← In the News

Claude Code makes auto mode the default, backed by a 1,053-tester safety study

Auto mode is now the default in Claude Code for Pro, Max, and Team plans · Conner Phillippi, Anthropic · Anthropic blog, August 7, 2026

Machine-readable Download Markdown

New Claude Code sessions on Pro, Max, and Team plans switch to auto mode by default on August 14, replacing per-command permission prompts with a classifier that blocks actions judged irreversible, destructive, or aimed outside the user's environment. Anthropic says the change is free: it is "no longer charging Claude Code users on Pro, Max, and Team plans for that classifier overhead, effective today." The company's case rests on a controlled study of 1,053 paid testers in which a single permission prompt was swapped for a clearly dangerous command mid-session: human reviewers caught it 13.6% of the time (143 of 1,053) while auto mode caught it 89% of the time (937 of 1,053), and human catch rates fell further the longer a session ran. Anthropic frames the underlying habit plainly: "manual review can become habitual: users approve 97% of permission prompts in Claude Code." Among Teams and Enterprise adopters, auto mode users reportedly ship about 25% more PRs. A separate third-party prompt-injection evaluation from Trajectory Labs ran 720 attack attempts across 72 scenarios; none succeeded against Claude Fable 5, Opus 5, or Sonnet 5 running auto mode, against a 5.83% success rate for GPT-5.6 Sol running Codex's Auto-review mode.

Why it matters: If you run Claude Code on a Pro, Max, or Team plan, your default working mode changes in two days whether you opt into it or not, and the company argues with real numbers that a bored human clicking "approve" is worse security than the classifier. Decide what belongs on your hard-deny list before the switch flips under you.