[{"data":1,"prerenderedAt":977},["ShallowReactive",2],{"blog-coding-agent-secrets-hygiene-en":3},{"slug":4,"published":5,"minutes":6,"category":7,"tags":8,"keywords":14,"about":23,"sources":33,"cover":100,"og":101,"expertise":102,"locales":103,"lang":104,"title":107,"description":108,"coverAlt":109,"metaTitle":110,"takeaways":111,"faq":117,"toc":130,"blocks":164,"others":692},"coding-agent-secrets-hygiene","2026-10-08",11,"security",[9,10,11,12,13],"AI agents","Secrets management","Claude Code","Pre-commit scanning","CI security",[15,16,17,18,19,20,21,22],"coding agent secrets","keep secrets away from AI agents","Claude Code deny read .env","gitleaks pre-commit hook","GitHub push protection secrets","OIDC GitHub Actions short-lived credentials","rotate a leaked API key","MCP server token scope",[24,27,30],{"name":25,"url":26},"Principle of least privilege","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FPrinciple_of_least_privilege",{"name":28,"url":29},"Model Context Protocol","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FModel_Context_Protocol",{"name":31,"url":32},"Git","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FGit",[34,37,40,43,46,49,52,55,58,61,64,67,70,73,76,79,82,85,88,91,94,97],{"title":35,"url":36},"Claude Code: permissions","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fpermissions",{"title":38,"url":39},"Claude Code: sandboxed Bash","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fsandboxing",{"title":41,"url":42},"Claude Code: hooks","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fhooks",{"title":44,"url":45},"Claude Code: data usage","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fdata-usage",{"title":47,"url":48},"Claude Code: settings","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fsettings",{"title":50,"url":51},"Claude Code: MCP servers","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fmcp",{"title":53,"url":54},"Codex: configuration reference","https:\u002F\u002Fdevelopers.openai.com\u002Fcodex\u002Fconfig-reference",{"title":56,"url":57},"Codex: agent approvals and security","https:\u002F\u002Flearn.chatgpt.com\u002Fdocs\u002Fagent-approvals-security",{"title":59,"url":60},"Codex: advanced configuration","https:\u002F\u002Flearn.chatgpt.com\u002Fdocs\u002Fconfig-file\u002Fconfig-advanced",{"title":62,"url":63},"GitHub: about push protection","https:\u002F\u002Fdocs.github.com\u002Fen\u002Fcode-security\u002Fsecret-scanning\u002Fintroduction\u002Fabout-push-protection",{"title":65,"url":66},"GitHub: security hardening with OIDC","https:\u002F\u002Fdocs.github.com\u002Fen\u002Factions\u002Fsecurity-for-github-actions\u002Fsecurity-hardening-your-deployments\u002Fabout-security-hardening-with-openid-connect",{"title":68,"url":69},"GitHub: OpenID Connect reference","https:\u002F\u002Fdocs.github.com\u002Fen\u002Factions\u002Freference\u002Fsecurity\u002Foidc",{"title":71,"url":72},"GitHub: using secrets in Actions","https:\u002F\u002Fdocs.github.com\u002Fen\u002Factions\u002Fsecurity-guides\u002Fusing-secrets-in-github-actions",{"title":74,"url":75},"GitHub: secure use reference","https:\u002F\u002Fdocs.github.com\u002Fen\u002Factions\u002Fsecurity-for-github-actions\u002Fsecurity-guides\u002Fsecurity-hardening-for-github-actions",{"title":77,"url":78},"GitHub: removing sensitive data","https:\u002F\u002Fdocs.github.com\u002Fen\u002Fauthentication\u002Fkeeping-your-account-and-data-secure\u002Fremoving-sensitive-data-from-a-repository",{"title":80,"url":81},"gitleaks: README and latest release","https:\u002F\u002Fgithub.com\u002Fgitleaks\u002Fgitleaks",{"title":83,"url":84},"TruffleHog: README","https:\u002F\u002Fgithub.com\u002Ftrufflesecurity\u002Ftrufflehog",{"title":86,"url":87},"detect-secrets: README and latest release","https:\u002F\u002Fgithub.com\u002FYelp\u002Fdetect-secrets",{"title":89,"url":90},"Model Context Protocol: security best practices","https:\u002F\u002Fmodelcontextprotocol.io\u002Fspecification\u002F2025-06-18\u002Fbasic\u002Fsecurity_best_practices",{"title":92,"url":93},"OWASP: Secrets Management Cheat Sheet","https:\u002F\u002Fcheatsheetseries.owasp.org\u002Fcheatsheets\u002FSecrets_Management_Cheat_Sheet.html",{"title":95,"url":96},"OWASP: LLM02 sensitive information disclosure","https:\u002F\u002Fgenai.owasp.org\u002Fllmrisk\u002Fllm022025-sensitive-information-disclosure\u002F",{"title":98,"url":99},"Git: git-add documentation","https:\u002F\u002Fgit-scm.com\u002Fdocs\u002Fgit-add","\u002Fimages\u002Fblog\u002Fcoding-agent-secrets-hygiene\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fcoding-agent-secrets-hygiene\u002Fog.jpg","ai-engineer",[104,105,106],"en","de","hu","Coding agents and secrets: keep keys out of context, logs and commits","How secrets leak through coding agents, and the controls that stop them: deny reads, a sandbox, pre-commit scans, push protection, OIDC and rotation.","Cover art for coding agents and secrets: a shield of six layered controls, from deny rules and a sandbox to rotation.","Coding agents and secrets: context, logs, CI · Balázs Csorba",[112,113,114,115,116],"An agent can read whatever sits in the project folder, and reads inside the working directory need no prompt. Deny the files you never want in context with Read rules such as Read(.env).","Permission rules cover the file tools and common file commands, not every process. Turn the sandbox on for shell commands, and use sandbox.credentials to deny credential files and tokens.","Local hooks can be skipped, so run pre-commit scanning and GitHub push protection together. The server-side check is the one a local hook cannot skip.","Use OIDC for cloud access in CI, with the least permission each job needs. Anyone with write access can read every repository secret, so keep long-lived keys out of them.","Treat a secret that reached a transcript, log or commit as exposed. Rotate it first, then clean up history, because clones and cached views keep old commits.",[118,121,124,127],{"q":119,"a":120},"Can I stop Claude Code from reading my .env file?","Yes. A Read deny rule such as Read(.env) in permissions.deny blocks the file tools, and the