Best AI Coding Assistant at 500 Seats: Buy Copilot Business

A vendor evaluation for VPs of Engineering buying 500+ seats: what each AI coding assistant actually costs once usage is metered, whose indemnity has a cap, which admin controls have documented holes, and why Amazon Q Developer is off the shortlist.

By Rajesh Beri·August 9, 2026·16 min read
Share:
A long fan-fold printer invoice spilling off the end of a conference-room table and pooling on the carpet beside a closed laptop, in an empty meeting room.

Illustration generated using AI

At 500 seats, you are not buying a coding assistant — you are buying a billing model. Every option below except one meters usage on top of the seat, so the number on your purchase order is a floor, not a price. Buy GitHub Copilot Business at $19 per seat as the baseline for all 500 engineers, add Claude Code on Anthropic's Enterprise plan as a metered second tool for the minority doing agentic work, and put a hard budget cap on both. Do not buy Amazon Q Developer at any price — AWS has already scheduled its funeral.

All prices below were fetched from each vendor's live pricing page on 10 August 2026.

Option List price / seat / month What the seat includes Overage IP indemnity Trains on your code
GitHub Copilot Business $19 $19 of AI credits metered at API rates Yes No
GitHub Copilot Enterprise $39 + $21 GitHub Enterprise Cloud $39 of AI credits metered at API rates Yes No
Cursor Teams $40 usage allotment, unpublished billed in arrears Yes, capped at 12 months of fees No
Claude Enterprise ~$20 + usage at API rates Claude Code, Claude on web uncapped inference Yes No
OpenAI Codex (ChatGPT Business) $20 annual / $25 monthly shared ChatGPT + Codex pool credits at rate card Yes No
Gemini Code Assist Standard $19 (annual commitment) 1,500 requests/user/day none — hard quota Yes No
Amazon Q Developer Pro $19 end of support April 2027 n/a Yes No

What 500 Seats Actually Costs on Each Plan

The sticker price is off by roughly an order of magnitude, and that gap is the entire buying decision.

Copilot Business is $19 per user per month and Copilot Enterprise is $39. At 500 seats that is $114,000 or $234,000 a year — except that on 1 June 2026 GitHub moved every Copilot plan to usage-based billing. The seat fee now buys a credit allotment equal to the seat price — $19 of credits on Business, $39 on Enterprise — and everything past it is metered: credits "will be consumed based on token usage, including input, output, and cached tokens, according to the published API rates for each model." Promotional credits of $30 and $70 per user ran June through August 2026 and are expiring now, which means your September invoice is the first honest one you will see.

Copilot Enterprise carries a second cost most evaluations miss: it requires GitHub Enterprise Cloud, which is $21 per user per month on its own. The real Enterprise seat is $60, not $39. If you are not already on GitHub Enterprise Cloud for source control, the $39 tier is a $360,000-a-year line item that buys you codebase indexing and custom model tuning on top of a product you could have had for $19.

Now the number that should govern the budget. DX, which instruments engineering organisations for a living, puts total cost per engineer — seat plus token spend — at "typically $200–$600/month" for teams mixing inline completion with agentic tools. Treat that as a practitioner's rule of thumb, not a measurement: DX attaches no sample or methodology to the range, unlike the throughput figure further down. At 500 engineers it still implies $1.2M to $3.6M a year against a $114,000 sticker. The same post reports individual developer bills going from $29 to $750 and from $50 to $3,000 a month after the June 2026 billing change. Our own reporting on how Uber burned through its AI budget in four months at $500–$2,000 per engineer landed on the same range from a different direction.

The one plan that does not work this way is Google's. Gemini Code Assist sells a flat seat with a hard ceiling: 1,500 requests per user per day on Standard and 2,000 on Enterprise, aggregated across agent mode and the CLI. When you hit the quota, you stop — there is no overage line. Google lists Standard at $19 and Enterprise at $45 per user per month on an annual commitment. It is the only major option on this list whose annual cost you can state to your CFO in a single sentence and be right.


