GitHub AI Code Generation Surge Triggers Secret Protection Expansion
Between Q2 2024 and Q2 2026, the volume of AI-generated pull requests on GitHub surged as one in three pull requests now involves an AI agent, up from fewer than one in 10 a year prior, according to GitHub data reported by the official GitHub Blog. Public pushes grew 2.84 times over the nine quarters ending in Q2 2026, while pushes carrying exposed credentials grew 2.59 times. To counter this accelerated software creation rate, GitHub announced the deployment of a fine-tuned ModernBERT classifier built with Microsoft Applied Sciences that assesses candidate secrets in under two milliseconds.
Push Protection Scaled by Compute and Microsoft Classifier
The new classifier evaluates candidate batches using surrounding code context without generating code or prose, achieving higher precision than existing large language model pipelines. The model processes unstructured database passwords, Kubernetes Secret manifests, and Dockerfiles to distinguish actual secrets from placeholder text like changeme. This capability allows GitHub to more than double the number of secrets it prevents from entering repository history.
Push protection stops approximately 30 percent of newly detected secrets before they reach visible history, while post-scan alerts capture the remaining 70 percent. Technical partners in GitHub’s secret scanning partnership program—including OpenAI, Google Cloud, Slack, Hugging Face, and SendGrid—covered more than 150 technical partners by Q2 2026. These integrations reported an average of 26 credential matches per second.
Developer Carelessness Claims Challenged by Nine Quarters of Data
GitHub’s nine-quarter analysis challenges the public perception that AI tools make developers more careless. The data shows no statistically detectable trend indicating an increase in per-push secret prevalence. Furthermore, developers demonstrate heightened risk awareness, as the share of push-path blocks overridden by developers declined linearly from 6.63% to 3.93% between Q2 2024 and Q2 2026.
Despite this caution, human remediation struggles to keep pace with automated code generation. The mean time to manually revoke an exposed secret hovers around 40 days, with roughly one in five exposures taking more than 90 days to resolve.

Deployment Timeline Across GitHub Enterprise and Copilot Surfaces
Later this month, GitHub will roll out the feature to organizations with GitHub Secret Protection across Enterprise Cloud and GitHub Teams, consuming standard AI credits.
How Does the ModernBERT Classifier Evaluate Secrets?
How fast does the new ModernBERT classifier evaluate potential secrets?
The classifier assesses a whole set of candidate secrets in less than two milliseconds, allowing it to run within the critical push path without causing noticeable latency for developers.
What percentage of newly detected secrets does push protection successfully stop?
Push protection intercepts roughly 30 percent of newly detected secrets before they enter repository history, while the remaining 70 percent are identified through post-push scanning.
Which environments receive the new classifier in GitHub Enterprise Server 3.23?
The model ships in public preview with GitHub Enterprise Server 3.23, bringing AI-detected alerts to Secret Protection customers operating within air-gapped environments.
Worth a look