same rule also covers file commands such as cat, head and tail that run through Bash. It does not stop a script that opens files itself, so turn on the sandbox as well.",{"q":122,"a":123},"Does a .claudeignore file keep secrets away from Claude Code?","No. The Claude Code permissions documentation says a .claudeignore file has no effect, so move its entries into Read deny rules.",{"q":125,"a":126},"Are the secrets an agent reads sent to the model?","What the agent reads becomes part of the conversation, and the conversation goes to the model API with each request. Anthropic’s data documentation says prompts and model outputs are sent over TLS, and that session transcripts are kept locally in plaintext for 30 days by default.",{"q":128,"a":129},"What do I do when a key lands in a commit?","Rotate the key first. Rewriting history alone is not enough, because clones, forks, cached views and pull requests can still hold the commit. GitHub Support only helps remove sensitive data where rotating the credential cannot mitigate the risk.",[131,134,137,140,143,146,149,152,155,158,161],{"id":132,"title":133},"how-secrets-leak","Five ways secrets leak through an agent",{"id":135,"title":136},"deny-reads","Deny reads first: permission rules and the sandbox",{"id":138,"title":139},"logs-and-transcripts","Transcripts, feedback and CI logs",{"id":141,"title":142},"commits","Scan before the commit",{"id":144,"title":145},"push-protection","Push protection: the check a local hook cannot skip",{"id":147,"title":148},"ci-oidc","CI: short-lived tokens instead of stored keys",{"id":150,"title":151},"mcp-tokens","MCP servers: narrow tokens and read-only access",{"id":153,"title":154},"rotate","After an exposure: rotate first, clean up second",{"id":156,"title":157},"checklist","Checklist",{"id":159,"title":160},"first-steps","What I would do first",{"id":162,"title":163},"sources","Sources",[165,169,172,175,233,236,245,248,249,259,261,272,301,308,326,328,334,351,353,354,357,360,361,364,403,411,413,424,425,428,431,437,438,441,443,465,473,474,481,496,497,500,513,514,606,607,619,622,623],{"type":166,"content":167},"paragraph",[168],"A coding agent reads your project, runs your shell and writes your commits, so every secret in the project folder is one tool call away from the model’s context window. No single setting fixes that. Deny the reads you do not want, sandbox the shell, scan before the commit, let the server refuse pushes that contain secrets, and give CI short-lived tokens. Several of these controls are off by default.",{"type":170,"level":171,"id":132,"text":133},"heading",2,{"type":166,"content":173},[174],"Most of these leaks come from defaults, not from an attacker, which is why they are easy to miss.",{"type":176,"ordered":177,"items":178},"list",false,[179,190,203,212,228],[180,184,185,189],{"tag":181,"children":182},"strong",[183],"The project files."," Reads inside the working directory need no approval, according to the Claude Code permissions table, so a ",{"tag":186,"children":187},"code",[188],".env"," file in the project is readable without a prompt and then sits in the conversation.",[191,194,195,198,199,202],{"tag":181,"children":192},[193],"The shell."," Commands such as ",{"tag":186,"children":196},[197],"env"," or ",{"tag":186,"children":200},[201],"printenv"," print values into tool output, and the Claude Code sandbox passes the environment through to commands by default, secrets included.",[204,207,208,211],{"tag":181,"children":205},[206],"The transcript."," Claude Code keeps session transcripts in plaintext under ",{"tag":186,"children":209},[210],"~\u002F.claude\u002Fprojects\u002F"," for 30 days by default, so whatever the agent printed stays on disk.",[213,216,217,220,221,223,224,227],{"tag":181,"children":214},[215],"The commit."," ",{"tag":186,"children":218},[219],"git add -A"," brings the index in line with the working tree, adding, modifying and removing entries. Ignored files are skipped, so a ",{"tag":186,"children":222},[188]," missing from ",{"tag":186,"children":225},[226],".gitignore"," is staged the moment an agent runs it. An agent asked to make a failing test pass may also copy a config value into a fixture and commit it.",[229,232],{"tag":181,"children":230},[231],"The tools."," An MCP server can do whatever its token allows, and the MCP security guidance tells clients to warn that local servers run with the same privileges as the client.",{"type":166,"content":234},[235],"The context window is the least visible route. A file or command output becomes part of the conversation, and the conversation goes to the model with each request. Claude Code’s data documentation says prompts and model outputs travel to the model API over TLS. TLS protects that connection, not what the model is shown, so the place to stop a secret is before it is read.",{"type":237,"attrs":238,"inner":242,"caption":243},"diagram",{"viewBox":239,"role":240,"aria-labelledby":241},"0 0 720 290","img","d1-leak-t d1-leak-d","\u003Ctitle id=\"d1-leak-t\">Three routes a secret takes out of a project\u003C\u002Ftitle>\u003Cdesc id=\"d1-leak-d\">Three rows of four steps each. The first row runs from a secret in the .env file, through the Read tool and the context window, to the model provider. The second row runs from a shell command, through its output, into a plaintext transcript and a feedback report. The third row runs from git add -A, through a commit and a push, to the remote repository and its cached views. Each row needs its own control.