Skip to main content

GitHub Copilot policy changes billing, retention and defaults: the admin checklist

4 min read

GitHub Copilot is changing upfront seat billing, chat retention and policy defaults. Here are the dates and controls Business and Enterprise admins need.

GitHub Copilot policy changes billing, retention and defaults: the admin checklist

GitHub is changing when Copilot seats are charged, how long chat data can remain, and which code-review setting becomes the default. The model prices are not changing. The operating contract is.

GitHub’s August 28 notice bundles billing, retention and product-default changes into one calendar. New Copilot Business and Enterprise customers who pay by card or PayPal face the first change on September 1, 2026. Existing card and PayPal customers move to upfront seat billing on October 1. A separate set of product and policy changes begins September 28.

Three dates belong on the admin calendar

GitHub Copilot policy and billing changes announced August 28, 2026.
DateWho is affectedWhat changes
September 1New Business and Enterprise customers paying by card or PayPalNew seats are paid before access; self-service signup reopens.
September 28Organizations using Copilot policies and code reviewUnified agent/chat policy is enabled by default; Balanced becomes the review default unless Lite is explicitly set.
October 1Existing Business and Enterprise customers paying by card or PayPalSeat charges move to upfront billing.

GitHub says Copilot prices are unchanged. The cash-flow timing is not. It also says a revoked seat will not receive a refund for the remaining period. That makes offboarding speed and seat reconciliation financially meaningful, even when the price per seat stays flat.

Upfront billing makes stale seats a direct cost

Under a pay-before-access model, an admin should not wait for the monthly invoice to discover abandoned seats. Reconcile the identity provider, GitHub organization membership and Copilot seat list before the billing date. Define who can assign a paid seat, who removes it, and how quickly a departure reaches GitHub.

  • Export the current seat roster before the applicable change date.
  • Match each seat to an active worker, team and cost center.
  • Set an approval path for new assignments.
  • Test the offboarding flow from the identity provider to Copilot.
  • Record the billing term because a revoked seat is not refunded.

Enterprise agreement and invoiced customers should verify their own contract rather than assuming the card and PayPal schedule applies. GitHub’s announcement is specific about the affected payment route.

Chat retention moves from 28 days to account life

The more consequential governance change is retention. GitHub says Copilot Chat conversations will be retained for the life of the user’s account instead of the current 28-day window. The company says administrators will have ways to review and manage the data.

Longer retention can improve continuity and investigation, but it expands the period during which pasted secrets, customer data, proprietary code or sensitive incident details may exist. A 28-day assumption embedded in a data inventory, risk assessment or employee notice will become wrong.

Before September 28, ask which conversations admins can inspect, which users can delete, what happens after account closure, how legal holds interact with deletion, and whether regional or contractual restrictions alter the default. Do not describe the new policy to staff as ordinary editor history.

The unified policy widens an existing permission

GitHub previously announced that separate agent and chat controls would become a unified policy. The August 28 notice says that policy will be enabled by default for current Business and Enterprise customers on September 28, unless an administrator disables it.

A unified switch is easier to administer, but it can also authorize more than a team expected if its old review only considered chat. Inventory where Copilot can act, which repositories contain regulated or confidential material, and whether repository rules, branch protection and human approval still enforce the intended boundary. Our Copilot review-effort guide explains why an AI setting belongs in the risk record rather than being treated as a quality badge.

Balanced is a default, not an approval

GitHub says Copilot code review will default to Balanced on September 28 unless an organization explicitly selects Lite. Balanced uses a higher-reasoning model. That may improve review depth, but it does not certify a change or replace tests, code scanning and a reviewer who understands the repository.

Choose Lite for ordinary, familiar changes where speed and cost matter. Use Balanced where the failure radius is larger: authentication, authorization, migrations, shared libraries, infrastructure and security boundaries. Then measure accepted findings, false positives, latency and premium-request consumption on your own pull requests.

My verdict: treat this as a control migration

After the change, capture screenshots or exports showing the organization policy, repository overrides, retention setting and seat roster. Re-run the same review-effort test on a known pull request and confirm that deprovisioning removes access without leaving an unexpected paid assignment. That evidence turns a one-day settings change into a repeatable control.

Include finance in the verification. Compare the expected seat count with the first invoice under the new timing, investigate every mismatch, and keep the account-specific contract beside the public announcement. A documented reconciliation will matter more than remembering that GitHub said prices were unchanged.

The headline is not a price increase. It is a shift in payment timing, refund exposure, data duration and default permissions. Assign one owner across procurement, security and engineering. Capture the before state, make explicit choices before the dates arrive, and verify the result after the rollout.

The same lesson appears in our AI agent containment review: written intent is weak when infrastructure and defaults enforce something else.

Read the primary notice

Checked August 29, 2026. Dates, retention language, default-policy behavior, billing timing and refund treatment come from GitHub. Operational recommendations are Musthave.ai analysis.

Leave a comment

Your email address will not be published. Required fields are marked *