Anthropic will make auto mode the default setting in Claude Code for Pro, Max and Team plans starting Aug. 14, according to Simon Willison and TechCrunch. Auto mode lets the coding agent take actions without stopping to ask a human to approve each one.

Anthropic said a study of 1,053 paid testers found auto mode caught 89% of actions the company judged harmful, compared with 13.6% caught when a human reviewed each permission prompt individually, TechCrunch reported. The company attributed part of the gap to habituation, noting that people approve 97% of permission prompts regardless of the underlying risk.

Third party testing from Trajectory Labs ran 72 prompt injection scenarios, 720 attacks in total, against Claude Fable 5, Opus 5 and Sonnet 5 running in auto mode, and none of the attacks succeeded, according to Willison's account of the announcement.

"The team and I use Auto mode exclusively, and have been for many months. I couldn't imagine going back to permission prompts," said Boris Cherny, who leads Claude Code at Anthropic, according to TechCrunch. Speaking separately about how Anthropic runs Claude Code internally, employees Cat Wu and Thariq Shihipar said "almost every single person uses auto mode," per Willison's account of that discussion.

Willison, who has written that he expects a security incident involving AI coding agents this year, said he would "dearly like to be proved wrong" but wants more independent confirmation before trusting the safety numbers, and said he remains unconvinced auto mode can catch malicious third party packages disguised as legitimate developer tools.

For teams running Claude Code day to day, the change removes a source of friction but raises the cost of a single missed classification, since the default backstop shifts from a human checking each action to the model's own judgment starting Aug. 14. Anyone who relies on permission prompts as a safety net should set explicit deny rules before then.