
Auto mode becomes the default in Claude Code
From August 14, new Claude Code sessions on Pro, Max and Team plans will run in auto mode. Anthropic says its testing shows the classifier is safer than users clicking through permission prompts.
What changes on August 14
Anthropic has made auto mode the default in Claude Code. Starting on August 14, new sessions on Pro, Max and Team plans will run in auto mode; users who have pinned a different default keep it, and others may see a one-time prompt asking whether to switch. The auto mode classifier spends a small number of extra tokens on each tool call, and Anthropic says it will no longer charge Pro, Max and Team users for that overhead.
Auto mode stays opt-in for now on Claude Enterprise, the Claude API, Claude Platform on AWS, Amazon Bedrock, Google Cloud's Agent Platform and Microsoft Foundry, so administrators have time to review the change. The company plans to make it the default there within the coming month, working with cloud partners; Enterprise admins can already enable it through managed settings.
How it works, and the case for it
Instead of asking for permission, auto mode routes every tool call through a classifier aimed at blocking actions that are irreversible, destructive or pointed outside the user's environment. When something is blocked, Claude usually finds a safer route or asks the user directly; if it cannot make progress — three blocks in a row, or twenty across a session — Claude Code falls back to manual approvals.
The argument for the switch is that manual review becomes habitual. Users approve 97% of permission prompts in Claude Code, while rejecting 39% of plans presented for approval.
The safety data
Anthropic cites internal and third-party red-teaming, prompt-injection evaluations, a controlled study with 1,053 paid testers and analysis of real production sessions, saying auto mode matched or outperformed manual review on every measure it tested. In one exercise, a clearly dangerous command was caught by human testers only 13.6% of the time (143 of 1,053), while auto mode blocked 89% of the same commands. Humans did worse as sessions grew longer, dropping to roughly 5% after 50 or more prior prompts.
In a two-week pilot with the UK safety startup Apollo Research, hardening the classifier after synthetic attacks let auto mode catch about half of the attacks it previously missed, with its miss rate falling from 12% to 7% across shared and held-out attack sets. A separate third-party evaluation by Trajectory Labs tested 72 indirect prompt-injection scenarios ten times each: none of the 720 attempts succeeded against Claude models running auto mode, while 5.83% succeeded against Codex in Auto-review mode and 19.03% in Full Access mode.
In production
Anthropic says auto mode is already the default for its own Claude Code usage, where the classifier has blocked a fallback upload of a report to a public code-sharing site and a mass process kill across roughly two thousand pods. Adobe, Nuro, Gusto and Garner Health use it as their production default, and Teams and Enterprise adopters using auto mode ship about 25% more pull requests.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.