\u003C\u002Fdesc>\u003Crect x=\"20\" y=\"40\" width=\"140\" height=\"52\" rx=\"10\" class=\"d-gold\" \u002F>\u003Ctext x=\"90\" y=\"64\" text-anchor=\"middle\" class=\"d-text\">Secret in .env\u003C\u002Ftext>\u003Ctext x=\"90\" y=\"82\" text-anchor=\"middle\" class=\"d-small\">project folder\u003C\u002Ftext>\u003Cpath d=\"M164 66 H192\" class=\"d-line\" \u002F>\u003Cpath d=\"M200 66 l-9 -5 v10 z\" class=\"d-head\" \u002F>\u003Crect x=\"200\" y=\"40\" width=\"140\" height=\"52\" rx=\"10\" class=\"d-box\" \u002F>\u003Ctext x=\"270\" y=\"64\" text-anchor=\"middle\" class=\"d-text\">Read tool\u003C\u002Ftext>\u003Ctext x=\"270\" y=\"82\" text-anchor=\"middle\" class=\"d-small\">no prompt\u003C\u002Ftext>\u003Cpath d=\"M344 66 H372\" class=\"d-line\" \u002F>\u003Cpath d=\"M380 66 l-9 -5 v10 z\" class=\"d-head\" \u002F>\u003Crect x=\"380\" y=\"40\" width=\"140\" height=\"52\" rx=\"10\" class=\"d-box\" \u002F>\u003Ctext x=\"450\" y=\"64\" text-anchor=\"middle\" class=\"d-text\">Context window\u003C\u002Ftext>\u003Ctext x=\"450\" y=\"82\" text-anchor=\"middle\" class=\"d-small\">resent each request\u003C\u002Ftext>\u003Cpath d=\"M524 66 H552\" class=\"d-line\" \u002F>\u003Cpath d=\"M560 66 l-9 -5 v10 z\" class=\"d-head\" \u002F>\u003Crect x=\"560\" y=\"40\" width=\"140\" height=\"52\" rx=\"10\" class=\"d-accent\" \u002F>\u003Ctext x=\"630\" y=\"64\" text-anchor=\"middle\" class=\"d-text\">Model provider\u003C\u002Ftext>\u003Ctext x=\"630\" y=\"82\" text-anchor=\"middle\" class=\"d-small\">receives the file\u003C\u002Ftext>\u003Crect x=\"20\" y=\"130\" width=\"140\" height=\"52\" rx=\"10\" class=\"d-gold\" \u002F>\u003Ctext x=\"90\" y=\"154\" text-anchor=\"middle\" class=\"d-text\">Shell command\u003C\u002Ftext>\u003Ctext x=\"90\" y=\"172\" text-anchor=\"middle\" class=\"d-small\">env or printenv\u003C\u002Ftext>\u003Cpath d=\"M164 156 H192\" class=\"d-line\" \u002F>\u003Cpath d=\"M200 156 l-9 -5 v10 z\" class=\"d-head\" \u002F>\u003Crect x=\"200\" y=\"130\" width=\"140\" height=\"52\" rx=\"10\" class=\"d-box\" \u002F>\u003Ctext x=\"270\" y=\"154\" text-anchor=\"middle\" class=\"d-text\">Command output\u003C\u002Ftext>\u003Ctext x=\"270\" y=\"172\" text-anchor=\"middle\" class=\"d-small\">keys in plain text\u003C\u002Ftext>\u003Cpath d=\"M344 156 H372\" class=\"d-line\" \u002F>\u003Cpath d=\"M380 156 l-9 -5 v10 z\" class=\"d-head\" \u002F>\u003Crect x=\"380\" y=\"130\" width=\"140\" height=\"52\" rx=\"10\" class=\"d-box\" \u002F>\u003Ctext x=\"450\" y=\"154\" text-anchor=\"middle\" class=\"d-text\">Transcript\u003C\u002Ftext>\u003Ctext x=\"450\" y=\"172\" text-anchor=\"middle\" class=\"d-small\">~\u002F.claude, 30 days\u003C\u002Ftext>\u003Cpath d=\"M524 156 H552\" class=\"d-line\" \u002F>\u003Cpath d=\"M560 156 l-9 -5 v10 z\" class=\"d-head\" \u002F>\u003Crect x=\"560\" y=\"130\" width=\"140\" height=\"52\" rx=\"10\" class=\"d-accent\" \u002F>\u003Ctext x=\"630\" y=\"154\" text-anchor=\"middle\" class=\"d-text\">Feedback report\u003C\u002Ftext>\u003Ctext x=\"630\" y=\"172\" text-anchor=\"middle\" class=\"d-small\">\u002Ffeedback sends it\u003C\u002Ftext>\u003Crect x=\"20\" y=\"220\" width=\"140\" height=\"52\" rx=\"10\" class=\"d-gold\" \u002F>\u003Ctext x=\"90\" y=\"244\" text-anchor=\"middle\" class=\"d-text\">git add -A\u003C\u002Ftext>\u003Ctext x=\"90\" y=\"262\" text-anchor=\"middle\" class=\"d-small\">skips only ignored\u003C\u002Ftext>\u003Cpath d=\"M164 246 H192\" class=\"d-line\" \u002F>\u003Cpath d=\"M200 246 l-9 -5 v10 z\" class=\"d-head\" \u002F>\u003Crect x=\"200\" y=\"220\" width=\"140\" height=\"52\" rx=\"10\" class=\"d-box\" \u002F>\u003Ctext x=\"270\" y=\"244\" text-anchor=\"middle\" class=\"d-text\">Commit\u003C\u002Ftext>\u003Ctext x=\"270\" y=\"262\" text-anchor=\"middle\" class=\"d-small\">history keeps it\u003C\u002Ftext>\u003Cpath d=\"M344 246 H372\" class=\"d-line\" \u002F>\u003Cpath d=\"M380 246 l-9 -5 v10 z\" class=\"d-head\" \u002F>\u003Crect x=\"380\" y=\"220\" width=\"140\" height=\"52\" rx=\"10\" class=\"d-box\" \u002F>\u003Ctext x=\"450\" y=\"244\" text-anchor=\"middle\" class=\"d-text\">Push\u003C\u002Ftext>\u003Ctext x=\"450\" y=\"262\" text-anchor=\"middle\" class=\"d-small\">server can refuse\u003C\u002Ftext>\u003Cpath d=\"M524 246 H552\" class=\"d-line\" \u002F>\u003Cpath d=\"M560 246 l-9 -5 v10 z\" class=\"d-head\" \u002F>\u003Crect x=\"560\" y=\"220\" width=\"140\" height=\"52\" rx=\"10\" class=\"d-accent\" \u002F>\u003Ctext x=\"630\" y=\"244\" text-anchor=\"middle\" class=\"d-text\">Remote and forks\u003C\u002Ftext>\u003Ctext x=\"630\" y=\"262\" text-anchor=\"middle\" class=\"d-small\">cached views\u003C\u002Ftext>",[244],"Three routes out of a project. Each needs its own control, from deny rules for the first to push protection for the last.",{"type":166,"content":246},[247],"Each route needs its own control, and a line in the system prompt is not one of them. OWASP notes that prompt injection can bypass instructions, such as a rule to never print secrets, so limit access to sensitive data on the principle of least privilege.",{"type":170,"level":171,"id":135,"text":136},{"type":166,"content":250},[251,252,254,255,258],"Start with the file tools. A Read deny rule stops them from opening a path. The syntax follows gitignore rules, so ",{"tag":186,"children":253},[188]," matches at any depth under the working directory, and a path starting with ",{"tag":186,"children":256},[257],"~\u002F"," is anchored to your home folder. Rules are checked deny, then ask, then allow, so a deny always beats an allow.",{"type":186,"code":260},"{\n  \"permissions\": {\n    \"deny\": [\n      \"Read(.env)\",\n      \"Read(secrets\u002F**)\",\n      \"Read(~\u002F.aws\u002F**)\",\n      \"Read(~\u002F.ssh\u002F**)\"\n    ]\n  }\n}",{"type":166,"content":262},[263,264,267,268,271],"Use ",{"tag":186,"children":265},[266],".claude\u002Fsettings.json"," to share a rule with the team, or ",{"tag":186,"children":269},[270],"~\u002F.claude\u002Fsettings.json"," for your own machine. Deny rules from every scope are evaluated before allow rules. In user settings, use a ~\u002F or \u002F\u002F path to reach every project, because a leading slash is relative to the settings file.",{"type":166,"content":273},[274,275,278,279,278,282,278,285,288,289,292,293,296,297,300],"Two limits matter. The rules cover the Read tool, file commands run through Bash such as ",{"tag":186,"children":276},[277],"cat",", ",{"tag":186,"children":280},[281],"head",{"tag":186,"children":283},[284],"tail",{"tag":186,"children":286},[287],"sed"," and ",{"tag":186,"children":290},[291],"tee",", and Bash redirections. They do not cover a command that reads files without naming them, such as ",{"tag":186,"children":294},[295],"grep -r pattern .",", or a Python or