
Anthropic will make auto mode the default in Claude Code for Pro, Max, and Team users starting August 14. The setting allows Claude Code to continue working without asking for approval at every step unless an action is classified as irreversible, destructive, or directed outside the user’s environment.
Anthropic first introduced auto mode in testing earlier this year as an alternative to repeated permission prompts. In its official announcement, the company said new sessions will automatically use auto mode unless users or administrators have already selected and pinned another default.
Enterprise customers, Claude API users, and customers using Claude through AWS, Google Cloud, and Microsoft Foundry will continue to use auto mode on an opt-in basis for now. Anthropic said it plans to make the setting the default for those users in the coming month.
Anthropic Says Auto Mode Caught More Harmful Actions
Instead of asking users to approve each individual tool call, auto mode sends actions through a classifier designed to block potentially harmful commands. When an action is blocked, Claude can try a safer approach or ask the user directly for permission.
Anthropic said its testing included internal and external red-teaming, prompt-injection evaluations, production data, and a controlled study involving 1,053 paid testers. Across its evaluations, the company said auto mode matched or performed better than manual review.
The company reported that auto mode detected 89% of harmful actions in the controlled study, compared with 13.6% for users reviewing permission prompts manually. Anthropic also found that Claude Code users approve about 97% of individual permission requests, suggesting repeated prompts can become routine rather than receiving close review.
Claude Code head Boris Cherny said on X that his team had been using auto mode exclusively for months and preferred it to repeated permission prompts.
Claude Code Can Run Longer Without Interruption
Anthropic said reducing permission prompts also allows Claude Code to work autonomously for longer periods, particularly on large programming tasks. Among Team and Enterprise users already using auto mode, the company said users produced about 25% more pull requests.
The company has also added protections including prompt-injection screening and configurable deny rules that can prevent actions such as data exfiltration. Existing permission rules continue to apply before auto mode’s classifier, although broad rules allowing arbitrary code execution are temporarily ignored so they cannot bypass the classifier.
Anthropic said auto mode does not eliminate risk and still recommends manual review for high-stakes changes involving production infrastructure. Users can also switch back to another permission mode or administrators can disable auto mode across an organisation.
Featured image credits: SlideTeam
For more stories like it, click the +Follow button at the top of this page to follow us.
