The short answer
From September 1, 2026, GitHub Copilot requires prepaid seat authorization before users gain access and has reverted promotional AI credit pools to standard allowances — 37% fewer credits for Business-plan teams. A second wave of changes arrives on September 28: unified Copilot Chat, a code-review default switch, and a chat data-retention extension from 28 days to account lifetime. Existing credit-card and PayPal customers have until October 1 to absorb the billing changes. This is not a price increase, but for teams that sized their AI engineering budgets against the promotional pools, it is a cost increase that arrives without a renewal event to catch it.
If you manage Copilot at scale, three actions matter right now: audit your seat list, recalculate your credit budget, and brief your legal team on the data-retention shift before September 28.
What changed September 1
GitHub published the changes on August 28, 2026 via its official Changelog. Two things took effect immediately on September 1. First, all new Copilot Business or Copilot Enterprise seat assignments now require payment before the user gains access. Previously, admins could assign seats and the charge would appear on the next billing cycle; under the new model, the authorization is upfront. For teams that manage large contractor rosters or run rapid onboarding cycles, this changes the day-to-day workflow: a seat cannot be provisioned without confirmed budget headroom.
Second, the promotional AI credit allowances that have been in place since Copilot’s usage-based billing launched were reset to standard levels. Teams relying on the promo pools — often without explicitly accounting for them — will see the reduction on their next usage report. GitHub has framed this as the end of a promotional period rather than a price change, but the practical effect is higher costs for teams whose AI-assisted development workflows were calibrated against the higher allowances.
The changes apply immediately to new customers. Existing customers on credit card or PayPal billing have until October 1 before their billing cycle reflects the new prepaid-seat model. Teams on invoiced billing should verify their agreement terms separately, as the October 1 date applies specifically to card and PayPal accounts.
The credit math
The numbers are concrete. Copilot Business drops from a promotional 3,000 AI credits per user per month to the standard 1,900 — a reduction of 1,100 credits, or 37%. Copilot Enterprise falls from 7,000 to 3,900 per user per month, a reduction of 3,100 credits, or 44%. For a team of 50 engineers on the Business plan, that is 55,000 fewer AI credits per month available before overages begin.
What counts as a credit varies by feature: Copilot code completions in the IDE, Copilot Chat requests, Copilot code review suggestions, and cloud agent tasks each consume different amounts. GitHub’s usage dashboard shows per-feature consumption, but teams that have not been monitoring it closely may not know how close they are to the new ceiling until the first billing cycle under the new rules lands.
GitHub’s spend controls remain available and unchanged. Admins can set a monthly credit spending limit, after which the service degrades gracefully rather than cutting off mid-task. Setting those limits now — before the October billing cycle — is the single highest-leverage action for teams that want to avoid an unexpected overages charge. This is standard practice for any cloud infrastructure cost management discipline, applied to AI tooling.
September 28 and the data governance shift
The September 28 changes are governed by a different risk register than the billing reset. GitHub will relaunch Copilot Chat on github.com, in GitHub Mobile, and the GitHub Copilot cloud agent as a single unified experience. Three specifics matter for enterprise teams.
The most significant is data retention. When the unified agent sessions experience launches, chat data retention will shift from 28 days to the lifetime of the account. Copilot Chat sessions can contain code snippets referencing personal data, internal system architecture, third-party API details, or proprietary business logic. A 28-day rolling delete gives compliance teams a bounded window; lifetime retention changes that calculus entirely. For teams subject to GDPR’s data minimisation principle (Article 5(1)(e)) or a CCPA deletion request obligation, this change may require a privacy impact assessment or an update to your records of processing activities before September 28.
The second change is more operational: the default effort level for Copilot code review switches from Lite to Balanced. Lite generates narrower, higher-signal review comments; Balanced generates more. For teams that adopted Lite deliberately — to reduce noise on pull requests — this default will reset unless individual users or org admins intervene before September 28.
The third is consolidation: the unified Copilot experience merges three previously separate surfaces. From a governance perspective, this means a single policy and a single audit log covers all Copilot interaction types, which simplifies some admin work but also means that any policy gap applies everywhere simultaneously.
What it means for US & EU software teams
GitHub is making the same transition that cloud infrastructure vendors made a decade ago: moving from consumption-first, generous-by-default pricing toward enterprise-grade billing that requires explicit budget authorisation before access is granted. That transition proved less visible during the promotional credit period because the high allowances absorbed usage spikes without triggering overages. The September 1 reset makes the economics visible again.
For US-based engineering teams, the immediate exposure is financial: teams that provisioned seats broadly, relied on promotional credits, and did not set spend limits will see their next invoice differently. The October 1 deadline gives card and PayPal customers one billing cycle to get ahead of it, but only if they act before the cycle closes.
