GitHub Introduces New Purpose-Built Secret Detection Model
GitHub is expanding its secret protection capabilities with a new purpose-built model designed to catch exposed credentials and unstructured passwords across developer workflows.

Context-Aware Secret Detection
Secret protection should keep pace with modern software development, whether code is written independently or alongside an AI agent. To address this, GitHub has announced a new purpose-built model designed to bring context-aware detection into additional developer workflows, helping teams catch exposed credentials before they reach production. According to the [GitHub Changelog](https://github.blog/changelog/2026-10-07-purpose-built-model-for-leaked-secret-detection/), the new fine-tuned model reads surrounding code to identify likely credentials—including passwords that lack a recognizable token format—without generating code or prose. Further details are available from GitHub Changelog in the original source material.
As part of this rollout, existing AI-detected password alerts have been automatically upgraded to the new model. These alert scans remain included with GitHub Secret Protection (GHSP) and GitHub Advanced Security (GHAS) at no additional charge.
Push Protection and Enterprise Availability
AI-detected secrets in push protection are currently available in private preview. This feature checks for unstructured credentials at push time, offering developers an opportunity to remove sensitive secrets before they enter repository history. The feature will be accessible to customers on GitHub Enterprise Cloud or GitHub Teams who purchase GHSP or GHAS, provided an administrator enables it in accordance with organizational policies.
Additionally, the new model will bring AI-detected alerts to GitHub Enterprise Server (GHES) 3.23 in public preview. This capability is included as part of an enterprise's existing purchase of GHSP and GHAS.
Integration with GitHub Copilot Security Reviews
GitHub is also integrating AI-based secret scanning into the Copilot security review command. In a supported Copilot CLI or Copilot App session, developers can utilize the feature before committing, pushing, or requesting pull request reviews to evaluate active changes for security vulnerabilities.
Developers can find further details and instructions by consulting the [Copilot CLI security-review agent documentation](https://docs.github.com/copilot/concepts/agents/copilot-cli/about-custom-agents#built-in-agents) as well as the [security-review instructions for Copilot App sessions](https://docs.github.com/copilot/how-tos/github-copilot-app/agent-sessions#using-security-review-in-app-sessions). These new checks from the secret classifier will run alongside existing LLM-based reviews, though they are turned off by default and require explicit opt-in.
Billing Models and AI Credit Consumption
While standard alert scans remain included at no extra cost, the new opt-in checks for push protection and the Copilot security review command will consume GitHub AI Credits. Billing will begin as soon as an organization opts into the public preview and enables the features.
Administrators looking to control expenditure can configure specific financial boundaries. Organizations can visit [budget settings](https://docs.github.com/billing/how-tos/set-up-budgets) to establish dedicated spending limits, select advanced security products, and manage Secret Protection AI Credits. For comprehensive financial planning, teams should review the official [documentation for usage-based billing](https://docs.github.com/enterprise-cloud@latest/copilot/concepts/billing-and-usage/organizations-and-enterprises/billing) to ensure transparent tracking of consumption metrics.
Sources
- GitHub ChangelogPurpose-built model for leaked secret detection
Continue chronologically





