull request reviews

Copilot Free

$0

limited

No

Copilot Student

free for verified students

not listed

Yes

Copilot Pro

$10 a month

1,500 ($15)

Yes

Copilot Pro+

$39 a month

7,000 ($70)

Yes

Copilot Max

$100 a month

20,000 ($200)

Yes

Copilot Business

$19 per seat a month

1,900 per user, pooled

Yes

Copilot Enterprise

$39 per seat a month

3,900 per user, pooled

Yes

Business and Enterprise organizations can also extend code review to members without a Copilot license on GitHub.com, billed to the organization. That takes two policies, AI credits paid usage and then Allow members without a Copilot license to use Copilot code review in GitHub.com, which is off by default. Automatic reviews then cover every pull request, whoever wrote it.

What a Copilot code review costs

Since June 1, 2026, each Copilot review runs on two meters:

  1. AI credits pay for the model, at $0.01 each. GitHub estimates $0.05 to $1 per review at Lite effort and $0.25 to $5 at Balanced, more for larger pull requests and with custom instructions.

  2. GitHub Actions minutes pay for the agent's run on private repositories, drawing on included minutes before standard rates. Larger runners cost more per minute, and self-hosted runners use none.

GitHub bills automatic reviews to the author and manual ones to the requester. On Business and Enterprise, a user who hits their budget stops getting reviews.

Say your team has 10 developers on Copilot Business. Their seats put 19,000 credits ($190) a month into the pool, enough for 38 to 760 Balanced reviews by GitHub's estimate if chat and agents spend none of it. A 20x range is as precise as GitHub's numbers get, so run automatic reviews for two weeks and check the billing usage report before you set a budget.

Annual Pro and Pro+ subscribers still on legacy billing pay 13 premium requests per review instead, out of 300 a month on Pro or 1,500 on Pro+. Past the allowance, each review costs $0.52 at $0.04 a request. Our AI code review pricing breakdown compares this with per-seat tools.

Lite or Balanced: which Copilot review effort to use

  • Lite gives fast, targeted feedback on common problems such as bugs, security issues and style. GitHub recommends it for routine changes.

  • Balanced uses a higher-reasoning model for a longer look at complex logic. It costs more and may use slightly more Actions minutes. GitHub recommends it for security-sensitive code, multi-service changes and strict repositories.

Balanced became the default on September 28, 2026. Reviews with no level picked moved from Lite to Balanced that day, and so did their cost. GitHub called the levels Low and Medium until August 7. You can set a default per user, repository, organization or enterprise.

We'd make Lite the repository default only where pull requests are mostly docs or config.

How to request a GitHub Copilot PR review

If your organization provides Copilot, an owner must first enable code review in its Copilot policies. Then click Request next to Copilot under Reviewers, after picking Lite or Balanced if you want. Or use the GitHub CLI:

# Request Copilot when you open the pull request
gh pr create --reviewer @copilot

# Add Copilot to an existing pull request
gh pr edit 123 --add-reviewer @copilot
# Request Copilot when you open the pull request
gh pr create --reviewer @copilot

# Add Copilot to an existing pull request
gh pr edit 123 --add-reviewer @copilot
# Request Copilot when you open the pull request
gh pr create --reviewer @copilot

# Add Copilot to an existing pull request
gh pr edit 123 --add-reviewer @copilot

Since October 2, the REST and GraphQL APIs can request a GitHub Copilot review too, with per-request effort. In REST, the reviewer is copilot-pull-request-reviewer[bot].

To get another review after you push changes, click the re-request button next to Copilot's name. Copilot also reviews local changes in VS Code, Visual Studio, JetBrains IDEs and Xcode.

How to turn on automatic Copilot reviews

GitHub's configuration guide covers both paths below, and if both apply, Copilot still posts one review.

Your own pull requests (Pro, Pro+ and Max, or a Business or Enterprise license; not managed user accounts): under your profile picture > Copilot settings > Code review, turn on Automatic Copilot code review.

A repository:

  1. In Settings > Rulesets, click New ruleset > New branch ruleset.

  2. Set Enforcement Status to Active and add Target branches, such as the default branch.

  3. Under Branch rules, select Automatically request Copilot code review, then click Create.

Organization owners do the same under the organization's Settings > Repository > Rulesets, targeting repositories by name pattern.

