One in three pull requests on GitHub now involves an AI agent, up from fewer than one in 10 a year ago. Should that rate continue, most code pushed to GitHub could be agent-written within two years, and much of it may never be fully read by a human.
The data behind this shift does not support the idea that developers have grown careless. Between Q2 2024 and Q2 2026, screened pushes grew 2.84 times while pushes carrying credentials grew 2.59 times. Across nine complete quarters, no statistically detectable trend in per-push prevalence appeared. Override rates for push-path blocks fell linearly from 6.63% to 3.93% — evidence that developers understand the risk and are less willing to accept it. They are being outpaced, not becoming indifferent.
Publicly visible code gains a new secret roughly every two seconds, a figure that has doubled yearly for three years. At a fixed detection rate, doubling activity doubles expected exposures, and if each exposure needs the same human response, so does the workload. Manual revocation averages around 40 days, with roughly one in five secrets taking more than 90 days to revoke. Faster code creation therefore leaves credentials usable for weeks or months.
Where prevention works today
GitHub's secret scanning partnership program connects more than 150 technical partners, who build out detectors and receive reports of public exposures. In Q2 2026, public scanning reported an average of 26 credential matches per second, repeat observations included. Many partners revoke immediately on notification — OpenAI API keys, Google Cloud account credentials, Slack webhooks, Hugging Face user tokens and SendGrid keys among them. The owner may still need to replace the token, but revocation no longer waits on a developer processing an alert.
Push protection intervenes one step earlier, stopping recognizable credentials before they enter repository history so the developer or agent can fix the change first. Detector precision is tuned with partners until defaults are safe to enable. In the past month, push protection blocked a secret at least once per second, and for issuer-bound credentials GitHub blocks more secrets than slip through.
Including additional secret types, push protection stops about 30% of newly detected secrets before they reach repository history. The remaining 70% are found only after the credential is already lost. Prevention scales with compute; remediation still scales with people. Refusing a push costs compute, while cleaning up a secret exposed in visible history costs a developer time and attention.
Four coupled constraints at the push boundary
Before a secret crosses the push boundary, blocking it is cheap and the decision is binary. After it crosses, the same string can authenticate against a real system and the cost is unbounded. In many cases the only detection clue is the surrounding code and world context: a provider-issued token may carry a recognizable prefix, while an internal database password may be entirely unstructured.
Context-aware judgement must be balanced against three other factors. GitHub calls this the four-body problem for secret protection: precision, latency, throughput and cost are coupled. A finding suitable for later review may not justify blocking a push, and a false positive interrupts a developer and erodes trust in the next block. A check that is too slow, expensive or hard to scale limits how often it can run.
A fine-tuned classifier for unstructured secrets
Built with Microsoft Applied Sciences, the ModernBERT-based classifier assesses candidate secrets in context without generating code or prose. It is more precise than existing LLM-based pipelines and evaluates candidate batches in under two milliseconds, cheaply enough to run in the critical path at scale. GitHub says it could more than double the number of secrets prevented.
- The push protection feature is in private preview and will reach organizations with GitHub Secret Protection on Enterprise Cloud and GitHub Teams later this month. It consumes AI credits.
- Organizations with AI secret detection are automatically updated to the new model. Alerts opened from these post-push scans stay included with a secret scanning purchase at no additional cost.
- The model ships with GitHub Enterprise Server 3.23 in public preview, bringing AI-detected alerts to Secret Protection customers in air-gapped environments.
- The classifier is also added to the
/security-reviewcommand for the Copilot CLI and Copilot App, so Copilot users can address secrets before a push without a GitHub Secret Protection plan. AI credit usage is attributed to GitHub Secret Protection in AI usage insights.
The target is a workflow where developers can hand more work to agents without supervising every request, and where the headcount needed to keep credentials safe no longer scales with the volume of code written.