The Terms Are the Product, Not the Autocomplete

At this scale the differences that survive contact with your legal and security teams are indemnity, retention, and training — not benchmark scores.

IP indemnity is a vendor's promise to defend you if a third party claims generated code infringes their copyright. Microsoft's Customer Copyright Commitment covers GitHub Copilot, and as of 3 April 2026 the terms got materially better: Microsoft's own page states that for GitHub offerings there are "no additional required mitigations" and that "use of the Duplicate Detection filter feature is no longer required for CCC coverage." That removes the condition most likely to void the indemnity in practice — a filter setting an individual developer could turn off.

Google's is structurally the broadest. Gemini Code Assist is a Generative AI Indemnified Service, and Google indemnifies both the training data and the generated output, with Code Assist's documentation describing "indemnification for code suggestions" as a shipped feature of the Standard and Enterprise editions.

Cursor indemnifies too, and its Master Services Agreement says so plainly: Anysphere will defend against a claim "that the Service or any Suggestion infringes or misappropriates such third party's intellectual property rights." Read the next clause. Total liability "shall not exceed the total amounts paid by Customer to Anysphere in the twelve (12) month period immediately preceding" the claim. At 500 Teams seats that is a $240,000 ceiling on an IP claim against your codebase. That is not an indemnity in the sense your general counsel means it; it is a refund.

On training, the commercial tiers have converged and the consumer tiers have not. GitHub's April 2026 policy update began using interaction data — "inputs, outputs, code snippets, and associated context" — to train models by default for Free, Pro and Pro+ users, and states explicitly that "Copilot Business and Copilot Enterprise users are not affected by this update." Cursor's MSA puts the commitment in capital letters: "ANYSPHERE WILL NOT USE CUSTOMER DATA OR SUGGESTIONS TO TRAIN... ANY AI MODELS, UNLESS CUSTOMER EXPLICITLY AGREES." Anthropic and OpenAI both state no training on business data by default on their Team and Enterprise and Business and Enterprise plans respectively.

The operational consequence is the one worth acting on: an engineer on a personal Copilot Pro seat is, by default, contributing your proprietary code to a training set, and an engineer on the Business seat two desks away is not. GitHub does offer those users an opt-out — "unless they opt out," under Privacy in their personal settings — which is precisely the problem: the control that protects your source code sits in an individual's consumer account, where your administrators cannot see it, set it, or audit it. Shadow AI on individual subscriptions is not a policy inconvenience at 500 engineers. It is a training-data leak with a documented effective date, and it belongs in the same category as the SEC 8-K a company filed after a single employee used an unapproved AI tool.


Who Should Not Buy Each of These

This is the part vendor comparison pages leave out.

Skip Copilot Business if your engineers do most of their work in agent mode. Content exclusion — the control your security team will ask about — is documented as not yet supported in the Edit and Agent modes of VS Code Copilot Chat, and GitHub notes that Copilot "may use semantic information from an excluded file if the information is provided by the IDE indirectly." You are buying a control with a hole in exactly the surface that is growing fastest.

Skip Copilot Enterprise unless you are already paying for GitHub Enterprise Cloud. At $60 all-in against Business's $19, the delta buys codebase indexing and custom model tuning. Most 500-engineer organisations do not need either badly enough to triple the floor.

Skip Cursor if finance requires a modelable bill before signature. Cursor Enterprise pricing is not published — the page says plans are "priced per seat with an included usage allotment" and routes you to sales — and the self-serve Teams tier is $40 per user with on-demand overages billed in arrears. Cursor has the strongest admin surface on this list, with SCIM, repository and MCP allow-lists, audit logs and an AI code tracking API. It also has the liability cap above, and it is a single-product startup in a market where Tricentis just bought Tabnine's context engine and not its IDE and Windsurf's pricing page now redirects to Devin's.

