Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The terms require users to comply with the GitHub Acceptable Use Policies, the Microsoft Generative AI Services Code of Conduct, and the Microsoft Customer Copyright Commitment Required Mitigations. These govern both the inputs users submit and the outputs they generate using Copilot.
This analysis describes what GitHub's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision incorporates three external policy documents by reference, including a Microsoft policy, creating a multi-document compliance obligation. The Required Mitigations at aka.ms/AIfilters establish specific technical and procedural obligations that apply alongside the GitHub Acceptable Use Policies.
Under these terms, users are bound by the GitHub Acceptable Use Policies, the Microsoft Generative AI Services Code of Conduct, and the Microsoft Customer Copyright Commitment Required Mitigations, all incorporated by reference. Violations of any of these documents may constitute a breach of the agreement.
Cross-platform context
See how other platforms handle Acceptable Use and AI Code of Conduct and similar clauses.
Compare across platforms →Monitoring
GitHub has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Your use of GitHub Copilot is subject to the Acceptable Use Policies, the AI Code of Conduct, and the Required Mitigations. For example, you may not prompt GitHub Copilot with content that is unlawful or otherwise prohibited by the Acceptable Use Policies, and you may not use GitHub Copilot to generate Suggestions whose use you know (or reasonably should know) would be unlawful or would infringe on the rights of others.Excerpt from GitHub's Copilot Product Terms
(1) REGULATORY LANDSCAPE: The incorporation of the Microsoft Customer Copyright Commitment Required Mitigations engages copyright law frameworks relevant to AI-generated output, including DMCA provisions in the US and EU Copyright Directive obligations. The AI Code of Conduct reference engages the evolving EU AI Act framework, which may impose additional obligations on deployers of AI tools in regulated contexts. (2) GOVERNANCE EXPOSURE: Medium. The incorporation of three separate external documents by reference creates a compliance obligation that extends beyond the terms of this document alone. Organizations must independently monitor each referenced document for changes, as updates to the Acceptable Use Policies, AI Code of Conduct, or Required Mitigations would affect the applicable obligations under this agreement. (3) JURISDICTION FLAGS: EU/EEA organizations should evaluate whether the Microsoft Generative AI Services Code of Conduct and Required Mitigations satisfy EU AI Act compliance obligations for AI system deployers. Organizations in jurisdictions with sector-specific AI governance requirements (financial services, healthcare) should assess whether the referenced policies are sufficient for their regulatory context. (4) CONTRACT AND VENDOR IMPLICATIONS: The incorporation of Microsoft-authored policy documents into a GitHub agreement reflects the Microsoft-GitHub corporate relationship and creates a vendor dependency for compliance purposes. Procurement teams should note that changes to any of the three referenced documents could modify the applicable obligations without requiring amendment to this agreement. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should maintain current copies of all three referenced documents and establish a monitoring process for updates. Internal acceptable use policies governing Copilot should be aligned with the requirements of all three incorporated documents, not solely the GitHub Acceptable Use Policies. Legal teams should assess whether the 'reasonably should know' standard in the Acceptable Use obligation creates a due diligence requirement that necessitates formal review procedures for Suggestion use.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision incorporates three external policy documents by reference, including a Microsoft policy, creating a multi-document compliance obligation. The Required Mitigations at aka.ms/AIfilters establish specific technical and procedural obligations that apply alongside the GitHub Acceptable Use Policies.
Under these terms, users are bound by the GitHub Acceptable Use Policies, the Microsoft Generative AI Services Code of Conduct, and the Microsoft Customer Copyright Commitment Required Mitigations, all incorporated by reference. Violations of any of these documents may constitute a breach of the agreement.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by GitHub.