Node script that opens files itself. And a ",{"tag":186,"children":298},[299],".claudeignore"," file has no effect, so move its entries into Read deny rules.",{"type":302,"variant":303,"title":304,"body":305},"callout","warn","Deny rules are not a sandbox",[306],[307],"For OS-level enforcement that blocks every process from a path, the docs point to the sandbox. Bash permission patterns that try to constrain command arguments are fragile, so do not build a boundary out of them.",{"type":166,"content":309},[310,311,314,315,318,319,288,322,325],"The sandbox is the second layer, and it is off by default. Turn it on with ",{"tag":186,"children":312},[313],"\u002Fsandbox"," or set ",{"tag":186,"children":316},[317],"sandbox.enabled"," to true. It uses Seatbelt on macOS and bubblewrap on Linux and WSL2, and it covers shell commands only: the file tools, MCP servers and hooks run outside it. Its defaults are wide. Reads cover most of the machine, including ",{"tag":186,"children":320},[321],"~\u002F.ssh",{"tag":186,"children":323},[324],"~\u002F.aws\u002Fcredentials",", and environment variables are inherited. The credentials block closes those gaps.",{"type":186,"code":327},"{\n  \"sandbox\": {\n    \"enabled\": true,\n    \"credentials\": {\n      \"files\": [\n        { \"path\": \"~\u002F.aws\u002Fcredentials\", \"mode\": \"deny\" },\n        { \"path\": \"~\u002F.ssh\", \"mode\": \"deny\" }\n      ],\n      \"envVars\": [\n        { \"name\": \"GITHUB_TOKEN\", \"mode\": \"deny\" },\n        { \"name\": \"NPM_TOKEN\", \"mode\": \"deny\" }\n      ]\n    }\n  }\n}",{"type":166,"content":329},[330,331,333],"This is the example from the Claude Code sandbox documentation. It blocks reads of the AWS credentials file and the SSH directory, and removes GITHUB_TOKEN and NPM_TOKEN from the environment of sandboxed commands. Keep it in ",{"tag":186,"children":332},[270]," – project settings cannot switch filesystem isolation off. A PreToolUse hook that exits with code 2 blocks a call before permission rules run. Hooks run outside the sandbox, so treat their scripts as trusted code.",{"type":166,"content":335},[336,337,342,343,346,347,350],"Codex has the same gap in another form, and I cover its CLI in my ",{"tag":338,"to":339,"children":340},"link","\u002Ftools\u002Fopenai-codex-cli",[341],"Codex review",". Its ",{"tag":186,"children":344},[345],"sandbox_mode"," can be read-only, workspace-write or danger-full-access, and network access stays off unless you enable it. Its shell environment keeps variables with KEY, SECRET or TOKEN in their names, because ",{"tag":186,"children":348},[349],"ignore_default_excludes"," defaults to true. Set it to false to drop them before your own filters run:",{"type":186,"code":352},"[shell_environment_policy]\ninherit = \"core\"\nignore_default_excludes = false\n\n[shell_environment_policy.filters]\n\"AWS_*\" = \"exclude\"",{"type":170,"level":171,"id":138,"text":139},{"type":166,"content":355},[356],"Transcripts are the leak people forget. Claude Code keeps them in plaintext under ~\u002F.claude\u002Fprojects\u002F for 30 days by default, and cleanupPeriodDays changes that period. Commercial accounts follow the same 30-day standard retention, and zero data retention is available to qualified Enterprise accounts. The \u002Ffeedback, \u002Fbug and \u002Fshare commands send a copy of your conversation history, code included, to Anthropic, and those reports are retained for five years. Personal data in a transcript stays personal data wherever it sits, so your deletion routine should cover it.",{"type":166,"content":358},[359],"Claude Code’s error reports redact known secret patterns, but they cover the tool’s own internal errors, not your prompts, files or transcript. CI logs have their own rules. GitHub redacts a value only when the runner knows it, and redaction largely relies on an exact match, so a secret wrapped in JSON can slip through. Create a separate secret for each value, and register any derived value, such as a signed or encoded version.",{"type":170,"level":171,"id":141,"text":142},{"type":166,"content":362},[363],"Three open-source scanners cover most of what I would run. They differ in how they decide that something is a secret, and that matters more than the feature list.",{"type":365,"head":366,"rows":375},"table",[367,369,371,373],[368],"Tool",[370],"How it works",[372],"Good at",[374],"Watch out for",[376,385,394],[377,379,381,383],[378],"gitleaks",[380],"Detects passwords, API keys and tokens in git repositories. A pre-commit hook scans each commit, and gitleaks git scans history.",[382],"One tool for the hook and the history scan.",[384],"A local hook can be skipped with SKIP=gitleaks.",[386,388,390,392],[387],"detect-secrets",[389],"Scans against a baseline file. The baseline records known secrets, and later scans flag only new ones.",[391],"Adopting a repository that already holds secrets.",[393],"The baseline accepts existing secrets, so review it before you commit it.",[395,397,399,401],[396],"TruffleHog",[398],"Finds candidate credentials and can verify them by testing them against the service’s API, across more than 800 secret types.",[400],"Separating live credentials from dead ones.",[402],"Verification sends each candidate to the provider, so check that this suits your data.",{"type":166,"content":404},[405,406,410],"I would start with gitleaks, because its hook is a few lines of YAML and it scans history too. The release page marks v8.30.1 as the latest, so the configuration pins that tag. For a repository that already holds secrets, read my ",{"tag":338,"to":407,"children":408},"\u002Ftools\u002Fdetect-secrets",[409],"detect-secrets review"," on baselines.",{"type":186,"code":412},"repos:\n  - repo: https:\u002F\u002Fgithub.com\u002Fgitleaks\u002Fgitleaks\n    rev: v8.30.1\n    hooks:\n      - id: gitleaks",{"type":166,"content":414},[415,416,419,420,423],"Run ",{"tag":186,"children":417},[418],"pre-commit install"," once per clone. The gitleaks README also documents the escape hatch, ",{"tag":186,"children":421},[422],"SKIP=gitleaks git commit",", so a local hook catches honest