Anthropic makes auto mode the default in Claude Code starting Aug. 14
Anthropic said auto mode becomes the default permission mode in Claude Code for Pro, Max and Team plans on August 14, replacing per-command approval prompts with a safety classifier.
Anthropic said auto mode will become the default permission mode in Claude Code for its Pro, Max and Team plans on August 14, 2026, replacing per-command approval prompts with a safety classifier. Claude Code is Anthropic’s agentic coding tool, which lets its Claude models read, edit and run code directly in a developer’s terminal. The classifier blocks any action it classifies as irreversible, destructive or aimed outside the user’s own environment.
The switch to auto mode inverts a common assumption about agent safety: that a human approving each command is safer than letting software do it. Anthropic’s own data argues the opposite. In a controlled study of 1,053 paid testers, auto mode caught 89% of dangerous commands, versus 13.6% caught by reviewers manually approving each one, the company said. Human vigilance dropped further over longer sessions.
An independent evaluator, Trajectory Labs, ran 720 prompt-injection attempts against Claude Fable 5, Opus 5 and Sonnet 5 running auto mode and reported zero successful breaches. It measured a 5.83% attack-success rate against a rival model, GPT-5.6 Sol, in a competing tool’s auto-review mode.
Those figures come from Anthropic and its chosen evaluator, and have not been independently verified. A classifier that stops 89% of dangerous commands still misses roughly one in nine, and the human baseline it beats is a distracted developer clicking approve.
Anthropic also said it stopped charging Pro, Max and Team users for the extra tokens the classifier consumes on each tool call, effective the announcement date. Auto mode stays opt-in on Claude Enterprise, the Claude API, Amazon Bedrock, Google Cloud’s Agent Platform and Microsoft Foundry, though the company said it will become the default there too within the coming month after notice to administrators.
More news

AWS releases six open-source Hugging Face deployment skills for SageMaker

Google Research releases MilleMiglia logistics benchmark generator

AWS launches AgentCore Runtime V2 with elastic memory and snapshot starts