Both paths offer Review new pushes and Review draft pull requests. Without new-push reviews, Copilot reviews once, when the pull request opens or first leaves draft. With them, every push gets a review that uses credits, so we'd leave them off until you've checked two weeks of billing data. A ruleset's push and draft settings override personal ones.

How to write custom instructions for Copilot code review

Copilot code review reads instructions from these files:

File

What it's for

.github/copilot-instructions.md

Rules for every review in the repository

.github/instructions/NAME.instructions.md

Rules for files that match the applyTo glob in its frontmatter

AGENTS.md

Rules you share with other AI agents

CLAUDE.md, GEMINI.md, REVIEW.md

Read by code review too, if they exist

.github/skills/NAME/SKILL.md

Task-specific skills Copilot uses when relevant

A path-specific file looks like this:

---
applyTo: "src/api/**/*.ts"
---
# API handler rules

- Check the caller's permissions before any read or write.
- Flag database queries inside loops and suggest one batched query.
- Never return stack traces or SQL errors to the client

---
applyTo: "src/api/**/*.ts"
---
# API handler rules

- Check the caller's permissions before any read or write.
- Flag database queries inside loops and suggest one batched query.
- Never return stack traces or SQL errors to the client

---
applyTo: "src/api/**/*.ts"
---
# API handler rules

- Check the caller's permissions before any read or write.
- Flag database queries inside loops and suggest one batched query.
- Never return stack traces or SQL errors to the client

To keep a file out of code review, add excludeAgent: "code-review" to its frontmatter, as GitHub's guide explains.

GitHub's tutorial on code review instructions warns that Copilot may not follow every instruction every time and can overlook parts of long files. It recommends starting with 10 to 20 specific instructions, in files under about 1,000 lines. Code review also ignores instructions about formatting, the overview comment or blocking merges, links to external standards (paste the text in instead) and vague goals.

Instructions add to credit use too, so keep to rules a reviewer can check against the diff, each with its reason.

Can Copilot approve pull requests?

Not by default. Copilot leaves a Comment review that doesn't count toward required approvals, with an approval assessment in its overview comment. Since September 1, 2026, admins can let it approve pull requests, a public preview on Pro, Pro+, Max, Business and Enterprise that's off by default.

Under Auto-approval in a repository's Settings > Copilot > Code review, you can turn approvals on, let them count toward merge requirements and, with File paths, count an approval only when every changed file matches one of up to 15 globs. Organization and enterprise admins decide whether repositories can turn this on, and a new push dismisses Copilot's approval.

GitHub's docs describe Comment and Approve reviews from Copilot, not Request changes, so it can't block a merge. If you try approvals, start with a File paths list such as docs/** and keep a human approval required everywhere else.

Azure DevOps Copilot code review

Microsoft announced a preview of Copilot code review for Azure Repos in its Sprint 279 release notes on September 4, 2026. Its docs describe a narrower product than the GitHub version:

  • Scope. Azure DevOps Services with Git repositories, not TFVC.

  • Setup. A Project Collection Administrator enables it under Organization settings > Repos > Repositories. Project administrators and repository owners then turn it on, and users opt in through preview features unless an admin enables it for everyone. Click Request next to GitHub Copilot under Reviewers, or add the Automatically request Copilot code review branch policy.

  • Reviews. Always a Comment review, so it can't approve, request changes or satisfy required reviewers. It doesn't re-review automatically after new commits and ignores replies.

  • Billing. AI credits at $0.01 each, on the Azure subscription linked to your organization under the meter GitHub Copilot for AzDO. Charges take 48 hours to show up.

  • Compute. The default Azure Pipelines pool or a Managed DevOps Pool on Ubuntu, not self-hosted pools or Windows images.

Preview limits, which Microsoft says can change:

Requirement or limit

Value

Pull request state

Active, with no merge conflicts

Repository size

10 GB or less

Changed files

100 or fewer

Changes in the pull request

100 or fewer

Reviews of the same version

1 completed review per merge commit

Concurrent reviews

1 per pull request, 5 per organization, 2 per user

The 100-file ceiling rules out big refactors. CodeRabbit, Qodo, DeepSource and, in beta, Cursor's Bugbot also list Azure DevOps support. cubic works only with GitHub, so it isn't an option there.