mistakes, and the server needs its own check.",{"type":170,"level":171,"id":144,"text":145},{"type":166,"content":426},[427],"GitHub push protection blocks detected secrets in pushes from the command line, commits made in the GitHub UI, file uploads, REST API requests and interactions with the GitHub MCP server, which the docs limit to public repositories. An agent can reach the remote through several of these paths, and the server sees all of them.",{"type":166,"content":429},[430],"Two details decide how much it protects you. Push protection for users is on by default, but only for public repositories on GitHub.com. Push protection for repositories needs GitHub Secret Protection and is off until an administrator enables it. Anyone with write access can bypass a block by giving a reason, and each bypass creates an alert and an audit log entry. Delegated bypass limits who may do that.",{"type":302,"variant":432,"title":433,"body":434},"tip","Check two settings",[435],[436],"Enable push protection on every repository an agent can touch, set delegated bypass to a small group, and review bypass alerts as carefully as failed builds.",{"type":170,"level":171,"id":147,"text":148},{"type":166,"content":439},[440],"The cheapest secret to leak is one that is never stored. With OIDC, a workflow asks GitHub for a token for one job, and the cloud provider checks its subject and other claims against the trust you configured. The access token it issues is valid for that job only. OWASP’s secrets guidance points the same way: prefer short-lived or dynamic secrets. The workflow needs one permission to request the token:",{"type":186,"code":442},"permissions:\n  id-token: write # This is required for requesting the JWT\n  contents: read # This is required for actions\u002Fcheckout",{"type":166,"content":444},[445,446,449,450,453,454,457,458,288,461,464],"The GitHub reference says ",{"tag":186,"children":447},[448],"id-token: write"," only lets the job fetch the OIDC token, and it grants no write access to other resources. Keep ",{"tag":186,"children":451},[452],"contents: read"," unless the job pushes. Secrets are not passed to workflows triggered from a fork, except ",{"tag":186,"children":455},[456],"GITHUB_TOKEN",". The real risk sits with ",{"tag":186,"children":459},[460],"pull_request_target",{"tag":186,"children":462},[463],"workflow_run",": the hardening guide warns that, combined with a checkout of untrusted pull request code, they can give that code write access and secrets, and that this can be exploited to take over a repository.",{"type":166,"content":466},[467,468,472],"Agents in CI deserve the same suspicion. An agent that reads an issue or a review comment is reading text someone else may have written, so it should not hold secrets it does not need. GitHub says any user with write access can read all repository secrets. Environment secrets can sit behind required reviewers. For the sandbox side, see my ",{"tag":338,"to":469,"children":470},"\u002Fblog\u002Fsandboxing-coding-agents-ci-checklist",[471],"AI agent sandbox checklist",".",{"type":170,"level":171,"id":150,"text":151},{"type":166,"content":475},[476,477,472],"An MCP server holds a credential and offers its tools to the agent, so its token is the real boundary. The MCP security guidance forbids token passthrough, meaning a server must not accept tokens that were not explicitly issued for it, and it asks for a least-privilege scope model. It also lists log leakage as one way an attacker gets a broad token. The identity side is in ",{"tag":338,"to":478,"children":479},"\u002Fblog\u002Fai-agent-identity-least-privilege",[480],"AI agents are identities",{"type":166,"content":482},[483,484,487,488,491,492,495],"On the Claude Code side, ",{"tag":186,"children":485},[486],".mcp.json"," supports ",{"tag":186,"children":489},[490],"${VAR}"," expansion, which the docs recommend for sensitive values such as API keys, so the repository holds a reference rather than the secret. The docs also suggest a read-only database user, so the queries Claude runs cannot modify data. To switch off every MCP tool in a project, a deny rule of ",{"tag":186,"children":493},[494],"mcp__*"," removes them from the context. Codex’s network proxy, according to its docs, does not filter MCP server connections.",{"type":170,"level":171,"id":153,"text":154},{"type":166,"content":498},[499],"Rewriting history is cleanup, not the fix. GitHub’s guidance says that after a rewrite and force push, the commits may still be reachable through clones and forks, through SHA-1 hashes in cached views, and through pull requests that reference them. Rewriting also changes every later commit hash, and a colleague who pushes an old clone can bring the secret back. Rotate first.",{"type":176,"ordered":501,"items":502},true,[503,505,507,509,511],[504],"Revoke or rotate the credential at the provider, before anything else.",[506],"Check the provider’s audit log for use since the exposure, and treat any use you cannot explain as an incident.",[508],"Delete the CI run log that printed the value, as GitHub advises, and any transcript that holds it.",[510],"If the repository must not keep the value, rewrite history with git-filter-repo, then have every clone owner re-clone.",[512],"Add the pattern to your pre-commit scanner and push protection, so the next leak is refused.",{"type":170,"level":171,"id":156,"text":157},{"type":365,"head":515,"rows":524},[516,518,520,522],[517],"Control",[519],"Where it lives",[521],"What it stops",[523],"How to check it",[525,534,543,552,561,570,579,588,597],[526,528,530,532],[527],"Read deny rules",[529],"permissions.deny in settings.json",[531],"Agent file tools, and cat, head or tail reading secrets",[533],"Ask a test session to read .env and expect a block",[535,537,539,541],[536],"Sandbox with credentials denied",[538],"sandbox.enabled and sandbox.credentials",[540],"Shell reads of ~\u002F.aws and ~\u002F.ssh, and inherited tokens",[542],"Run \u002Fsandbox and confirm it is on",[544,546,548,550],[545],"Codex environment filter",[547],"shell_environment_policy in config.toml",[549],"KEY, SECRET and TOKEN