PuppyIP Resource Center
AI Development And Administration 7 minutes Published 2026-09-19

Copilot's September 28 policy notice: unified access, chat retention and review effort

GitHub plans to unify some Copilot access policies no earlier than September 28 and change chat retention, with a separate change to default review effort. Administrators should assess access and data boundaries without treating an advance notice as already fully deployed.

GitHub Copilot Organization policies Data retention Code review Change notice

Service eligibility and regional restrictions

PuppyIP serves only compliant overseas businesses and their authorized personnel. Proxy services are not available in mainland China. The service may only be used for lawful business activities outside mainland China. Use of this service within mainland China is prohibited.

Hosting a proxy IP or server overseas does not change these restrictions. The service must not be provided to end users in mainland China through relaying, forwarding, sharing or resale. Before use, read the Terms of Service.

Key Takeaways

  • As checked September 19, the August 28 announcement describes upcoming changes. Unified access starts no earlier than September 28; do not invent an exact rollout time.
  • The unified policy defaults on. Opting out affects GitHub.com and Mobile Copilot after rollout, not necessarily every IDE feature.
  • GitHub.com Copilot chats move into agent sessions, changing retention from 28 days to the account lifetime. This does not mean all Copilot data is retained forever.
  • From September 28, default code-review effort changes from Lite to Balanced. Explicit prior Lite choices are honored, and repository overrides need separate checks.
  • Seat prepayment in the next billing cycle from October 1 is a separate change with unchanged prices. Access policies, AI usage and subscription bills are not one switch.

One announcement, four distinct decisions

On August 28, GitHub announced upcoming unified experiences, default code-review effort and organizational subscription billing changes. This article checked the announcement and current review documentation on September 19, focusing on whether administrators accept new access and retention boundaries and want to pin review effort, rather than repeating registration or payment-method tutorials.

The unified policy rolls out no earlier than September 28; review defaults change from September 28; seat billing changes in the next billing period from October 1. Dates and subjects differ. There is no evidence of a simultaneous midnight September 28 switch for everyone, or of this site's account having tested the new interface.

Access scope: an organization default does not affect every client identically

The announcement plans one policy connecting GitHub.com Copilot Chat, GitHub Mobile and cloud-agent experiences, enabled by default at launch. Administrators must decide whether members may use these unified surfaces and whether internal guidelines cover cloud-agent sandbox execution.

GitHub explicitly says opting out removes GitHub.com and Mobile Copilot access after rollout. That cannot be generalized to all IDE completion or other products. Inventory actual surfaces, then map policy choices to affected people instead of communicating an inaccurate “company-wide Copilot shutdown.”

GitHub describes a prelaunch route to the upcoming cloud-agent policy in organization Copilot settings. This review used public sources without an organization administrator login, so it provides no purportedly tested button instructions. If the entry is absent, revisit the announcement and current help instead of trying to bypass organizational management.

Retention scope: which chats, for how long

The announcement moves GitHub.com Copilot chats into agent sessions and changes retention from 28 days to the account lifetime. This is a substantive information-governance and compliance concern, but it applies to the described chat migration, not indefinite retention of every IDE prompt, log, telemetry item or arbitrary file.

Teams previously managing chat content around a 28-day window may need to reassess permitted input, internal retention requirements, offboarding and account handling. This is a governance inference from the retention change, not evidence of a leak or new third-party sharing.

These sources do not establish every historical-chat migration batch, individual organization deletion procedures or an exact rollout time. This article cannot replace contracts and organizational data policies. Resolve conflicts with administrators and compliance owners before accepting the enabled default.

Review effort: defaults, organizations and repository overrides

The announcement changes default code effort from Lite to Balanced starting September 28 and honors explicit Lite choices made before then. Organization defaults apply where repositories lack overrides; repository automatic review and manual PR review also have separate controls. One organization switch does not establish identical effort everywhere.

Current documentation positions Lite for faster, focused checks and Balanced for deeper context and complex issues, potentially consuming more AI credits and related Actions resources. Choose based on risk and budget, without presenting official positioning as measured accuracy from this site or guaranteeing Balanced finds every security issue.

To retain Lite, an authorized administrator should explicitly choose it before the change and inspect repository overrides. To accept Balanced, assess frequent automatic-review usage first. After manual review, inspect the actual effort in the PR overview comment rather than guessing from defaults. AI suggestions still need human checking.

A decision example: compliance requirements and small repositories

Suppose an organization has web chats involving sensitive internal material and small repositories with frequent automatic review. Administrators can submit unified access and retention requirements to information governance while independently deciding whether to pin Lite and retain particular repository overrides. These choices need not be an all-or-nothing Copilot upgrade or exit.

This is a hypothetical explanatory scenario, not a customer experience from this site. Record existing policies, surfaces, repository overrides and budgets, and set review points. After changes, verify access, actual review effort and usage. If retention requirements or permission scope remain unclear, stop expanding use rather than probing with real sensitive material.

October billing needs its own check

The same announcement says existing credit-card or PayPal Business/Enterprise subscriptions switch to prepayment for assigned seats in the next billing period from October 1, with unchanged prices. Revoking seats does not generate a prorated refund for the current period but affects the next; added seats are billed for remaining time. Retain payment-channel and billing-period scope rather than extending the change to every contract.

Seat inventory is therefore separate from access-policy review, and unchanged prices do not prove unchanged total bills. This article separates responsibilities and timelines without claiming logged-in cancellation, refund or repurchase tests. Do not cancel an entire subscription to experiment with policy settings; repurchase may depend on application-review rules then in force.

Recheck conditions and scope

Recheck if GitHub changes rollout dates, retention details or policy scope, or an organization finds its configuration differs from the announcement. This explanatory article made no settings changes, so operational rollback does not apply. For future changes preserve original settings, while recognizing that restoring a switch does not automatically delete generated data or undo completed actions.

For review failures after the change, consult the Copilot code-review outage checklist rather than confusing a service failure with organization-policy denial. PRODUCT_FIT=NONE: changing IPs does not alter organization policies, data retention or seat billing periods.

Sources

Frequently Asked Questions

Has the unified policy launched for every organization?

That cannot be claimed. The announcement says no earlier than September 28, 2026. The September 19 review treats it as upcoming, without account testing or an exact time.

Does opting out also disable all IDE completion?

The explicit impact is GitHub.com and Mobile Copilot after rollout. Do not extend it to every client and feature.

Does account-lifetime retention mean all Copilot data is retained forever?

No. The announcement concerns GitHub.com chats moving to agent sessions, not every log, IDE prompt and file.

Are repositories explicitly using Lite forced to Balanced?

GitHub says explicit Lite choices before the change are honored. Check organization defaults and repository overrides separately, and inspect actual effort in review overview comments.

Do unchanged prices guarantee an unchanged October bill?

No. Billing timing and assigned seats affect bills. Check access policy, review usage and subscription seats separately.