Security

GitHub AI Scan Now Works Without CodeQL Default Setup

The security feature expands to more repositories as GitHub removes a key configuration requirement for Advanced Security customers.

Omega Editorial· September 16, 2026· 2 min read

GitHub expands AI-powered security scanning

GitHub has removed a significant barrier to using its AI Scan feature for pull requests. The security tool now detects vulnerabilities in repositories even when CodeQL default setup isn't configured, according to a changelog entry published by GitHub.

Previously, organizations could only run AI Scan on repositories where they had already enabled CodeQL's default setup. That prerequisite limited the feature's reach, particularly in organizations with mixed security configurations across their repository portfolios.

What changed for Advanced Security customers

The update maintains existing permission requirements while eliminating the CodeQL dependency. Code scanning and AI Scan must still be enabled at the repository, organization, or enterprise level, and the same permission hierarchy applies. However, no new setup steps are required.

For organizations that have already activated GitHub code scanning's AI Scan, the feature now automatically runs across a broader set of eligible repositories. The expansion happens without additional configuration, immediately increasing coverage for teams using GitHub Advanced Security.

The change is currently in public preview for organization-owned and personal repositories on github.com. GitHub Advanced Security customers can access the expanded functionality now, though GitHub Enterprise Server is not supported in this release.

Why it matters

This change lowers the operational overhead for security teams managing large repository portfolios. Organizations can now deploy AI-powered vulnerability detection more uniformly without first ensuring every repository has CodeQL configured. For companies with hundreds or thousands of repositories, eliminating this setup dependency means faster security coverage and fewer gaps in automated scanning. It also signals GitHub's broader strategy to make AI security tools more accessible and less dependent on specific toolchain configurations.

Implementation details

The feature operates within GitHub's existing security framework. AI Scan analyzes pull requests to identify potential security vulnerabilities using machine learning models. By decoupling it from CodeQL default setup, GitHub has made the tool more flexible for diverse development environments.

Organizations interested in the feature can review GitHub's documentation on AI-powered security detections for implementation guidance. GitHub is also collecting feedback through its Community forum as the public preview continues.

The details were first reported in GitHub's official changelog.

#github#code-scanning#ai-security#codeql#devsecops#application-security

This is an original analysis by the Omega editorial team. Source reporting: AI Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

OX Security Launches Cloud Platform With Live AI Agent Monitoring

New CNAPP combines traditional posture management with real-time detection of autonomous agents and non-human identities in production environments.

Via AI Watch · Sep 16, 2026
Security· 4 min read

Hackers Extract Flock Camera Data, Reveal People-Tracking Code

Activists reverse-engineered a stolen surveillance camera and published encryption keys, exposing software that explicitly detects pedestrians alongside vehicles.

Via WIRED · Sep 16, 2026
Security· 3 min read

Half of Employee-Built AI Agents Access HR Data, Study Finds

A September survey of 1,100 workers reveals widespread AI agent adoption with minimal safeguards around sensitive company information.

Via AI Watch · Sep 16, 2026