You are fully responsible for keeping your GitHub account secure and for everything that happens under your account, even if someone else posts content using your credentials.
This analysis describes what GitHub's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The account responsibility clause assigns liability for all account activity to the account holder, including unauthorized access by third parties, which means users may be held responsible for policy violations or content posted by others who gained access to their account.
GitHub's updated Terms of Service now include an explicit section governing AI features, including Copilot. The new section establishes specific contractual terms for how user data may be collected, used, and retained for developing and improving AI and machine learning models, and identifies what controls are available to users. The practical effect is that AI-related data practices are now consolidated under dedicated contractual language rather than dispersed across general service terms.
View change record →GitHub's Terms of Service update on April 19, 2026 involved substantial revisions across 54 sentences, with 40 sentences removed and 4 added. The extent of change suggests modifications to core service provisions; however, without access to the specific language that was modified, removed, or added, the precise operational implications for users cannot be determined. Users should review the updated Terms directly to understand how the changes affect their usage rights, account obligations, or dispute resolution procedures.
View change record →Previous version had no excerpt; current version includes full language clarifying user liability for account security and all activities under that account.
View full change record →All activity under your GitHub account is your responsibility under these terms, even if your account is accessed without your permission by a third party. Enabling two-factor authentication and monitoring account activity are the primary ways to reduce exposure under this provision.
How other platforms handle this
If we learn that we've collected the personal data of a child under the age of 13 or 16, as applicable, we'll take reasonable steps to delete the personal data. This may require us to delete the Skillshare account...
If our moderators decide to remove content, or suspend or terminate the Member's account, we will notify the Member and explain how to contact us.
If we become aware that a child has provided us with personal data without parental consent, we remove such data and terminate the child's account (except where we are required to retain all or a portion of such data for compliance purposes).
"You are responsible for maintaining the security of your account and password. GitHub cannot and will not be liable for any loss or damage from your failure to comply with this security obligation. You are responsible for all content posted and activity that occurs under your account (even when content is posted by others who have access to your account). You may not use another User's account without permission.Excerpt from GitHub's Terms of Service
REGULATORY LANDSCAPE: The account holder responsibility clause may interact with data protection obligations under GDPR where a compromised account is used to process or expose personal data.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The account responsibility clause assigns liability for all account activity to the account holder, including unauthorized access by third parties, which means users may be held responsible for policy violations or content posted by others who gained access to their account.
All activity under your GitHub account is your responsibility under these terms, even if your account is accessed without your permission by a third party. Enabling two-factor authentication and monitoring account activity are the primary ways to reduce exposure under this provision.
ConductAtlas has identified this type of provision across 277 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by GitHub.