
GitHub AI Secret Detection: How Push Protection Gets Smarter
GitHub is adding a ModernBERT classifier to push protection that spots unstructured passwords in under 2 ms and could more than double blocked secrets.
GitHub is giving its push protection feature a machine-learning upgrade. In a post published October 7, 2026, the company announced a fine-tuned ModernBERT classifier, built with Microsoft Applied Sciences, that can recognize secrets with no predictable pattern, such as an internal database password, and stop them before they ever land in a repository's history. GitHub says the change could more than double the number of secrets it prevents from leaking.
- Model: a fine-tuned ModernBERT classifier that judges candidate secrets in context, without generating code or prose.
- Speed: evaluates a batch of candidate secrets in under 2 ms, fast enough to sit in the push path.
- Rollout: private preview now; GitHub plans to release it later in October 2026 for organizations with GitHub Secret Protection on Enterprise Cloud and Team plans, consuming AI credits.
- Also shipping in GitHub Enterprise Server 3.23 (public preview, including air-gapped setups) and the /security-review command in Copilot CLI and Copilot App.
Why Do Unstructured Secrets Slip Through?
Traditional secret scanning works best on credentials with a recognizable shape, like cloud provider keys that start with a known prefix. A generic password assigned to a variable has no such fingerprint, which makes it hard to catch with pattern matching alone without drowning developers in false alarms. A classifier that reads the surrounding code can tell the difference between a real credential and a harmless placeholder, which is exactly where AI earns its keep.
GitHub's own numbers explain the urgency. Between Q2 2024 and Q2 2026, public pushes grew from 202 million to 574 million, and in Q2 2026 about 0.47% contained a detected secret. GitHub says a new secret appears in publicly visible code roughly every two seconds.
How Effective Is GitHub Push Protection Today?
According to GitHub, push protection currently stops about 30% of newly detected secrets before they enter repository history; the other 70% are found after exposure. That gap is costly, because manual revocation takes about 40 days on average, and roughly one in five exposed secrets takes more than 90 days to revoke. Blocking more secrets at push time means fewer emergency key rotations later.
There is encouraging news on developer behavior too. GitHub reports that the share of push blocks developers override has fallen steadily from 6.63% to 3.93%, a sign that teams increasingly trust the warnings and fix the problem instead of bypassing it. Help Net Security's coverage confirms the figures and the rollout timeline.
How Can Copilot Users Check for Secrets?
One of the most practical parts of the announcement: GitHub is adding the classifier to the /security-review command in Copilot CLI and Copilot App. That lets developers catch secrets before they push, even if their organization does not pay for a Secret Protection plan. Existing AI secret detection customers are moved to the new model automatically, and post-push alerts remain included at no additional cost.
The Bigger Picture for AI-Era Development
GitHub notes that roughly a third of pull requests on the platform now involve an AI agent, up from fewer than one in ten a year earlier. More code, written faster, means more chances for a credential to sneak into a commit. Putting a fast, context-aware model directly in the push path is a sensible, defense-in-depth answer: it scales with the code instead of relying on humans to spot every slip.
For related reading, see how GitHub's AI taskflows helped find Android vulnerabilities and our guide to keeping MCP server credentials out of Git. More defensive tooling news is in our AI security section.
Sources: GitHub Blog — October 7, 2026; Help Net Security — October 8, 2026.
More Ai Security Stories

Anthropic Cyber Verification Program: Which Tier Fits You?
Anthropic split its Cyber Verification Program into 3 tiers, Defense, Red Team and Specialized, giving vetted defenders broader Claude access for security.

SailPoint Autonomous Agents: Identity Security for AI Agents
SailPoint launched Autonomous Agents and just-in-time access at Navigate 2026, citing a survey where 79% of firms run AI agents but only 2% govern them.

Apple Full Disk Access Changes: What Mac Users Should Know
Apple says new macOS controls will make Full Disk Access require very explicit user action as AI agents grow more capable. Here is what is known so far.