Skip Claude Code if you cannot run a metered bill. Anthropic's Team plan is sold "for teams of 2 to 150," so a 500-engineer organisation is on Enterprise by definition, and Enterprise is described as "seat price + usage at API rates" — roughly $20 a seat plus inference that "scales with model and task." That is the most capable agentic option here and the least predictable one. Its enterprise controls are real but not airtight: Anthropic's own documentation notes that while terminal, VS Code and SDK logins enforce both forceLoginMethod and forceLoginOrgUUID, claude setup-token and /install-github-app enforce only the first "so they can mint a token in a different organization".

Skip Codex if you want a coding tool rather than a workspace. Codex is bundled into ChatGPT plans and shares its usage pool with ChatGPT Work, so at 500 seats you are buying a general-purpose AI workspace and getting the coding agent inside it. Business at $20 annual gets SAML SSO and MFA; SCIM, audit logs, the Compliance API and data residency controls are Enterprise-only. If you already bought ChatGPT Business for the company, the marginal cost of Codex is close to zero and this becomes the obvious pilot.

Skip Gemini Code Assist if your engineers are not already inside Google Cloud, or if 1,500 requests per user per day is too tight. Google's quota documentation warns that "one prompt might result in multiple model requests" in agent mode — the ceiling that makes the bill predictable is the same ceiling that will stop a heavy agentic user mid-afternoon.


The Productivity Evidence Is Thinner Than Every Vendor Deck

Nobody has demonstrated a large, durable productivity gain for experienced engineers in a controlled setting, and the best-run study on the question still cannot rule out zero.

METR ran a randomised controlled trial with experienced open-source developers on real issues in their own repositories and found in July 2025 that they were 19% slower with AI tools while believing they were 20% faster. METR then re-ran it. Its February 2026 update estimates "a speedup of -18% with a confidence interval between -38% and +9%" for returning developers — a subset of just 10 of the 57 developers in the new sample, which is why that interval is so wide — and "-4%, with a confidence interval between -15% and +9%" for the newly recruited majority. Negative means faster. Read the intervals: after a year of tool improvement, both cross zero. METR also says the true speedup could be higher because developers increasingly decline to participate in a study that might make them work without AI — an honest caveat no vendor deck contains.

Google's own enterprise RCT is the most favourable credible number and it is smaller than the marketing: 96 Google engineers on a complex internal task, roughly 21% faster, with the authors noting "our confidence interval is large".

The 2025 DORA report is where the buying signal actually is. 90% of respondents use AI at work and more than 80% believe it increased their productivity, while 30% report little or no trust in the code it generates. DORA finds a positive relationship between AI adoption and software delivery throughput — and a negative relationship with software delivery stability. Its own framing is that AI is an amplifier of what your organisation already is.

GitClear — which sells code-quality analytics, so weigh the interest — measured 623 million changes from 2023 to 2026 and found the maintainability signals moving the wrong way as AI authorship scaled: within-commit copy/paste up 41%, duplicated code blocks up 81%, error-masking constructs up 47%, cross-file function calls down 35% and refactoring line moves down 70%. It is careful not to claim AI caused this — its own framing is that "the headline is not 'AI writes bad code'" but that the default AI workflow rewards atomic output over reuse. Correlation, on a trend line with a lot else moving. DX's instrumented view of the upside is correspondingly modest: median PR throughput up 7.76% across 400-plus organisations tracked over 14 months, with most landing in a 5–15% band.

Build the business case on 5–15% throughput with a measurable maintainability cost, not on a vendor's 55%. If your board approved this on a bigger number, that gap is now your problem to manage, and it is the same gap we found when 64% of the Fortune 500 reported using AI coding agents while only 33% measured ROI.


Amazon Q Developer Is the Loser, and It Is Not Close

It is the cheapest way to buy a migration project in 2027.

On paper, Amazon Q Developer Pro is the safe institutional choice: $19 per user per month, IP indemnity included, Pro users automatically opted out of data collection, IAM Identity Center integration, and an AWS paper trail your procurement team already knows how to process.

