Skip to main content

GitHub AI secret detection: what to switch on and what it costs

GitHub has a purpose-built model for spotting leaked secrets across secret scanning alerts, push protection and the Copilot security review command. What is included, what will consume AI Credits, and how teams using coding agents should roll it out.

Share -
A software engineer in an office studies a monitor showing a red CRITICAL ERROR warning over dark security dashboards, hand raised to their chin

GitHub now uses a purpose-built model to find leaked secrets, including passwords with no recognisable token format. Existing AI-detected password alerts switch to it at no extra charge, while new push protection and Copilot security review checks are opt-in and will consume AI Credits. Teams should decide who can switch those on before agents start pushing code.

What was released

A purpose-built model for leaked secret detection was announced by GitHub on 7 October 2026 in the GitHub changelog. GitHub describes it as a fine-tuned model that reads the code around a value to judge whether it is a credential, and that does not generate code or prose. It is being brought into three places: secret scanning alerts, push protection, and the Copilot /security-review command.

What actually changed

The announcement gives a different status for each surface:

  • Secret scanning alerts: customers with AI-detected password alerts have been moved to the new model automatically. These scans stay included in GitHub Secret Protection (GHSP) and GitHub Advanced Security (GHAS) at no additional charge.
  • Push protection: AI-detected secrets in push protection is in private preview. It checks for unstructured credentials at push time, before a secret enters repository history. It needs GitHub Team or GitHub Enterprise Cloud with GHSP or GHAS, and an administrator must enable it.
  • Copilot /security-review: checks from the secret classifier will be added alongside the existing LLM-based review in Copilot CLI and the Copilot app, in private preview soon. No GHSP or GHAS licence is needed, and the checks are off by default.
  • GitHub Enterprise Server: the model is planned for AI-detected alerts in GHES 3.23 in public preview, included with GHSP or GHAS. Push protection and the security review command are not part of that Server release.

How the billing works

GitHub has published the billing model ahead of wider availability, which is the detail most teams will need to plan around. The push protection checks and the security review checks consume GitHub AI Credits, starting once an organisation opts into the preview and enables the feature.

  • Push protection usage is billed to the organisation that owns the repository, reported under a Secret Protection AI Credits SKU, and not taken from any user's allocated credits. The exception is user-namespace repositories for Enterprise Managed Users, where usage is attributed to the pusher.
  • A check can consume credits even if it does not block a push. Cost follows push volume, not the number of secrets found.
  • Security review usage goes to the billing account of the active Copilot plan, on top of the review's existing usage.

GitHub also states that running /security-review will not turn the new checks on, and that agents should not enable credit-consuming features or change policies or budgets without explicit authorisation.

What it means for teams building with AI agents

Coding agents write and push more code, faster, and they copy configuration and connection strings from wherever they find them. Format-based scanners catch tokens with a known prefix, but a plain database password in a config file has no pattern to match. A context-aware model closes some of that gap. In CodeDTX's view, these are the practical steps:

  1. Check that the included upgrade is working. If you already have GHSP or GHAS with AI-detected password alerts, the new model is already on. Review the next batch of alerts for false positives and missed cases before trusting it further.
  2. Pilot push protection where agents push most. Blocking a secret at push time is cheaper than rotating it after it lands in history. Because every check can consume credits, start with the repositories where agents and automated workflows push, and set a budget before you enable it widely.
  3. Make /security-review part of the agent's routine, not a replacement for scanning. It is read-only and suits a step before commit or pull request. Treat it as a second check alongside push protection and code review, as in what AI agent evals catch.
  4. Keep the opt-in decision with people. GitHub's own note that agents should not switch on paid features matches a wider rule: an agent's permissions should not include changing its own budget or policy. See AI agent skills security and governance and controlling AI agent running costs.
  5. Reduce what agents can leak in the first place. Detection is a safety net. Scoped, short-lived credentials and sandboxed tool access, as in Copilot local sandboxing, limit the damage when something slips through.

When not to rely on it

Push protection and the security review checks are previews, and the security review checks have not shipped yet, so neither should be the only control in a compliance argument today. GHES customers get the improved alerts but not push protection or the review command in 3.23. Secrets that reach logs, tickets or prompts rather than repositories are outside what this covers; our guide on keeping personal data out of AI agent logs deals with that side.

Frequently asked questions

What is GitHub's new secret detection model?

It is a fine-tuned model GitHub built for finding leaked credentials, announced on 7 October 2026. It reads the code surrounding a value to decide whether it is likely to be a secret, which lets it flag passwords that have no recognisable token format. GitHub says it does not generate code or prose. It powers AI-detected secret alerts and is coming to push protection and Copilot security review.

Does the new model cost extra for existing GitHub Advanced Security customers?

Not for alerts. AI-detected secret alerts have switched to the new model automatically and remain included in GitHub Secret Protection and GitHub Advanced Security at no additional charge. The new opt-in checks are different: AI push protection and the secret checks in the Copilot security review command consume GitHub AI Credits once an organisation or user opts into the preview and enables them.

Who pays for AI push protection checks?

The organisation that owns the repository. Usage is reported under the Secret Protection AI Credits SKU and does not come from any individual user's allocated credits. The exception is user-namespace repositories for Enterprise Managed Users, where usage is attributed to the person pushing. A check can consume credits even when it does not block the push, so cost tracks push volume.

Do you need a GitHub Advanced Security licence to use the Copilot security review checks?

No. GitHub says the secret classifier checks in the Copilot security review command do not need a GHSP or GHAS licence. They are off by default, and running the command does not enable them. Usage goes to the billing account of your active Copilot plan, in addition to the review's existing usage, and individual and business Copilot plans are listed as eligible.

Is AI secret detection available on GitHub Enterprise Server?

Partly. GitHub plans to bring the new model to AI-detected alerts in GitHub Enterprise Server 3.23 as a public preview, included with an existing GHSP or GHAS purchase. AI push protection and the Copilot security review command are not part of that Server release, so GHES teams should keep their current push-time controls and review steps in place.

Share this post

Contact us to build the right product

Talk to our engineers about your application, the systems it connects to, and what you want to build next.

Get in touch
Two people discussing work with a laptop