For EU-based teams, the September 28 data-retention change is the more urgent concern. GDPR requires a legal basis for retaining personal data and limits retention to what is necessary for the stated purpose. If Copilot Chat sessions contain data about individuals — even incidentally, in code or prompts — moving from a 28-day to a lifetime retention window is a change in data processing terms that may require controller-side action. The relevant question to answer before September 28 is whether your organisation has a legitimate interest assessment or a data processing agreement with GitHub that covers the extended retention, and whether your existing ROPA entry needs updating.
For teams in both regions, the code-review default switch is minor in isolation but is a reminder that managed SaaS products change default behaviour through updates, and that “set and forget” governance only works until the next vendor policy refresh. Periodic reviews of AI tool settings — the same cadence you would apply to cloud IAM policies — catch these shifts before they affect team output.
Action checklist before October 1
Nothing here requires a policy rewrite or a vendor negotiation. It is operational hygiene applied to a changing tool contract:
- Audit your Copilot seat assignments. Remove unneeded seats now. Under the new prepaid model, every assigned seat will incur an upfront charge on your next billing cycle. Seats assigned to contractors who finished last quarter, or to employees who never activated Copilot, cost money immediately rather than at billing time.
- Pull your current AI credit consumption report. Compare actual monthly usage against the new 1,900 (Business) or 3,900 (Enterprise) standard allowances. If you were in the upper third of the promotional pool, you are likely to hit the ceiling before the billing cycle ends. Set a spend cap that reflects your actual needs, not the promotional headroom.
- Brief your legal or privacy team on the September 28 data-retention change. Ask them to determine whether the extended retention requires a privacy impact assessment under GDPR Article 35, an update to your records of processing activities, or a review of your data processing agreement with GitHub. Do not wait until September 27.
- Decide on the code-review default before September 28. If your team adopted Copilot code review on the Lite setting deliberately, configure the Balanced-to-Lite preference at the org or user level before the default switches on September 28. Otherwise, re-configuring it after the fact is a minor inconvenience rather than a serious risk — but it is avoidable.
- Update your AI tooling cost model. If your team bills Copilot costs to a client or to an internal P&L, the promotional-to-standard credit reduction changes the unit cost of AI-assisted development. Models built on the 2025 promotional allowances are now producing incorrect numbers.
Frequently asked questions
What is the GitHub Copilot billing reset in September 2026?
GitHub changed three things in its Copilot plans, effective September and October 2026. First, from September 1, all new Copilot Business and Enterprise seat assignments require upfront payment before the user gains access. Second, also on September 1, promotional AI credit pools dropped from 3,000 to 1,900 credits per user per month (Business) and from 7,000 to 3,900 (Enterprise). Third, from October 1, these billing changes apply to existing customers who pay by credit card or PayPal. The changes are part of GitHub’s shift to treating Copilot as enterprise software requiring formal budget controls.
How many AI credits does GitHub Copilot Business include from September 1, 2026?
From September 1, 2026, Copilot Business includes 1,900 AI credits per user per month at the standard rate. This is down from a promotional allowance of 3,000 credits per user per month. Copilot Enterprise drops from a promotional 7,000 to the standard 3,900 credits per user per month. Teams whose AI-assisted workflows were sized against the promotional pools will need to either trim usage or budget for overages.
What is the chat data retention change on September 28, 2026?
When GitHub relaunches Copilot Chat as a unified experience on September 28, 2026, chat data retention will extend from 28 days to the lifetime of the account. This is a material change for companies processing personal data under GDPR or CCPA, because Copilot Chat sessions may contain code referencing personal data, internal architecture details, or proprietary business logic. Enterprise admins should assess whether the extended retention period aligns with their data minimisation obligations before September 28.
What should engineering teams do before October 1, 2026?
Four actions before October 1: (1) Audit Copilot seat assignments and remove unneeded seats, because the prepaid-before-access rule means you will be charged upfront on the next billing cycle for every assigned seat. (2) Recalculate your AI credit budget against the reduced 1,900 (Business) or 3,900 (Enterprise) allowances and set spend caps to avoid overages. (3) Review your Copilot Chat usage with your legal team before September 28 in light of the lifetime data retention policy change. (4) Optionally switch Copilot code review from the new default of Balanced back to Lite before September 28 if your team preferred the lighter output.
Sources
GitHub Changelog — Upcoming changes to GitHub Copilot policies and billing (August 28, 2026)
DevOps.com — GitHub Tightens Copilot’s Billing and Governance Rules Ahead of a Busy Fall
CloudZero — GitHub Copilot Enterprise Pricing: Seats, AI Credits, and the September Cliff