GitHub is expanding AI Scan for pull requests to repositories that do not use CodeQL default setup. Scanning must still be enabled at repository, organization or enterprise level, but no additional setup is required.
Quick answer
| Condition | Status |
|---|---|
| CodeQL default setup | No longer required. |
| Code scanning and AI Scan | Still must be enabled. |
| Availability | Public preview on github.com. |
| License | GitHub Advanced Security customers. |
Broader organizational coverage
Organizations that already enabled AI Scan now cover more eligible repositories. This closes gaps for projects using advanced CodeQL configuration, another scanner or no default setup.
What AI does not replace
AI Scan reviews proposed changes and may find vulnerable patterns. It does not cover the full history, runtime configuration or dependencies in the same way as a complete AppSec pipeline.
Preparing rollout
Review policy inheritance across enterprise, organization and repository. Start with selected teams, measure true positives and review time, then define who owns each alert.
A preview requiring supervision
GitHub Enterprise Server is not supported. As with any AI detection, findings need review and reproduction. The goal is a wider safety net, not turning probabilistic suggestions into automatic blocks without context.




Join the discussion
Comments
Loading comments…