Anthropic is making auto mode the default in Claude Code for Pro, Max, and Team plans starting August 14. New sessions will run this way unless a user has already pinned a different setting. In auto mode, Claude Code no longer asks for approval on every step. A classifier reviews each action and only stops if it looks irreversible, destructive, or aimed outside the local environment. The company tested this with 1,053 paid testers. Auto mode blocked 89 percent of harmful actions. Human reviewers caught only 13.6 percent, and that rate fell further as sessions grew longer. Users approve 97 percent of permission prompts today, which points to approval fatigue. Anthropic is also adding prompt injection screening and customizable hard deny rules. Auto mode stays opt-in for Enterprise and API users for now. The company plans to expand the default later. Teams already using it report shipping about 25 percent more pull requests.
Anthropic is making auto mode the default in Claude Code for Pro, Max, and Team plans starting August 14. New sessions will run this way unless a user has already pinned a different setting. In auto mode, Claude Code no longer asks for approval on every step. A classifier reviews each action and only stops if it looks irreversible, destructive, or aimed outside the local environment. The company tested this with 1,053 paid testers. Auto mode blocked 89 percent of harmful actions. Human reviewers caught only 13.6 percent, and that rate fell further as sessions grew longer. Users approve 97 percent of permission prompts today, which points to approval fatigue. Anthropic is also adding prompt injection screening and customizable hard deny rules. Auto mode stays opt-in for Enterprise and API users for now. The company plans to expand the default later. Teams already using it report shipping about 25 percent more pull requests.