AWS has ended it. Its own announcement states that "new signups will no longer be available starting May 15, 2026" and that "Amazon Q Developer IDE plugins and paid Subscriptions will reach end of support on April 30, 2027." Q Developer in the AWS Management Console survives; the IDE product you would be rolling out to 500 engineers does not. AWS directs customers to Kiro, its spec-driven agentic IDE, which is priced on credits: $20 per user for 1,000, up to $200 for 10,000, with add-on credits at $0.04 each.

Kiro may well be the better product. That is not the point. A 500-seat rollout is twelve to eighteen months of IDE plugin distribution, policy configuration, identity plumbing and training, and you would be starting that clock on a product with a published end-of-support date inside the same window. If Q Developer is on your shortlist because someone built the comparison in Q1, take it off.


The Three Criteria That Predict Regret at 500 Seats

Feature checklists do not predict regret. These three do.

1. Can you cap the bill without a support ticket? Copilot lets administrators set budgets at the enterprise, cost center, and user levels and choose whether to allow overage or stop at the included pool. Kiro disables pay-per-use overage by default. Claude Enterprise bills usage at API rates. Gemini Code Assist has no overage to cap. If the answer is "talk to your account manager," you have bought an uncapped liability with a seat count attached.

2. Does the policy control cover the mode your engineers actually use? Ask the vendor which surfaces honour content exclusion or repository allow-lists, in writing, naming agent mode and the CLI specifically. Both GitHub and Anthropic document their own gaps; a vendor that will not put its exceptions in writing has more of them, not fewer.

3. Does the indemnity have a cap, and what is it? A twelve-month-fees cap on a $240,000 contract is a materially different instrument from Microsoft's or Google's uncapped commitments. This is a five-minute question for your general counsel and it changes the answer more often than any benchmark.

What changes the recommendation: if you are already standardised on Google Cloud, Gemini Code Assist's flat quota is worth more than Copilot's ecosystem. If you already bought ChatGPT Business company-wide, Codex is nearly free at the margin. If developer preference is your binding constraint and attrition is a live risk, Cursor wins on product and you accept the liability cap and the opaque quote as the price.


What to Do Before Your Next Renewal

This week. Pull your actual credit and token consumption for the last 60 days, per developer, and find your p95. The mean is useless; the p95 is what your invoice tracks. Then audit for individual Copilot Pro and Cursor Pro subscriptions on expense reports — those seats have been training on your code by default since April 2026, unless the individual holding them found the opt-out.

This month. Set a hard budget at the cost-center level, not the enterprise level, so an overrun is visible to the manager who can act on it. Put the three questions above to every vendor on your shortlist in writing, and give them a deadline.

Before your next renewal. Instrument PR throughput and change failure rate now, with a clean pre-period, so the renewal conversation is about measured delta rather than a survey of how fast people feel. Assume 5–15%. And run one security review of the agent surface specifically — sandbox escapes hit Cursor, Codex, Gemini CLI and Claude in a single week last month, and agent configuration files have already been used as a persistence mechanism for a supply-chain worm.


The Bottom Line

The per-seat era for developer tools ended on 1 June 2026, and most engineering organisations have not repriced their assumptions. You are no longer buying a licence with a known annual cost; you are buying a metered utility with a seat-shaped minimum, from vendors who are still discovering what it costs them to serve you.

That is why the recommendation is boring. Copilot Business at $19 gives 500 engineers a defensible floor, an indemnity with no required mitigations, a contractual no-training commitment, and budget caps at three levels. Claude Code on Enterprise, metered and capped, gives the 10–20% doing genuine agentic work the best tool available. Gemini Code Assist is the pick if a predictable invoice is worth more to you than a best-in-class product — and for a lot of 500-person organisations, it quietly is.

Buy the terms. The models will be substitutable long before your contract expires.

Continue Reading

Share:

Frequently Asked Questions

What is the best AI coding assistant for an organization with 500+ engineers?

GitHub Copilot Business at $19 per seat is the right baseline for all seats: it carries Microsoft's Customer Copyright Commitment with no required mitigations as of April 2026, does not train on Business or Enterprise data, and supports budget caps at the enterprise, cost-center and user levels. Add Claude Code on Anthropic's Enterprise plan, metered and capped, for the minority doing agentic work.

