September 16, 2026: GitHub AI Scan for pull requests can now run on eligible repositories without CodeQL default setup. The change removes a prerequisite that previously limited where the AI security scanner could operate, according to GitHub’s announcement.
What changed
Code scanning and AI Scan must still be enabled under the applicable repository, organization or enterprise settings. Existing permission precedence remains in place. GitHub says organizations that already enabled AI Scan need no additional setup step for it to reach more eligible repositories.
The update is in public preview for organization-owned and personal repositories on github.com for GitHub Advanced Security customers. GitHub Enterprise Server is excluded from this release.
This is a separate rollout change from the AI Scan API preview covered last week: today’s news concerns repository eligibility.
Limits and documentation to check
GitHub’s AI-powered security detections documentation describes findings as advisory: they do not block merges or provide full-repository scans. During preview, the documentation lists both Advanced Security and Copilot licenses and says usage consumes AI credits.
Documentation note: At verification on September 16, the guide still stated the older CodeQL default-setup prerequisite. The dated September 16 changelog explicitly removes that prerequisite; use that announcement for the new eligibility rule.
Why this matters for QA engineers
For QA teams, the practical implication is a potentially larger review surface, including repositories previously left outside the scanner’s reach. That may create additional findings to triage; it does not establish that those repositories are secure.
Suggested QA follow-up: Compare the repository inventory against effective AI Scan settings, pilot a representative pull request in a newly eligible repository, and record whether findings appear. Track false positives, review effort and credit usage before broadening adoption. Keep existing regression checks and security merge gates in place because advisory findings alone do not enforce release criteria.
Sources
GitHub Changelog: Code scanning AI Scan no longer requires CodeQL default setup (September 16, 2026); GitHub Docs: AI-powered security detections in pull requests (checked September 16, 2026).