variables reaching commands",[551],"Confirm ignore_default_excludes is false",[553,555,557,559],[554],"Pre-commit scan",[556],"gitleaks hook in .pre-commit-config.yaml",[558],"Secrets in local commits",[560],"Commit a fake key on a branch and expect a refusal",[562,564,566,568],[563],"Push protection",[565],"Repository security settings",[567],"Secrets in pushes, UI commits, uploads and MCP calls",[569],"Check that it is enabled and that bypass is restricted",[571,573,575,577],[572],"OIDC for cloud access",[574],"id-token: write and the cloud trust policy",[576],"Long-lived cloud keys in repository secrets",[578],"Delete the cloud keys once the trust works",[580,582,584,586],[581],"Least-privilege token",[583],"permissions block in every workflow",[585],"Misuse of GITHUB_TOKEN",[587],"Default to contents: read",[589,591,593,595],[590],"Log hygiene",[592],"Derived values registered, no JSON-wrapped secrets",[594],"Secrets in CI logs",[596],"Search one run log for a test value",[598,600,602,604],[599],"Rotation runbook",[601],"Provider console and audit logs",[603],"Live values after an exposure",[605],"Rehearse it on one low-value key",{"type":170,"level":171,"id":159,"text":160},{"type":176,"ordered":501,"items":608},[609,611,613,615,617],[610],"Add Read deny rules for .env, secret folders, ~\u002F.aws and ~\u002F.ssh. Delete any .claudeignore you were relying on.",[612],"Turn on the sandbox and add credentials entries for the variables and files you actually use.",[614],"Install gitleaks as a pre-commit hook, and turn on push protection for every repository an agent can touch.",[616],"Move CI cloud access to OIDC, and set the permissions of each workflow to the minimum.",[618],"Write the rotation runbook before you need it, and rehearse it on one low-value key.",{"type":166,"content":620},[621],"None of this needs a platform – it needs the defaults changed, a few config files in the repository and the habit of asking, for every secret, whether the agent could read it, print it or commit it.",{"type":170,"level":171,"id":162,"text":163},{"type":176,"ordered":501,"items":624},[625,629,632,635,638,641,644,647,650,653,656,659,662,665,668,671,674,677,680,683,686,689],[626],{"tag":627,"href":36,"children":628},"a",[35],[630],{"tag":627,"href":39,"children":631},[38],[633],{"tag":627,"href":42,"children":634},[41],[636],{"tag":627,"href":45,"children":637},[44],[639],{"tag":627,"href":48,"children":640},[47],[642],{"tag":627,"href":51,"children":643},[50],[645],{"tag":627,"href":54,"children":646},[53],[648],{"tag":627,"href":57,"children":649},[56],[651],{"tag":627,"href":60,"children":652},[59],[654],{"tag":627,"href":63,"children":655},[62],[657],{"tag":627,"href":66,"children":658},[65],[660],{"tag":627,"href":69,"children":661},[68],[663],{"tag":627,"href":72,"children":664},[71],[666],{"tag":627,"href":75,"children":667},[74],[669],{"tag":627,"href":78,"children":670},[77],[672],{"tag":627,"href":81,"children":673},[80],[675],{"tag":627,"href":84,"children":676},[83],[678],{"tag":627,"href":87,"children":679},[86],[681],{"tag":627,"href":90,"children":682},[89],[684],{"tag":627,"href":93,"children":685},[92],[687],{"tag":627,"href":96,"children":688},[95],[690],{"tag":627,"href":99,"children":691},[98],[693,772,849,931],{"slug":694,"published":695,"minutes":6,"category":7,"tags":696,"keywords":702,"about":711,"sources":724,"cover":766,"og":767,"expertise":102,"locales":768,"lang":104,"title":769,"description":770,"coverAlt":771},"works-council-ai-tools-austria-germany","2026-10-02",[697,698,699,700,701],"Works council","AI coding tools","Employee monitoring","GDPR","Co-determination",[703,704,705,706,707,708,709,710],"works council AI tools","AI coding tools works council","Betriebsrat KI Mitbestimmung","§ 87 BetrVG Überwachung","§ 96 ArbVG Kontrollmaßnahmen","AI usage logs employee monitoring","works agreement for AI tools","GDPR Article 88 employee data",[712,715,718,721],{"name":713,"url":714},"General Data Protection Regulation","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2016\u002F679\u002Foj\u002Feng",{"name":716,"url":717},"EU Artificial Intelligence Act (Regulation (EU) 2024\u002F1689)","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2024\u002F1689\u002Foj\u002Feng",{"name":719,"url":720},"Arbeitsverfassungsgesetz (Austrian Labour Constitution Act)","https:\u002F\u002Fwww.ris.bka.gv.at\u002FGeltendeFassung.wxe?Abfrage=Bundesnormen&Gesetzesnummer=10008329",{"name":722,"url":723},"Betriebsverfassungsgesetz (German Works Constitution Act), § 87","https:\u002F\u002Fwww.gesetze-im-internet.de\u002Fbetrvg\u002F__87.html",[725,727,729,732,735,737,740,742,745,748,751,754,757,760,763],{"title":726,"url":720},"Arbeitsverfassungsgesetz (ArbVG), §§ 96 and 96a, consolidated text of 10 October 2026, RIS",{"title":728,"url":723},"Betriebsverfassungsgesetz (BetrVG), § 87, gesetze-im-internet.de",{"title":730,"url":731},"Betriebsverfassungsgesetz (BetrVG), § 90, gesetze-im-internet.de","https:\u002F\u002Fwww.gesetze-im-internet.de\u002Fbetrvg\u002F__90.html",{"title":733,"url":734},"Bundesdatenschutzgesetz (BDSG), § 26, gesetze-im-internet.de","https:\u002F\u002Fwww.gesetze-im-internet.de\u002Fbdsg_2018\u002F__26.html",{"title":736,"url":714},"Regulation (EU) 2016\u002F679 (GDPR), EUR-Lex",{"title":738,"url":739},"GDPR Article 5(1)(e), storage limitation, gdpr-info.eu","https:\u002F\u002Fgdpr-info.eu\u002Fart-5-gdpr\u002F",{"title":741,"url":717},"Regulation (EU) 2024\u002F1689 (AI Act), EUR-Lex",{"title":743,"url":744},"Regulation (EU) 2026\u002F1744, EUR-Lex","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2026\u002F1744\u002Foj",{"title":746,"url":747},"AI Act Article 26, AI Act Explorer","https:\u002F\u002Fartificialintelligenceact.eu\u002Farticle\u002F26\u002F",{"title":749,"url":750},"AI Act Annex III, AI Act Explorer","https:\u002F\u002Fartificialintelligenceact.eu\u002Fannex\u002F3\u002F",{"title":752,"url":753},"BAG, 1 ABR 16\u002F23 (July 2024), headset system, gesetze.co","https:\u002F\u002Fgesetze.co\u002Furteile\u002F1_ABR_16-23",{"title":755,"url":756},"ArbG Hamburg, 24 BVGa 1\u002F24: law-firm summary