GitHub is expanding AI Scan for pull requests to repositories that do not use CodeQL default setup. Scanning must still be enabled at repository, organization or enterprise level, but no additional setup is required.

Quick answer

ConditionStatus
CodeQL default setupNo longer required.
Code scanning and AI ScanStill must be enabled.
AvailabilityPublic preview on github.com.
LicenseGitHub Advanced Security customers.

Broader organizational coverage

Organizations that already enabled AI Scan now cover more eligible repositories. This closes gaps for projects using advanced CodeQL configuration, another scanner or no default setup.

What AI does not replace

AI Scan reviews proposed changes and may find vulnerable patterns. It does not cover the full history, runtime configuration or dependencies in the same way as a complete AppSec pipeline.

Preparing rollout

Review policy inheritance across enterprise, organization and repository. Start with selected teams, measure true positives and review time, then define who owns each alert.

A preview requiring supervision

GitHub Enterprise Server is not supported. As with any AI detection, findings need review and reproduction. The goal is a wider safety net, not turning probabilistic suggestions into automatic blocks without context.