GitHub's new secret-detection model catches passwords that regex can't. Check the billing before you opt in
AI push protection is in private preview, and it spends AI Credits even on pushes it doesn't block.

GitHub has swapped the engine behind its AI-detected secret alerts for a purpose-built model, and it’s now using the same model for two new checks aimed at the places agent-written code tends to leak: the push, and the review. The details are in GitHub’s changelog entry for October 7 .
The model is fine-tuned for one job. It reads the code around a candidate string to decide whether it’s a real credential, which is how it can flag passwords that have no recognizable token format. That’s the gap pattern matching leaves open. A ghp_ prefix is easy to match; db_pass = "hunter2-prod" in a config an agent helpfully scaffolded is not. GitHub says the model doesn’t generate code or prose.
What changes and what doesn’t
Existing AI-detected alerts have already moved to the new model, and customers with AI-detected Password alerts were upgraded automatically. Those alerts stay included with GitHub Secret Protection (GHSP) and GitHub Advanced Security (GHAS) at no extra charge.
Two things are new, and both are opt-in:
- AI push protection checks pushes for unstructured credentials, so a secret can be stopped before it lands in history. Private preview.
- Secret checks inside Copilot
/security-review, which GitHub describes as a read-only review of your active changes that returns prioritized findings. Listed as coming soon, with a private preview planned for Copilot CLI and the Copilot app.
On GitHub Enterprise Server, only AI-detected alerts arrive, in public preview in 3.23. Push protection and the review command aren’t part of the Server release.
The billing catch
Both new checks consume GitHub AI Credits, with usage starting “in the coming weeks” per the changelog. For push protection, usage is billed to the repository’s owning organization under a “Secret Protection AI Credits” SKU. It can accrue even when a push isn’t blocked.
That matters if your agents push often: usage isn’t tied to pushes that get blocked, so a busy fleet can run up credits without a single alert. Watch the SKU in your first billing cycle.
The checks are off by default, and running /security-review doesn’t switch them on. Admins can disable them by policy and set budgets. One gotcha: budget alerts don’t stop spending. To enforce a cap, turn on “Stop usage when budget limit is reached” where it’s available. The dedicated budget lives under Billing and licensing, Budgets and alerts, as a SKU-level budget with Advanced Security as the product and Secret Protection AI Credits as the SKU.
If you’re already in the push protection private preview, usage will start consuming credits once the change takes effect. Disable it beforehand if you don’t want that.
What GitHub doesn’t say
The changelog gives no detection rates, no false-positive numbers and no AI Credit prices; it points to the billing docs for rates. So there’s no way yet to judge how often it flags a harmless test fixture or misses a real password. A sensible trial is one noisy repository with a budget cap set first, then a look at the alerts it raises against what your existing scanner already catches.
Plan eligibility is also split. Individual Copilot plans can use the security review checks without a GHSP or GHAS license. Push protection on Team and Enterprise Cloud needs paid GHSP or GHAS coverage, and a Copilot Business or Enterprise seat doesn’t substitute for it.