In the span of just one year, the landscape of software development has undergone a seismic shift. Today, one in every three pull requests submitted to GitHub involves an AI agent—a staggering increase from the fewer than one-in-ten ratio observed just twelve months ago. As these agents become increasingly autonomous, the velocity of code creation is reaching unprecedented heights. If this trajectory holds, experts predict that within two years, the majority of code pushed to global repositories will be generated by AI, much of which may never be read or audited by human eyes.
This technological leap presents a profound dilemma: as the rate of code creation accelerates, so too does the risk of accidental security exposures. For GitHub, the world’s largest development platform, the mission is clear. Security can no longer rely on human oversight alone; the tools that enable developers to create software at machine speeds must also assume the responsibility of protecting that software.
The Chronology of an Escalating Threat
To understand the current crisis, one must look at the data collected over the last nine quarters. The narrative that AI is making developers "careless" is a common, yet statistically unfounded, trope. GitHub’s internal telemetry, analyzed by Product Manager Erin Havens, reveals a different story: developers are not losing their focus; they are simply being outpaced by the sheer volume of their output.
Between Q2 2024 and Q2 2026, the total number of screened pushes grew by a factor of 2.84, while pushes containing inadvertent credentials grew by 2.59. When adjusted for scale, the prevalence of secret leaks per push has remained remarkably flat. Even more telling is the trend in "push-path blocks"—instances where GitHub’s security systems intercept a potential leak, prompting the developer to intervene. Over that same two-year period, the rate at which developers overrode these security warnings fell linearly from 6.63% to 3.93%. This indicates that, despite the increased reliance on AI, developers are actually more receptive to security interventions than they were before the AI boom.
However, the sheer mathematical reality of the "doubling effect" remains a persistent threat. If the rate of leaked secrets remains constant while the volume of pushes doubles, the absolute number of exposures inevitably climbs. Currently, a new secret appears in publicly visible code approximately once every two seconds. When these secrets enter the wild, the human cost of remediation is unsustainable; the mean time to manually revoke a compromised credential hovers around 40 days, with one in five incidents taking more than 90 days to resolve.
Supporting Data: The "Four-Body Problem" of Secret Detection
The challenge of securing code at scale is what industry insiders call the "four-body problem." To effectively prevent a leak, a platform must balance four tightly coupled constraints: precision, latency, throughput, and cost.
- Precision: Every false positive interrupts a developer’s workflow. If a security tool cries wolf too often, it erodes trust and diminishes the efficacy of the system.
- Latency: In a CI/CD pipeline, every millisecond counts. A security check that takes too long to execute becomes a bottleneck that developers will inevitably try to bypass.
- Throughput: With over 574 million public pushes in Q2 2026 alone, the system must be capable of processing immense volumes of data without failing.
- Cost: Security mechanisms must be economically viable to run at the scale of the entire internet.
Previously, detection was often reactive. GitHub’s secret scanning partnership program—which collaborates with issuers like OpenAI, Google Cloud, and Slack to revoke tokens automatically—has been highly successful. In Q2 2026, the platform successfully reported an average of 26 credential matches per second. Yet, this is a "post-push" solution. The credential has already left the developer’s environment and entered the repository history, leaving a window of vulnerability that malicious actors can exploit.
"Before a secret crosses the push boundary, the cost of stopping it is small," explains Erin Havens. "After it crosses, the same string can authenticate to a real system, and the cost becomes unbounded."
Official Response: The Rise of ModernBERT
To bridge this gap, GitHub, in collaboration with Microsoft Applied Sciences, has introduced a breakthrough in push protection. The solution is a fine-tuned classifier based on the "ModernBERT" architecture, designed to assess candidate secrets in their surrounding code context.

Unlike traditional regex-based scanners that look for simple patterns, this model evaluates the context of the code without generating prose or massive amounts of extra data. Most importantly, it is optimized for speed. The model assesses a full set of candidate secrets in less than two milliseconds, allowing it to sit directly in the critical path of a developer’s commit process without inducing friction.
This AI-powered, context-aware detection is a force multiplier. By moving from simple pattern matching to sophisticated behavioral analysis, the platform can now prevent more than 30% of newly detected secrets before they ever reach the repository. The new model, currently in private preview, is expected to more than double the number of secrets GitHub can proactively block.
The Implications for the Future of Development
The shift toward AI-automated security has deep implications for the future of the software industry. If the goal is to allow developers to entrust more work to agents without the constant need for manual, line-by-line supervision, the security infrastructure must become as autonomous as the code generation itself.
A New Paradigm for Security
The era of relying on human vigilance to catch hardcoded API keys or database passwords is coming to a close. Organizations are beginning to realize that "telling developers to be more careful" is not a scalable security strategy. Instead, the burden of protection is shifting to the platforms and the underlying models.
Economic and Operational Impact
For enterprises, the automation of secret detection reduces the massive operational overhead associated with incident response. By catching a leaked credential in milliseconds, companies avoid the "remediation tax"—the thousands of dollars in lost time and potential damages associated with rotating compromised keys and investigating potential breaches.
The Human-Agent Partnership
The ultimate objective is a seamless environment where the AI agent writing the code and the AI model protecting the code operate in a continuous feedback loop. As GitHub integrates this model into more surfaces beyond the initial push, the hope is to create a "zero-leak" culture where security is baked into the fabric of development, rather than treated as a post-hoc manual audit.
Looking Forward: A Sustainable Trajectory
The rapid rise of AI agents in development has undeniably strained existing security models, but it has also provided the impetus for a necessary evolution. By leveraging high-performance, low-latency machine learning models, platforms like GitHub are proving that security can indeed keep pace with the velocity of AI-driven creation.
As we look toward 2027 and beyond, the success of this model will depend on its ability to evolve alongside the changing nature of code. As agents become better at obfuscating their intent or creating more complex, dynamic secrets, the "four-body problem" will remain a constant challenge. However, the precedent has been set: in a world where the majority of code is written by machines, the only logical way to secure it is to let the machines take the watch.
The mandate for the next generation of software development is clear: our capacity to protect software must grow at the same exponential rate as our capacity to create it. With the deployment of AI-native, sub-millisecond detection, the industry has taken a decisive step toward that future.







