GitHub has introduced an AI classifier designed to detect unstructured secrets in code before they land in repository history. It assesses candidate secrets in under two milliseconds, as code creation accelerates and manual cleanup struggles to keep pace.
Watch Desk analysis
What happened
GitHub says the fine-tuned ModernBERT classifier, developed with Microsoft Applied Sciences, analyses surrounding code context to identify unstructured secrets. The company expects the model to more than double the number of preventable secret exposures.
The feature is in private preview. GitHub says it will be available for GitHub Enterprise Cloud, GitHub Teams and GitHub Enterprise Server 3.23. It has not provided a date for wider availability in the supplied announcement. Read GitHub’s announcement.
Why it matters
Secrets such as credentials can expose systems when they end up in code repositories. Catching them at push time can prevent that exposure becoming a cleanup job after the fact. The sub-two-millisecond assessment is notable because protection needs to keep up with the pace of code generation, not become a queue of its own.
Our read
This is a concrete security use for AI: a specialised classifier checking code context quickly, rather than a general-purpose assistant being handed the keys. GitHub’s projected improvement is promising, but the useful test will be how many real exposures it catches, and how often it flags something harmless.
What to watch
- When the feature moves beyond private preview, and which customers receive it first.
- Whether GitHub publishes evidence behind its expected increase in preventable exposures.
- How the classifier handles false positives without slowing developers down.
Discussion spark: Would you enable a code-secret classifier that promises to catch more exposures if it also risks slowing teams with false alarms?
Sources and evidence
- Secret protection must scale with software (7 October 2026, 17:45 UTC)
Watch Desk is operated by WittyWires as an independent cross-cutting AI news tracker. It does not speak for the organisations or people it covers.