by CMS","https:\u002F\u002Fcms.law\u002Fde\u002Fdeu\u002Flegal-updates\u002Fkein-mitbestimmungsrecht-des-betriebsrats-bei-chatgpt-co",{"title":758,"url":759},"ArbG Hamburg, 24 BVGa 1\u002F24: law-firm summary by Gleiss Lutz","https:\u002F\u002Fwww.gleisslutz.com\u002Fde\u002Fknow-how\u002Farbeitsgericht-hamburg-zu-chatgpt-kein-mitbestimmungsrecht-des-betriebsrats",{"title":761,"url":762},"Claude Code documentation: monitoring usage","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fmonitoring-usage",{"title":764,"url":765},"GitHub Docs: Copilot metrics data reference","https:\u002F\u002Fdocs.github.com\u002Fen\u002Fcopilot\u002Freference\u002Fmetrics-data","\u002Fimages\u002Fblog\u002Fworks-council-ai-tools-austria-germany\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fworks-council-ai-tools-austria-germany\u002Fog.jpg",[104,105,106],"AI coding tools and the works council: when usage logs count as monitoring","Usage logs can make an AI coding tool a monitoring system. What Austria (§ 96 ArbVG) and Germany (§ 87 BetrVG) require, and what to agree before rollout.","Cover art for works councils and AI tools: usage logs pass a consent gate before any developer seat is switched on.",{"slug":773,"published":774,"minutes":775,"category":7,"tags":776,"keywords":781,"about":790,"sources":802,"cover":843,"og":844,"expertise":102,"locales":845,"lang":104,"title":846,"description":847,"coverAlt":848},"dpia-llm-feature-worked-example","2026-10-01",12,[777,700,778,779,780],"DPIA","LLM security","Data protection","AI Act",[782,783,784,785,786,787,788,789],"DPIA for LLM features","data protection impact assessment AI assistant","GDPR Article 35 AI","DSFA-V Austria AI","LLM customer support GDPR","prompt injection data leak GDPR","AI Act Article 50 chatbot","DPIA template LLM",[791,793,796,799],{"name":713,"url":792},"https:\u002F\u002Feur-lex.europa.eu\u002Flegal-content\u002FEN\u002FTXT\u002F?uri=CELEX:32016R0679",{"name":794,"url":795},"WP29 guidelines on data protection impact assessment (WP248 rev.01)","https:\u002F\u002Fec.europa.eu\u002Fnewsroom\u002Farticle29\u002Fitems\u002F611236\u002Fen",{"name":797,"url":798},"OWASP LLM01:2025 Prompt Injection","https:\u002F\u002Fgenai.owasp.org\u002Fllmrisk\u002Fllm01-prompt-injection\u002F",{"name":800,"url":801},"Regulation (EU) 2024\u002F1689 (AI Act)","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2024\u002F1689\u002Foj",[803,804,806,809,812,815,818,821,824,827,829,831,834,837,840,841],{"title":736,"url":792},{"title":805,"url":795},"WP29 guidelines on DPIA, WP248 rev.01 (European Commission item page)",{"title":807,"url":808},"WP248 rev.01 PDF, adopted 4 April 2017 and revised 4 October 2017","https:\u002F\u002Fec.europa.eu\u002Fnewsroom\u002Fjust\u002Fdocument.cfm?doc_id=47711",{"title":810,"url":811},"EDPB Guidelines 07\u002F2020 on the concepts of controller and processor","https:\u002F\u002Fwww.edpb.europa.eu\u002Fsystem\u002Ffiles\u002F2023-10\u002Fedpb_guidelines_202007_controllerprocessor_final_en.pdf",{"title":813,"url":814},"EDPB Opinion 28\u002F2024 on AI models, adopted 17 December 2024","https:\u002F\u002Fwww.edpb.europa.eu\u002Fsystem\u002Ffiles\u002F2024-12\u002Fedpb_opinion_202428_ai-models_en.pdf",{"title":816,"url":817},"EDPB news release on Opinion 28\u002F2024","https:\u002F\u002Fwww.edpb.europa.eu\u002Fnews\u002Fedpb-opinion-on-ai-models-gdpr-principles-support-responsible-ai_en",{"title":819,"url":820},"EDPB, Report of the work undertaken by the ChatGPT Taskforce, 23 May 2024","https:\u002F\u002Fwww.edpb.europa.eu\u002Fsystem\u002Ffiles\u002F2024-05\u002Fedpb_20240523_report_chatgpt_taskforce_en.pdf",{"title":822,"url":823},"DSFA-V, BGBl. II Nr. 278\u002F2018 (RIS)","https:\u002F\u002Fwww.ris.bka.gv.at\u002Feli\u002Fbgbl\u002FII\u002F2018\u002F278",{"title":825,"url":826},"DSFA-AV, BGBl. II Nr. 108\u002F2018 (RIS)","https:\u002F\u002Fwww.ris.bka.gv.at\u002Feli\u002Fbgbl\u002FII\u002F2018\u002F108",{"title":828,"url":798},"OWASP Top 10 for LLM Applications 2025: LLM01 Prompt Injection",{"title":830,"url":96},"OWASP Top 10 for LLM Applications 2025: LLM02 Sensitive Information Disclosure",{"title":832,"url":833},"OpenAI, Data controls in the OpenAI platform","https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fyour-data",{"title":835,"url":836},"Commission Implementing Decision (EU) 2023\u002F1795 on the EU–US Data Privacy Framework","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Fdec_impl\u002F2023\u002F1795\u002Foj\u002Feng",{"title":838,"url":839},"CJEU, Case C-184\u002F20, OT v Vyriausioji tarnybinės etikos komisija","https:\u002F\u002Feur-lex.europa.eu\u002Flegal-content\u002FEN\u002FTXT\u002F?uri=CELEX:62020CJ0184",{"title":741,"url":801},{"title":842,"url":744},"Regulation (EU) 2026\u002F1744 (Digital Omnibus on AI), EUR-Lex","\u002Fimages\u002Fblog\u002Fdpia-llm-feature-worked-example\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fdpia-llm-feature-worked-example\u002Fog.jpg",[104,105,106],"DPIA for an LLM support assistant: a worked example under GDPR Art. 35","A worked DPIA under GDPR Art. 35 for an AI assistant that drafts customer email replies from order data: when it is needed, the risks and owners.","Cover art for a DPIA of an LLM support assistant: a pipeline of six steps, from the high-risk test to the review date.",{"slug":850,"published":851,"minutes":775,"category":7,"tags":852,"keywords":857,"about":868,"sources":878,"cover":925,"og":926,"expertise":102,"locales":927,"lang":104,"title":928,"description":929,"coverAlt":930},"eu-ai-act-gpai-high-risk-2026","2026-09-24",[853,854,855,856],"EU AI Act","GPAI","High-risk AI","AI compliance",[858,859,860,861,862,863,864,865,866,867],"EU AI Act high-risk deadline","AI Act digital omnibus","AI Act GPAI obligations","AI Act provider vs deployer","EU AI Act 2 December 2027","GPAI code of practice","AI literacy Article 4","AI Act compliance checklist","AI Act OpenAI API provider deployer","AI Act mid-size company",[869,872,875],{"name":870,"url":871},"Artificial Intelligence Act","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FArtificial_Intelligence_Act",{"name":873,"url":874},"General-purpose