Announced 7 Oct 2026 · Sources checked
What did GitHub announce?
The 7 October changelog is titled “Purpose-built model for leaked secret detection.” It says GitHub is sharing plans for AI secret detection across secret scanning alerts, push protection, and GitHub Copilot security reviews, all using a fine-tuned model that “reads surrounding code to identify likely credentials, including passwords without a recognizable token format, without generating code or prose.”
A same-day essay by Erin Havens, GitHub’s product lead for secret scanning, supplies the technical name and the operating numbers. Havens writes that GitHub built a ModernBERT classifier with Microsoft Applied Sciences to extend push protection to unstructured secrets, that the model “assesses a whole set of candidate secrets in less than two milliseconds,” and that putting it in push protection “could more than double the number of secrets that we can prevent.” Those speed and coverage claims are GitHub’s. This publication did not time the classifier or measure prevented leaks.
The useful split is between a model that is already scoring repository text and a product that can refuse a push. Pattern-based detectors still cover partner tokens. The new work is aimed at unstructured strings, such as a password in a database URL. That is a different problem from a backdoored coding-agent model that exfiltrates secrets, which starts after a credential is already on disk.
What do the nine quarters of data show?
Havens’s essay is built around GitHub’s own telemetry, not an independent audit. The headline claim is that developers are being outpaced, not that they have become more careless. The essay says a new secret appears in publicly visible code about once every two seconds, and that the count has doubled yearly for the past three years.
Between the second quarter of 2024 and the second quarter of 2026, GitHub says screened public pushes grew 2.84 times, from 202 million to 574 million, while pushes carrying credentials grew 2.59 times. Across nine complete quarters it reports no statistically detectable trend in per-push prevalence. In the second quarter of 2026 it gives a push prevalence of 0.47 percent with a detected secret, covering supported provider patterns including GitHub’s own tokens.
The same series says the share of push-path blocks overridden by developers fell linearly from 6.63 percent to 3.93 percent, and that mean time to manually revoke a secret “hovers around 40 days.” Those are company counts. We did not reproduce the series.
How does the new classifier work?
GitHub’s application card for security and quality AI features still describes generic secret detection as an expansion of secret scanning that looks for unstructured secrets pattern matching cannot find. Alerts land in a separate “Generic” list under the Security and quality tab. Each alert notes that it was detected using AI. A Copilot subscription is not required. The card says input is limited to text a user has checked into a repository, that the user does not talk to the model directly, and that multiple models may be used to validate a single finding.
The essay adds a constraint GitHub calls the “four-body problem”: precision, latency, throughput, and cost have to hold together if a check is going to sit on the push path. A finding that is fine for later review may not justify blocking a push. A false positive trains people to click through the next block. A check that is too slow or expensive cannot run at the volume GitHub describes.
Havens says the ModernBERT classifier is more precise than existing LLM-based pipelines, cheap enough for the critical path, and able to allow a placeholder such as changeme while still flagging a password-like value in a database URL, a Kubernetes Secret manifest, or a Dockerfile. That is a vendor comparison, not a bake-off we ran. It also does not replace agent sandboxing or least-privilege credentials. A detector that fires after the string is in a working tree is still later than not writing the secret down.
What is live today, and what is still preview?
Three availability lines sit next to each other in the changelog. Customers who already have AI-detected password alerts were automatically upgraded to the new model. AI-detected secrets in push protection are in private preview. AI-based secret scanning inside the Copilot /security-review command for Copilot CLI and the Copilot app is “available soon in private preview.”
The essay repeats that any organization with AI secret detection was updated automatically on 7 October, that those post-push alerts remain included with secret scanning, and that the model is planned for GitHub Enterprise Server 3.23 in public preview, including air-gapped environments. AI push protection is not part of that Server release. The Copilot security-review command is not part of that Server release either.
For push protection, GitHub says the feature will later this month be available to organizations with GitHub Secret Protection on Enterprise Cloud and GitHub Teams, that an administrator must enable it, and that it will consume AI credits. A check can consume credits even if it does not block a push. Usage is billed to the organization that owns the repository, except on user-namespace repositories for enterprise-managed users, where it is attributed to the pusher.
Who can use it, and what does it cost?
The docs page for enabling AI-detected secrets is unchanged in shape: repository Settings, Advanced Security, then Enable next to “Scan for AI-detected secrets.” Organizations turn it on through a custom security configuration that has Secret Protection enabled. You still need GitHub Secret Protection; you do not need Copilot for the alert scans.
Billing splits. Existing AI-detected alert scans stay included in GHSP and GHAS. The new opt-in push-protection checks and the coming Copilot /security-review secret checks will consume GitHub AI Credits. Individual Copilot plans can use the security-review checks without a GHSP license, subject to access controls. Administrators can disable the new capabilities by policy and set a SKU-level budget for “Secret Protection AI Credits.” Budget alerts alone do not stop usage; GitHub tells admins to configure “Stop usage when budget limit is reached” if they want a cap. That is the same class of limit you would treat as a spend control in any API cost plan, not a security guarantee.
What remains unproven?
GitHub did not publish an independent precision or recall study for the new classifier, and we did not run one. “More than double the number of secrets that we can prevent” is a company projection for push protection that is still in preview. The application card still warns that AI-detected strings need human triage. A detector that reads surrounding code can still miss a secret, or flag a test fixture. That is closer to prompt-injection hygiene: useful, incomplete, and not a substitute for not committing the credential.
The 7 October pages also do not say the classifier revokes tokens, rotates keys, or proves a string is live. Partner-program revocation for recognizable issuer tokens is a separate path, described in the essay as reporting public matches so issuers can respond. An internal database password has no such issuer hook.
Common questions
Did GitHub turn on AI push protection for everyone?
No. The changelog and essay say push-time unstructured-secret checks are in private preview, with a wider opt-in preview planned later this month for GHSP customers on Enterprise Cloud and GitHub Teams.
Do I need Copilot to get the new alert model?
No. GitHub’s enabling docs and application card say AI-detected secret alerts need GitHub Secret Protection, not a Copilot subscription. Copilot is relevant for the coming /security-review checks.
Are the new checks free?
The upgraded post-push alerts remain included in GHSP and GHAS. The new opt-in push-protection and Copilot security-review checks will consume AI Credits once you opt in and billing begins.
What to remember
GitHub has swapped the model behind existing AI password alerts and published a preview path for push-time and Copilot checks. Use the live alerts if you already pay for Secret Protection. Do not plan as if unstructured secrets are blocked on every push.
Sources & further reading
How this story was made
Written by Kristian Kostov with AI assistance and checked against the linked sources. Company performance claims are attributed to the company. Analysis reflects AiLookout’s interpretation; we have not independently tested the products discussed. Cover photography is illustrative and does not depict the specific announcement or product.
Our editorial standards





