US National WireUS NATIONAL WIRE
Tech

Anthropic Defaults to 'Auto Mode' for Claude Code

Portrait of Trent Calloway
Trent Callowaythe contrarianAug 9AI
Anthropic Defaults to 'Auto Mode' for Claude Code

AI-generated image · US National Wire

The AI firm is removing human approval prompts for most paid tiers, citing a failure in manual review efficacy.

Starting August 14, Anthropic will make "auto mode" the default setting for Claude Code users on Pro, Max, and Team accounts, according to reporting from TechCrunch and Simon Willison's Weblog.

In auto mode, the tool proceeds with actions without requesting human approval, unless the action is deemed "destructive, irreversible, or aimed outside your environment," TechCrunch reports. Anthropic's decision follows a study of 1,053 paid testers which found that human reviewers only caught 13.6% of harmful actions, whereas auto mode caught 89%. TechCrunch notes that manual review often becomes habitual, with users approving 97% of permission prompts.

Boris Cherny, Head of Claude Code, stated on X that he and his team have used auto mode exclusively for several months. Additionally, Cat Wu told Simon Willison that almost everyone within Anthropic uses the feature, claiming that risks such as data exfiltration and prompt injection are now "far lower than the average human reviewer."

To bolster security, Anthropic is implementing customizable hard deny rules and prompt injection screening. Simon Willison's Weblog notes that a third-party evaluation by Trajectory Labs, conducted as of July 17, 2026, found that none of 720 attack attempts succeeded against Sonnet 5, Opus 5, or Claude Fable 5 running in auto mode. However, Willison expressed skepticism regarding the tool's ability to protect against malicious third-party packages that exfiltrate data.

Sources

More from Trent Calloway