GitHub added AI Scan for pull requests status to the Coverage view in Security Overview on October 6, 2026. Organization and enterprise administrators can see counts for repositories where the feature is enabled or not enabled, then inspect the effective status on each repository row. AI Scan is a code scanning feature that examines code changes in pull requests. Source

Review coverage without opening every repository

The Coverage view now gives administrators one place to review adoption across an organization or enterprise. The summary separates repositories into enabled and not enabled counts, while the repository list shows the effective AI Scan status for each entry. This update changes administrative visibility; it does not announce a new detection method or a change to scan results. Source

Use two filters to separate the review queue

The filter code-scanning-ai-scan-pr-scan:enabled shows repositories with AI Scan enabled. The filter code-scanning-ai-scan-pr-scan:not-enabled finds repositories where it is not enabled. An administrator can use the second list to identify repositories that need review, then use the enabled list to check whether a policy or configuration change took effect. Source

A not enabled result does not by itself prove that someone missed a setting. GitHub’s official documentation (https://docs.github.com/en/enterprise-cloud@latest/code-security/how-tos/view-and-interpret-data/analyze-organization-data/assessing-adoption-code-security) says the group can include repositories that are ineligible for AI Scan, and Security Overview does not distinguish the reason. Before changing settings, check repository eligibility, enterprise policy, organization configuration, and any repository opt-out.

CSV exports gain a dedicated field

Coverage CSV exports now include a Code Scanning AI Scan for pull requests column. Its values are enabled and not-enabled. The page is useful for a current visual check, while the CSV can be matched with an internal asset list or team ownership data for a broader review. Source

The CSV value also does not explain why a repository is not enabled. Treat it as a queue for verification rather than a list where every row needs the same configuration change.

Who benefits from the change

The update is aimed at organization and enterprise administrators responsible for security coverage across many repositories. A practical review starts by filtering the not-enabled group, checking effective status and eligibility for each repository, and then using the CSV to assign follow-up work when needed. Source