How much does an AI coding assistant really cost per developer at enterprise scale?

Far more than the seat price. DX puts total cost per engineer, seat plus token spend, at typically $200 to $600 a month for teams mixing inline completion with agentic tools — a practitioner's rule of thumb rather than a published measurement, but at 500 engineers it implies $1.2M to $3.6M a year against a $114,000 sticker for 500 Copilot Business seats.

Should we buy GitHub Copilot Business or Copilot Enterprise?

Business, unless you already pay for GitHub Enterprise Cloud. Copilot Enterprise is $39 per seat but requires GitHub Enterprise Cloud at $21 per user per month, making the real seat $60. The delta buys codebase indexing and custom model tuning, which most 500-engineer organizations do not need enough to triple the floor.

Which AI coding assistants train on enterprise code?

None of the commercial tiers do. GitHub's April 2026 policy update began training on Free, Pro and Pro+ interaction data by default but explicitly excludes Copilot Business and Enterprise. Cursor, Anthropic and OpenAI all commit contractually to no training on business data. The exposure is individual subscriptions expensed by developers, not the corporate plan.

Is Amazon Q Developer still a viable choice for enterprise rollouts?

No. AWS blocked new signups on 15 May 2026 and the IDE plugins and paid subscriptions reach end of support on 30 April 2027. Q Developer inside the AWS Management Console continues, but the IDE product is being retired in favour of Kiro, which is credit-metered from $20 to $200 per user per month.

Do AI coding assistants actually make engineers faster?

The controlled evidence is weak. METR's February 2026 update estimates an 18% speedup for returning developers with a confidence interval from 38% faster to 9% slower — on a subset of just 10 developers — and 4% for new recruits with a similar spread. METR's own read is that developers are likely more sped up in 2026 than in 2025, but it calls its data very weak evidence for the size. DX measures median PR throughput up 7.76% across 400-plus organizations. Build the case on 5 to 15%, not on a vendor's 55%.

Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe

Related Articles

AI engineering productivity

Airbnb Shipped 80% More Features. One Number Is Auditable.

Airbnb put five AI productivity numbers on the record at Q2 earnings. Four are activity counts only Airbnb can define. One — support cost per booking, down about 16% — is the only figure a filed line item actually moves with.

August 9, 2026
Claude Code

Anthropic's Self-Hosted Gateway Rewrites the AI Coding War

Anthropic just shipped a self-hosted gateway that lets enterprises run Claude Code inside their own cloud tenancy — with SSO, audit logging, policy enforcement, and spend caps built in. This isn't a model upgrade. It's an infrastructure land grab that redraws the enterprise AI coding platform map. Here's what it means and how to evaluate your options.

July 2, 2026
Agentjacking

Agentjacking: AI Agents Hijacked via Fake Bug Reports

Security researchers demonstrated a new attack class called Agentjacking that hijacks AI coding agents through fake Sentry error reports — no credentials stolen, no servers breached, no malware deployed. A single POST request with embedded markdown turned a Fortune 100 company's AI coding agent into an exfiltration tool. Tenet Security found 2,388 organizations exposed and achieved an 85% success rate across Claude Code, Cursor, and Codex. The NSA had already warned about this exact vulnerability class. Enterprise attack surface assessment and security hardening checklist inside.

June 28, 2026
SpaceX Cursor acquisition

$60B Bought Cursor. Your Dev Team Is the Product Now.

SpaceX's $60 billion all-stock acquisition of Cursor is the largest VC-backed startup deal in history. It puts 50% of Fortune 500 developer machines inside Elon Musk's vertically integrated AI empire — from Grok models to Colossus compute to Starlink connectivity. For enterprise engineering leaders, the question is no longer whether to evaluate alternatives. It's how fast. Vendor risk assessment framework and platform decision matrix inside.

June 27, 2026

Latest Articles

View All →