PACO.IO

Obsidian Vault Portal v2.0
guest@paco.io:~$cat "_posts/2026-09-15-ptir-daily-briefing.md"
15 September 2026

PTIR — Daily Briefing — 2026-09-15

by

Executive Summary

Two actions are worth the time today. ISC2 is running a one-hour briefing at noon Central on the security gap created when agentic AI expands non-human identities faster than access governance can keep up; it offers one Group A CPE. GitHub has also added efficiency, balance, and intelligence controls to Copilot’s automatic model selection, making a bounded comparison useful before choosing a default.

Action Queue

Register for today’s ISC2 briefing on AI, identity, and data security

The session examines how enterprise AI agents obtain real permissions while identity programs still operate at human onboarding speed. ISC2 lists a September 15 start at 1:00 p.m. Eastern (noon Central), a 60-minute duration, intermediate level, and one Group A CPE. The briefing is sponsored by Netwrix, so treat its statistics as vendor research and focus on the governance questions: inventorying non-human identities, mapping their access to sensitive data, finding escalation paths, and shortening remediation time.

Recommended action: Register before noon Central and attend live if the agenda fits. Capture a four-line checklist covering identity ownership, credential lifetime, least privilege, and revocation for AI agents.

  • Urgency: Immediate
  • Importance: ★★★★★
  • Verified active: September 15, 2026
  • Deadline: September 15, 2026 at 12:00 p.m. Central (session start)
  • Cost: Free security briefing; one Group A CPE
  • Requirements: BrightTALK account; ISC2 says this account is separate from an ISC2 member login
  • Official registration: ISC2 Security Briefings

Compare Copilot’s three auto-selection tiers on one repeatable task

GitHub Copilot’s automatic model selection now offers efficiency, balance, and intelligence tiers. All three draw from the same model pool; the tier changes how the router weighs cost, quality, and response time. Billing still follows the model selected, and paid subscribers receive GitHub’s stated 10% discount on usage billed through auto. The control is rolling out across VS Code, Copilot CLI, and the GitHub Copilot app.

GitHub Copilot auto model-selection controls

Recommended action: Run the same bounded, non-sensitive task once under each tier. Record selected model, elapsed time, premium-request cost, correctness, and cleanup required. Keep balance as the provisional default unless the comparison gives a concrete reason to change.

  • Urgency: This week
  • Importance: ★★★★☆
  • Verified active: September 15, 2026
  • Deadline: None announced
  • Cost: Included subject to the user’s Copilot plan and premium-request allowance; overage depends on the selected model
  • Requirements: GitHub Copilot access and a client where the rollout has arrived
  • Official announcement: Configure cost and quality in Copilot auto model selection

AI

The GitHub control is useful because “auto” is no longer a single opaque optimization target. It still does not make cost predictable: the chosen tier influences routing priorities, while the selected model determines usage. A small benchmark log is more informative than assuming that efficiency is always cheapest or intelligence always produces the best final result.

Agentic AI is producing two linked governance layers. At the infrastructure layer, systems need explicit identities, scoped permissions, credential rotation, and rapid revocation. At the model layer, users increasingly choose policy objectives—cost, latency, or quality—while a router makes the per-request decision. Both layers need logs sufficient to reconstruct what was allowed, selected, and spent.

tags: cybersecurity - ai - identity-security - github-copilot - professional-development