GitHub is preparing to combine Copilot Chat on github.com, Copilot Chat in GitHub Mobile, and Copilot cloud agent into one experience controlled by one policy. GitHub says the relaunch will happen no earlier than September 28, 2026, and the unified experience will be enabled by default after launch.
The consequential data change is easy to miss: chat data on github.com will be retained for the life of the account instead of 28 days. Business and Enterprise administrators therefore have a policy and retention decision to make before the launch, not merely a new interface to announce to developers.
What changes under the unified Copilot policy?
GitHub's August 28 announcement says three surfaces will converge: Copilot Chat on github.com, Copilot Chat in GitHub Mobile, and Copilot cloud agent. Separate policies for those experiences will be replaced by a single policy.
Keeping the unified experience requires no action because GitHub plans to enable it by default. An administrator can opt out, but GitHub says that choice will remove Copilot access on github.com and GitHub Mobile after the new experience launches. This makes the setting a bundled access decision across surfaces rather than an independent switch for each interface.
The announcement also says the github.com experience will move fully to the agent-sessions experience previously used only by Copilot cloud agent. As part of that move, github.com chat data will be retained for the life of the account rather than 28 days, aligning it with the existing cloud-agent experience.
That statement defines a product retention period. It does not, by itself, explain what happens after account closure, how deletion requests or legal holds work, which export tools cover the data, or whether every administrator can retrieve it. Those questions need current documentation or a direct answer from GitHub before a team records a compliance conclusion.
Why does the retention change matter to a business?
A 28-day window and an account-lifetime period create different operating assumptions. Developers may place source excerpts, issue details, customer context, incident clues, or proposed fixes into chat. A longer period increases the time that content may remain associated with the account, even if nobody changes what they type.
Longer retention can also be useful. It may preserve continuity for an ongoing agent session or make prior work available to the product. GitHub's announcement, however, does not claim that the change creates a complete audit record, makes every conversation discoverable, or replaces a company's own incident and change records.
That distinction separates product history from evidence management. Our guide to Copilot agent session records covers a different surface: enterprise usage-record streaming and a rolling 48-hour REST retrieval window. Neither that operational record nor account-lifetime chat should be assumed to substitute for the other without testing what each actually contains and who can access it.

What should administrators decide before September 28?
First, identify which of the three affected surfaces are currently allowed and used. Do not infer use from seat assignment alone. Ask engineering owners for representative workflows on github.com, mobile, and cloud agent, then identify the content those workflows can place in chat.
Next, assign one owner to the unified policy decision. Security and privacy teams should describe the content and retention questions; engineering should describe the operational need; the Copilot administrator should implement the approved setting. Legal counsel may need to interpret contractual or regulatory obligations, but this product announcement is not enough to decide those obligations.
Then decide whether the unified experience can remain enabled while the unanswered retention questions are resolved. The trade-off is explicit: opting out removes Copilot on github.com and GitHub Mobile after launch, while leaving the default in place accepts the unified experience and its stated retention behavior. Record who accepted that scope and when it should be reviewed again.
Finally, prepare a short user notice before behavior changes. It should name the affected surfaces, state GitHub's account-lifetime retention description exactly, remind users what information should not enter Copilot, and point to an internal owner for questions. Avoid saying chats are “permanent” or “fully auditable”; neither claim appears in the announcement.
How can a team verify the effective result?
Configuration evidence should show the policy value before and after launch, but a screenshot of a setting is not enough. Test with approved, non-sensitive content on each surface the organization intends to keep. Confirm that the surface is available or unavailable as expected and record the account and organization context used for the check.
Keep the retention claim bounded to what GitHub has stated until the product exposes evidence that supports more. If the team needs deletion, export, access-control, regional, or legal-hold answers, obtain those answers separately and attach them to the policy decision. Do not turn an absence of visible old chat into proof that the underlying data was deleted.
The same GitHub announcement includes seat-billing changes and a Copilot code-review default change. Those deserve separate owners and tests. Our review of the Balanced code-review default addresses the engineering setting; it does not answer the web, mobile, and cloud-agent retention decision.
GitHub tells Business and Enterprise administrators to review the unified policy before September 28. The practical result should be one deliberate setting, a clear user notice, and a dated list of unresolved retention questions—not silent acceptance of a default because the three surfaces now share one name.
BaristaLabs helps teams connect AI product settings to accountable operating controls through responsible AI consulting. If your organization already uses Copilot on the web, mobile, or cloud agent, bring one policy scope to a focused retention review.
Source
Copilot policy review
Review one Copilot retention decision before September 28
BaristaLabs can help map the affected surfaces, likely content classes, policy owner, user notice, and verification evidence before the unified experience launches.
Best fit for organizations already allowing Copilot Chat on github.com, GitHub Mobile, or Copilot cloud agent.
Turn this idea into a pilot
Which workflow should go first?
Use the readiness check to compare impact, effort, risk, owner, and next step before requesting a review.
- 3-5 minutes
- Deterministic score
- No sensitive data
Practical AI Workflow Notes
Want more practical AI operations ideas?
Get short notes on applying AI inside real small-business workflows — from document handling and customer follow-up to internal reporting, compliance, and automation guardrails.