Skip to content
The AI-First Web

GitHub's opt-in AI push protection can use credits even when it blocks nothing

Two new opt-in checks that read code in context will be metered. AI-detected alert scanning stays included.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
GitHub's opt-in AI push protection can use credits even when it blocks nothing
In brief
  • GitHub announced a fine-tuned model that reads surrounding code to find likely credentials, including passwords with no recognizable token format.
  • AI-detected alert scanning stays included for GHSP and GHAS customers. Opt-in AI push protection can consume credits even if it blocks no push.
  • The Copilot security-review checks add AI Credit usage once an organization opts in. Set a budget with a spending cap before anyone enables them.

AI detection already powers alerts and now reaches push time

A password in a config file looks like any other text. Scanners built on known token formats have little to match. GitHub's new model takes another approach.

On October 7, GitHub described a fine-tuned model for finding leaked secrets. It reads the code around a string to judge whether it is likely a credential. That includes passwords with no recognizable token format. GitHub says the model does not generate code or prose.

The lesson here is that judgment-based detection is spreading from alerts into push time and Copilot code review. In those two new places, it is metered. That is our interpretation, not GitHub's claim.

Private preview
Release status of AI push protection
Source: GitHub changelog (October 7, 2026)

What stays included

Alert scanning that already used AI detection switched to the new model on October 7. The upgrade adds no fee for holders of GitHub Secret Protection (GHSP) or GitHub Advanced Security (GHAS).

The same alerts are also coming to GitHub Enterprise Server 3.23 in public preview. They come with an enterprise's current GHSP and GHAS purchase.

GHES 3.23
GitHub Enterprise Server version for AI-detected alerts
Source: GitHub changelog (October 7, 2026): public preview, included with GHSP and GHAS

Only two new opt-in checks are planned to be metered. Both will use GitHub AI Credits.

Two opt-in checks, two different bills

The first is AI push protection. It looks for credentials with no fixed format at the moment of a push. The developer can remove the secret before it lands in repository history. The feature is in private preview. It needs Enterprise Cloud or Teams, plus GHSP or GHAS. An administrator must turn it on, within company policy.

The second lives inside Copilot. Developers can run a command called /security-review in the Copilot command-line tool or the Copilot App. It scans unfinished changes for security flaws and suggests fixes. GitHub describes the review as read-only.

GitHub is adding secret classifier checks to that review. They will add AI Credit usage on top of what the review already uses. They are off by default, and running the command does not switch them on. No GHSP or GHAS license is needed. They are coming soon in private preview.

A check can cost credits even when it blocks nothing

GitHub warns that a push protection check may draw down credits even when the push goes through unblocked. The notice does not say how often that happens. It does not say every push is billed.

The charge goes to the organization that owns the repository. One exception covers enterprise-managed users working in their own namespace. There, usage counts against the pusher's allocated credits. The Copilot checks go to the billing account behind the active Copilot plan.

Billing for either check starts only after an organization opts in and turns the feature on. AI push protection usage appears under the Secret Protection AI Credits SKU in AI usage insights. A SKU is one billable product code. The Copilot checks are reported under GHSP in those same insights.

GitHub says credit usage for these checks arrives in the coming weeks. The announcement gives no per-check price.

One instruction is aimed at software, not people. GitHub tells coding agents to get explicit permission before enabling paid features or changing budgets and policies. A billing notice now sets rules for the tools that write code.

Controls exist, but someone must set them

Administrators at the organization or enterprise level will be able to turn the new checks off by policy. They can also set budgets. Opting in does not override either control.

To create a dedicated budget, open Billing and licensing, then Budgets and alerts. Scope it to one SKU. The product is Advanced Security. The SKU is Secret Protection AI Credits.

An alert by itself does not halt spending. A cap requires the setting "Stop usage when budget limit is reached", where it is available.

Teams already trying AI push protection in private preview face a coming billing change, due in the coming weeks. Once it takes effect, continued use will consume credits. GitHub advises turning it off first if you want to avoid that.

What to ask your team this week

Ask who owns the Secret Protection AI Credits budget and who receives its alerts. Ask whether a spending cap is set, since an alert alone stops nothing.

List every team using AI push protection in private preview. Decide whether each should keep it once billing begins.

Name who may approve credit-using checks, for developers and for coding agents. Ask GitHub for the per-check rate before anyone opts in.

Older scanners asked whether a string matched a known key. The new model asks whether it looks like a secret. Alert scanning already works that way and stays included. Push protection and security review now extend it, and there some answers can carry a charge. Set the budget before you switch it on.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: GitHub.

Share this insight