GitHub Copilot Unified Policy: What Changes After September 28
GitHub says that no earlier than September 28, 2026 it plans to relaunch Copilot Chat on github.com, GitHub Mobile and the Copilot cloud agent as a single unified experience with one set of policies. The change is planned, not yet something to report as already live on September 22. GitHub says the unified experience will be enabled by default; Copilot on github.com will move to agent sessions, the cloud agent will use GitHub's Sandbox, and chat data on github.com will be retained for the life of the account rather than 28 days. Organizations that opt out of the unified experience will lose access to Copilot on github.com and Mobile after launch, so Business and Enterprise admins should review policy, retention and access implications before the rollout rather than discovering them after it happens.
Your organization uses Copilot Chat on github.com or GitHub Mobile and needs to prepare for the planned unified experience
A privacy or compliance reviewer is relying on the previous 28-day github.com chat-retention period
An administrator is considering opting out and needs to understand the access consequence
Developers assume the September 28 date means the change is guaranteed to go live that morning
Possible causes
GitHub is consolidating previously separate Copilot Chat, Mobile and cloud-agent experiences under one policy model
The github.com experience is planned to migrate to agent sessions and cloud-agent execution uses GitHub's Sandbox
GitHub is changing chat-data retention on github.com from 28 days to the life of the account for the unified experience
The rollout is described as no earlier than September 28, so exact production timing can differ from the earliest date
HOW TO FIX IT
Work from the safest step to the harder repair.
Step 1. Treat September 28 as the earliest announced rollout date, not a guaranteed launch timestamp. Re-read GitHub's current changelog immediately before changing organizational policy or telling users the new experience is active.
Step 2. Inventory where Copilot is used today: github.com chat, GitHub Mobile, cloud agent, IDE integrations, code review and any organization-specific policy controls. The September announcement specifically addresses the github.com, Mobile and cloud-agent experience, so do not assume every IDE behavior changes identically.
Step 3. For Business and Enterprise organizations, record the current Copilot policy settings and identify who owns the decision to accept or opt out of the unified experience. GitHub says the new experience will be enabled by default, which makes pre-rollout policy review important.
Step 4. Review data-governance expectations around chat retention. GitHub says chat data on github.com will be retained for the life of the account instead of 28 days after the migration. Update internal retention notices, acceptable-use guidance and data-classification rules if the previous 28-day assumption was material.
Step 5. Remind developers not to paste secrets, credentials, regulated personal data or proprietary material into Copilot merely because the interface is convenient. A longer retention period increases the importance of keeping sensitive data out of prompts in the first place.
Step 6. Understand the opt-out tradeoff before using it as a privacy shortcut. GitHub says organizations that opt out will lose access to Copilot on github.com and GitHub Mobile after launch. Evaluate the access impact, user communication and alternative workflows before changing the setting.
Step 7. Treat GitHub Sandbox as an execution boundary, not a substitute for repository authorization, branch protection, code review or least privilege. Agent sessions still need ordinary controls around what repositories, actions and credentials are available to the user or automation.
Step 8. Test the post-rollout workflow with a low-risk repository first. Verify chat history/retention expectations, repository context, agent-session behavior, mobile access, approval requirements and any audit trail your organization depends on before expanding use.
Step 9. Keep adjacent September changes separate. GitHub also announced a Copilot code-review default-effort change starting September 28 and Business/Enterprise billing changes beginning October 1. Those are related operational dates but are not the same policy or retention change.
Step 10. Document the actual rollout date your organization observes, the policy decision, affected users, retention posture and any follow-up controls. Update this same canonical when GitHub materially changes the unified-experience policy rather than creating interface-by-interface duplicates.
Need the actual code? Go to GenesisCodeDoctor.com to search the Code Store or request code for the exact platform, error, and repair you are working on.
Keep secrets, access tokens, private keys and regulated data out of Copilot prompts and examples.
Test agentic workflows in a low-risk repository with least-privilege credentials and normal branch/review protections before broader use.
Preserve an audit trail of organizational policy changes and use GitHub's current admin documentation rather than relying on screenshots of pre-rollout settings.
STOP AND GET HELP WHEN
Do not turn a repair into a larger outage.
Do not claim the unified Copilot experience is already live merely because September 28 is approaching; GitHub says no earlier than that date.
Do not tell users that all Copilot data everywhere is retained for the life of the account; the cited announcement specifically describes github.com chat data in the unified experience.
Do not assume opting out preserves github.com or Mobile Copilot access; GitHub says those surfaces will become unavailable after launch for organizations that opt out.
Do not treat Sandbox execution as permission to bypass repository access controls, branch protections, review requirements or secret-handling rules.
HOW GENESIS HANDLES IT
Diagnose the exact failure before choosing a repair.
Genesis separates the visible symptom from the underlying technical cause. Run the supported diagnostic first, review the evidence, and then use a matching repair only when the failure is actually verified.
Platform scope
GitHub Copilot on github.com, GitHub Mobile, Copilot cloud agent, Business and Enterprise administration
Category
GitHub Copilot · AI governance
Last updated
2026-09-22
REPAIR PROFILE
Know the complexity before you edit.
Difficulty
Intermediate
Change risk
Medium
These labels describe implementation complexity and blast radius, not a guaranteed repair time.
AUTHORITATIVE SOURCES
Verify time-sensitive platform details at the source.
Is GitHub's unified Copilot experience live on September 22, 2026?
No. GitHub says the relaunch will happen no earlier than September 28, 2026. Treat the announcement as a planned change until GitHub confirms rollout on the surfaces your organization uses.
What happens to Copilot chat retention on github.com?
GitHub says chat data on github.com will be retained for the life of the account instead of 28 days after the unified-experience migration.
Can an organization opt out?
GitHub says organizations can opt out, but after launch that choice means losing access to Copilot on github.com and GitHub Mobile.
Does GitHub Sandbox replace normal security controls?
No. Sandbox execution can limit an agent's runtime environment, but repository authorization, branch protections, reviews, secrets and least-privilege access still need ordinary controls.
Once you know the platform and the verified problem, search the Genesis Code Doctor Code Store for a matching package. If the exact integration or repair is not there, use Request a Code and describe the platform, official documentation, desired behavior, and sanitized error—never send your secret key.
Start with a free diagnostic. If Genesis verifies a problem and a compatible treatment exists, continue to the matching Code Store product or repair path. If you cannot find the exact code you need, request it at GenesisCodeDoctor.com rather than forcing a generic snippet into the wrong platform.