Copilot code review limitations, by GitHub's own account

  • It misses things and can be wrong. GitHub doesn't guarantee it catches every problem and says to validate its feedback and add a human review.

  • It doesn't read replies, so it won't answer them either.

  • It can repeat itself. A re-review may repost comments you resolved or gave a thumbs down.

  • Thumbs go to GitHub, which uses them to improve the product. Your own levers are instruction files, skills and Copilot Memory, a public preview on Pro, Pro+ and Max.

  • Full reviews need Actions runners. Without GitHub-hosted or self-hosted runners, reviews fall back to a more limited version.

  • It skips some files. Copilot doesn't review dependency files such as package.json and Gemfile.lock, log files or SVGs.

  • No model choice. GitHub doesn't support model switching.

  • No GitHub Enterprise Server. Copilot isn't available there.

For a team, the second and third limits cost the most. Copilot can't see a reply that says "this is intentional", so it can raise the same point on the next review, and someone has to dismiss it again.

How good is GitHub Copilot code review?

Copilot holds its own against dedicated AI reviewers. On the online tracker of Martian's Code Review Bench, in the default last-month view checked October 4, 2026, Copilot ranks #4 of 14 tools at 61.0% F1, within a point of Greptile (61.9%), CodeRabbit (61.8%), Macroscope (60.7%) and Claude (60.2%). cubic, our product, ranks #1 at 65.3%.

Martian, a research lab that says it doesn't sell coding tools, scores reviewers on real open-source pull requests. Precision is the share of a reviewer's comments developers acted on, recall is the share of real fixes it caught, and F1 balances the two. Copilot scores 67.0% precision and 56.0% recall. cubic scores 72.0% and 59.7%.

The board moves daily, and several vendors, cubic included, have each reported #1 at different dates and in different modes. On Martian's offline benchmark of 50 hard-to-find bugs, as labeled on September 8, 2026, Qodo's Deep configuration leads cubic by 0.2 F2 points. Copilot's recall there, 66.5%, is the highest of the 21 tools listed.

Who should use GitHub Copilot code review

  • Teams already paying for Copilot Business or Enterprise. The credits are already in your pool, there's no new vendor, and you can cover members without a license. A ruleset and a short instructions file give you a first-pass reviewer the same day.

  • Azure DevOps teams. It runs inside Azure Repos and bills to your Azure subscription. Mind the 100-file limit and the preview label.

  • Teams that want comments, not a gate. If human approval and CI already decide merges, a reviewer that only comments fits in without changing your rules.

  • Individuals with light volume. Pro's $15 of monthly credits pays for 3 to 60 Balanced reviews by GitHub's estimate, before any other Copilot use.

When a dedicated reviewer is worth adding

cubic is our product, so weigh this section accordingly. We'd add a dedicated reviewer when:

  • You want each team rule checked on its own. GitHub says Copilot may not follow every instruction every time. In cubic, each custom rule is a named agent with path filters, and each comment names the rule that flagged it.

  • You want it to learn from your team. cubic learns from replies, thumbs up or down, and the past comments of up to five senior reviewers you pick. It drops a finding when the author, a coding agent or anyone with write access replies that it's wrong.

  • Risky changes need a deeper pass. cubic's ultrareview makes multiple passes with its most capable models, usually in about 9 minutes, by hand or automatically on high-risk pull requests. It's on every paid plan, including Pro and Max, and counts 3x toward your allowance.

  • You'd rather budget per developer. As of October 2026, cubic's paid plans start at $30 per developer a month billed yearly, or $40 monthly, each with a set number of reviewed lines. Extra lines cost $20 per 10,000.

Run both on your own pull requests for two weeks and count which comments led to a fix, the same measure Martian uses for precision. cubic vs GitHub Copilot compares features, and our GitHub Copilot code review alternatives and AI code review pages cover other GitHub AI code review options.

If you already pay for Copilot on GitHub, turning on its code review takes one ruleset and no new vendor. Measure what it catches before you decide it's enough.

If you want a second reviewer in that test, try cubic on the same pull requests. It's free for public repositories, and paid plans start with a 7-day trial.

Table of contents