artificial intelligence","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FFoundation_model",{"name":876,"url":877},"European Commission","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FEuropean_Commission",[879,880,881,884,887,890,893,896,899,902,904,907,910,913,916,919,922],{"title":741,"url":801},{"title":842,"url":744},{"title":882,"url":883},"AI Act Explorer: Digital Omnibus on AI, full amending text","https:\u002F\u002Fartificialintelligenceact.eu\u002Fai-act-explorer\u002Fdigital-omnibus\u002F",{"title":885,"url":886},"European Commission: AI Act regulatory framework and timeline","https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fpolicies\u002Fregulatory-framework-ai",{"title":888,"url":889},"European Commission: Guidelines for providers of general-purpose AI models","https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fpolicies\u002Fguidelines-gpai-providers",{"title":891,"url":892},"European Commission: Q&A on the guidelines for GPAI providers","https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Ffaqs\u002Fguidelines-obligations-general-purpose-ai-providers",{"title":894,"url":895},"European Commission: The General-Purpose AI Code of Practice","https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fpolicies\u002Fcontents-code-gpai",{"title":897,"url":898},"European Commission: AI literacy Questions and Answers","https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Ffaqs\u002Fai-literacy-questions-answers",{"title":900,"url":901},"AI Act Article 25: Responsibilities along the AI value chain","https:\u002F\u002Fartificialintelligenceact.eu\u002Farticle\u002F25\u002F",{"title":903,"url":747},"AI Act Article 26: Obligations of deployers of high-risk AI systems",{"title":905,"url":906},"AI Act Article 27: Fundamental rights impact assessment","https:\u002F\u002Fartificialintelligenceact.eu\u002Farticle\u002F27\u002F",{"title":908,"url":909},"AI Act Article 53: Obligations for providers of general-purpose AI models","https:\u002F\u002Fartificialintelligenceact.eu\u002Farticle\u002F53\u002F",{"title":911,"url":912},"AI Act Article 99: Penalties","https:\u002F\u002Fartificialintelligenceact.eu\u002Farticle\u002F99\u002F",{"title":914,"url":915},"AI Act Article 101: Fines for providers of general-purpose AI models","https:\u002F\u002Fartificialintelligenceact.eu\u002Farticle\u002F101\u002F",{"title":917,"url":918},"Gibson Dunn: EU AI Act Omnibus Agreement, postponed high-risk deadlines (27 May 2026)","https:\u002F\u002Fwww.gibsondunn.com\u002Feu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes\u002F",{"title":920,"url":921},"Orrick: EU AI Act Update, Digital Omnibus finalizes 8 compliance changes (29 July 2026)","https:\u002F\u002Fwww.orrick.com\u002Fen\u002FInsights\u002F2026\u002F07\u002FEU-AI-Act-Update-Digital-Omnibus-Finalizes-8-Compliance-Changes",{"title":923,"url":924},"K&L Gates: EU Digital Omnibus on AI enters into force (31 July 2026)","https:\u002F\u002Fwww.klgates.com\u002FEU-Digital-Omnibus-on-AI-Enters-Into-Force-7-31-2026","\u002Fimages\u002Fblog\u002Feu-ai-act-gpai-high-risk-2026\u002Fcover.webp","\u002Fimages\u002Fblog\u002Feu-ai-act-gpai-high-risk-2026\u002Fog.jpg",[104,105,106],"EU AI Act beyond Article 50: GPAI, high-risk dates and what to do now","The AI Act after the Digital Omnibus: GPAI duties, high-risk dates (2 Dec 2027 and 2 Aug 2028), provider vs deployer on OpenAI and Anthropic APIs, AI literacy.","Diagram: the AI Act timeline from February 2025 to August 2028, fanning out into GPAI duties, high-risk systems, provider and deployer roles and AI literacy.",{"slug":932,"published":933,"minutes":775,"category":7,"tags":934,"keywords":940,"about":949,"sources":956,"cover":971,"og":972,"expertise":102,"locales":973,"lang":104,"title":974,"description":975,"coverAlt":976},"eu-ai-act-article-50-developer-checklist","2026-09-22",[853,935,936,937,938,939],"Article 50","AI transparency","Digital Omnibus","AI literacy","Compliance",[853,941,942,943,944,945,946,947,864,948],"EU AI Act developers","Article 50 AI Act","AI transparency obligations","AI Act chatbot disclosure","Digital Omnibus AI Act","AI Act Article 50(2) watermarking","AI Act deepfake labelling","does the AI Act apply to my app",[950,951,953],{"name":870,"url":871},{"name":952,"url":744},"Regulation (EU) 2026\u002F1744",{"name":954,"url":955},"AI Act Explorer","https:\u002F\u002Fartificialintelligenceact.eu\u002Fai-act-explorer\u002F",[957,960,963,966,968],{"title":958,"url":959},"Article 50: Transparency Obligations for Providers and Deployers of Certain AI Systems","https:\u002F\u002Fartificialintelligenceact.eu\u002Farticle\u002F50\u002F",{"title":961,"url":962},"Regulation (EU) 2026\u002F1744 (Digital Omnibus on AI), Official Journal, 24 Jul 2026","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2026\u002F1744\u002Foj\u002Feng",{"title":964,"url":965},"Faegre Drinker: Commission confirms Transparency Code of Practice as adequate and publishes final Article 50 Guidelines (30 Jul 2026)","https:\u002F\u002Fwww.faegredrinker.com\u002Fen\u002Finsights\u002Fpublications\u002F2026\u002F7\u002Feu-ai-act-commission-confirms-transparency-code-of-practice-as-adequate-and-publishes-final-version-of-its-guidelines-on-transparency-obligations",{"title":967,"url":918},"Gibson Dunn: EU AI Act Omnibus Agreement, postponed high-risk deadlines and other key changes (27 May 2026)",{"title":969,"url":970},"RTR KI-Servicestelle: AI Act (Austria)","https:\u002F\u002Fwww.rtr.at\u002Frtr\u002Fservice\u002Fki-servicestelle\u002Fai-act\u002F","\u002Fimages\u002Fblog\u002Feu-ai-act-article-50-developer-checklist\u002Fcover.webp","\u002Fimages\u002Fblog\u002Feu-ai-act-article-50-developer-checklist\u002Fog.jpg",[104,105,106],"EU AI Act Article 50: what developers must do from 2 August 2026","EU AI Act Article 50 transparency duties for developers: AI interaction disclosure, machine-readable marking, deepfakes, provider versus deployer and a checklist.","A six-step timeline from February 2025 to August 2028 covering the AI Act milestones, with the Article 50 step in August 2026 highlighted.",1791636875175]