On October 7, 2026, GitHub announced a purpose-built model for secret detection, upgrading context-aware credential scanning for security teams and developers. Existing AI password-alert users receive the model automatically without an additional scanning charge. Its use in push protection is in private preview; a Copilot review integration is also planned.
The decision is where to intervene. Alerts flag possible exposures after code lands; push protection intervenes at the repository boundary; a developer review can happen earlier. Choose the layer your workflow needs, then check who can enable it and whose account pays.
Separate alerting, push protection and developer review
GitHub Secret Protection (GHSP) or GitHub Advanced Security (GHAS) coverage should not be confused with a Copilot subscription. This is the announced access and billing split, not a claim that every account can use every feature today.
Workflow | Access and release status | Cost treatment | Use it for |
|---|---|---|---|
AI-detected alerts | Existing users upgraded automatically. Enabled Secret Protection is required; Copilot is not. | Finding potential exposures for a triage queue. | |
AI push protection | Private preview; paid GHSP/GHAS on Team or Enterprise Cloud, with administrator enablement. | AI Credit usage at the billing transition. | A centrally managed check as code enters repository history. |
Classifier in | Private preview coming soon; no GHSP/GHAS required. Separate opt-in, off by default. | Extra credits at the billing transition, charged to the active Copilot billing account. | An earlier check within a developer’s review workflow. |
The CLI security-review specialist already exists and is read-only; the app’s review command is already in public preview. Neither fact establishes access to the new classifier. Running the command does not enable it. Read-only describes editing authority, not whether a review consumes billed resources.
GHES 3.23 is planned to add AI alerts in public preview, including air-gapped environments. That Server release excludes AI push protection and Copilot security review; AI push protection on ghe.com also remains planned.
Assign the budget to the account that pays
GitHub’s billing notice specifies three details to check before rollout:
Metering starts with public-preview opt-in and enablement in the coming weeks; continuing private-preview users also become billable.
Push checks can consume credits without blocking. Repository-owner organizations pay outside individual allocations; Enterprise Managed User namespace repositories instead use the pusher’s allocation.
The dedicated budget SKU is Advanced Security → Secret Protection AI Credits. Review-check usage appears under GHSP even without that license.
Our recommendation: name the charged account’s budget owner before approving a rollout. A developer’s personal Copilot limit is not sufficient assurance for organization-owned push checks. For coding agents, keep permission to inspect code separate from permission to enable paid checks or change spending controls.
A budget notification is not a cap. GitHub’s budget documentation distinguishes threshold emails from the stop-usage option, where available. Review overlapping scopes too: an exhausted blocking budget can stop metered usage even when another budget has room. The inspected material does not establish whether exhausting this detector’s budget allows or rejects a push; confirm that behavior before relying on it for enforcement.
Keep the base license separate from incremental checks. GitHub lists Secret Protection at US$19 per active committer per month. Its estimator counts active committers over the preceding 90 days and avoids counting the same covered committer again across repositories. Illustrative calculation: 50 distinct billable committers × US$19 = US$950/month for that license component, not US$950 per repository. This assumes list pricing without discounts and excludes hosting, Copilot, taxes and metered extras.
For Copilot Business and Enterprise, one AI Credit represents US$0.01. That conversion does not tell you the price of a detector check. The inspected announcement and billing material do not establish a per-check rate, so a dollar-per-push estimate would be speculative. Confirm applicable allowances rather than assuming every Secret Protection charge draws from the same Copilot pool.
Check detection limits before enforcing blocks
GitHub describes a fine-tuned ModernBERT classifier developed with Microsoft Applied Sciences that evaluates candidate credentials in code context without generating prose. GitHub reports candidate-batch inference below two milliseconds and says the model could more than double the secrets it can prevent. Those are vendor claims, not independent measurements of end-to-end push latency, false blocks or customer outcomes.
The supported-pattern reference still states that password push protection and validity checks are unsupported. That differs from the dated private-preview announcement. Treat the preview as a separately gated capability, not general password support, and do not assume it verifies whether a detected password actually works.
Alert visibility also has limits. GitHub’s alert documentation says generic alerts are absent from security-overview summary views and AI-detected secrets show only their first detected location. The generic list is capped at 5,000 alerts per repository, including closed alerts. A quiet summary dashboard is therefore not an inventory of every potential exposure.
Make a bounded rollout decision
Already using AI alerts? Review findings and triage capacity after the automatic upgrade. There is no reason to buy Copilot solely for this alert feature.
Enabling alerts for the first time? For eligible repositories, follow GitHub’s alert-enablement instructions: Settings → Advanced Security → Secret Protection → Scan for AI-detected secrets. Organization-wide rollout uses a custom security configuration. These steps do not enroll you in either new preview.
Need preventive enforcement? Choose a small repository scope once access is available. Agree who handles false blocks, who owns spending and what happens if checks become unavailable before expanding.
Want earlier developer feedback? Use review as an additional check, not a replacement for repository policy. A voluntary review can be skipped; a central push check serves a different enforcement role.
For a pilot, record actionable findings, missed known cases, false interruptions, triage time and attributable credits by repository and language. These are proposed acceptance criteria, not results from a test. RohitAI’s GitHub ReviewBench guide explains how to assess reviewer quality and noise; its benchmark does not validate this secret classifier.
Methodology: AI-assisted reporting and analysis based on GitHub’s October 7 announcements, official documentation and pricing, rechecked on October 7, 2026. No hands-on detector test or production pilot was performed. The license calculation is illustrative; preview timing and account-specific charges remain subject to GitHub’s rollout and billing terms.
