GitGuardian: AI-assisted commits leak secrets at twice the rate
GitGuardian's 2026 State of Secrets Sprawl report found that commits flagged as AI-assisted leak credentials roughly twice as often as other commits. The cause is a workflow problem: generated code looks correct, and hardcoded keys in configs or test fixtures pass review and unit tests unnoticed.
- AI-assisted commits leak secrets about twice as often as others
- Secret scanning catches a credential only after it enters repo history
- Rotation and short-lived scoped credentials are the real remediation
- Coding agents should be instructed never to write credential values into source
Read next
Security