The landscape of software development is undergoing a seismic shift, driven by the rapid adoption of artificial intelligence. Today, one in every three pull requests submitted to GitHub involves an AI agent—a staggering increase from fewer than one in ten just a year ago. If this current trajectory persists, the industry is on the cusp of a future where the majority of code pushed to global repositories will be generated by autonomous agents, much of which may never be fully scrutinized by human eyes.
This transformation brings a pressing mandate for the developer community and platform stewards alike: security protections must evolve to match the blistering pace of AI-augmented production. As developers and agents move faster, the risk of accidental credential exposure grows, necessitating a shift toward automated prevention that removes the reliance on manual human intervention to remediate leaks. We are currently at a critical juncture where the tools designed to empower developers to write more software must also take on the burden of securing it.
The Myth of Developer Carelessness
For years, the industry has operated under the assumption that an increase in leaked secrets is a direct byproduct of human error or negligence. However, data from the last nine quarters suggests a different reality. A new secret appears in publicly visible code approximately once every two seconds, a rate that has doubled annually for the past three years. While public discourse often blames this on developers becoming more careless in the era of AI, the empirical evidence tells a story of developers being outpaced by the sheer velocity of modern development cycles.
Between the second quarter of 2024 and the second quarter of 2026, the volume of screened pushes grew by 2.84 times, while the number of pushes containing actual credentials grew by 2.59 times. When examining the nine complete quarters of data, researchers found no statistically detectable trend regarding the per-push prevalence of leaks. In fact, data indicates that developers are more cognizant of security risks than ever before. During this same period, the share of push-path blocks overridden by developers—a metric that suggests a user deliberately ignoring a security warning—fell linearly from 6.63% to 3.93%. These figures directly challenge the narrative that AI agents are making developers more reckless.
Instead, the problem is one of scale. If the rate of activity doubles, the volume of expected exposures also doubles. If every one of those exposures requires a manual human response—such as revoking a token or rotating a key—the workload on security teams becomes unsustainable. Currently, the mean time to manually revoke a compromised secret hovers around 40 days, and roughly one in five incidents takes more than 90 days to resolve. In an environment where code is being generated in seconds, credentials can remain exposed and usable for weeks or months, creating a dangerous gap between development velocity and security remediation.
Scaling Prevention Through Strategic Partnerships
GitHub has spent years refining its secret scanning capabilities, focusing on the essential task of bridging the gap between detection and automated action. The platform’s success is anchored in its extensive ecosystem, which currently includes more than 150 technical partners. Through the secret scanning partnership program, GitHub works closely with credential issuers—such as OpenAI, Google Cloud, Slack, Hugging Face, and SendGrid—to build specialized detectors.
In the second quarter of 2026, public scanning systems successfully reported an average of 26 credential matches per second. Because of the direct integration with these partners, many of these tokens are revoked almost instantaneously upon detection. This is a vital improvement, as it allows for the neutralization of a threat without waiting for a developer to manually process a security alert.

Push protection serves as the primary line of defense by intervening even earlier in the development lifecycle. By stopping recognizable credentials before they are committed to a repository’s history, the system provides developers and their agents with an immediate opportunity to rectify a mistake before an exposure ever occurs. The goal is to make this security intervention a frictionless, background process. Over the last month, push protection has successfully blocked a secret at least once every second. For many issuer-bound credentials, GitHub now blocks more secrets than those that successfully make it into the codebase.
Addressing the Four-Body Problem
The challenge of securing code at scale is often referred to as the "four-body problem," where four distinct constraints—precision, latency, throughput, and cost—must be perfectly balanced. Before a secret crosses the push boundary, the cost of stopping it is relatively low and the decision is binary: block the commit or allow it. However, once that secret is pushed, it can be used to authenticate to real-world systems, turning a small mistake into a potentially unbounded security incident.
The difficulty lies in identifying secrets that do not follow predictable patterns. While a provider-issued token might have a clear, recognizable prefix, an internal database password or a sensitive environment variable might be completely unstructured. To address this, security systems must rely on the context of the surrounding code. Balancing this context-aware judgment with the need for speed and accuracy is a complex technical undertaking. A false positive, for instance, can interrupt a developer’s flow and erode trust in the security tooling, while a check that is too slow or resource-intensive cannot be implemented in the critical path of a push.
High-Speed Protection with ModernBERT
To solve these challenges, GitHub has introduced a new, fine-tuned classifier powered by ModernBERT, developed in collaboration with Microsoft Applied Sciences. This model assesses candidate secrets based on their surrounding code context without the overhead of generating prose or full code blocks.
The performance of this model is a significant technical leap. It is capable of evaluating candidate batches in under two milliseconds, making it efficient enough to run at scale in the critical path of development. Because of its precision and speed, this model is expected to more than double the number of secrets the platform can prevent. This feature is currently in private preview and will soon be available to organizations using GitHub Secret Protection across Enterprise Cloud and GitHub Teams.
By integrating this model directly into developer workflows, GitHub is moving toward a future where security is an inherent, automated property of the development process rather than a reactive afterthought. As organizations continue to increase their reliance on AI agents to write, debug, and maintain code, the infrastructure supporting those developers must keep pace. The objective is to reach a state where the ability to protect software grows in tandem with the ability to create it, ensuring that developers can focus on innovation without the perpetual fear of accidental exposure.
As the industry looks forward, the mandate remains clear: we must build a development environment where security is as automated and efficient as the code generation itself. By removing the burden of manual intervention and leveraging high-speed, AI-driven detection, the developer community can safely embrace the full potential of the AI-powered future.

