Anthropic Defaults Claude Code to Auto Mode for Safety
Anthropic is making auto mode the default setting for Claude Code users on Pro, Max, and Team plans starting August 14, aiming to improve security by reducing human confirmation fatigue.

Starting August 14, Anthropic will make auto mode the default configuration for new sessions across its Claude Code Pro, Max, and Team tiers. The shift reflects the company's growing confidence in the autonomous setting's ability to handle tasks safely without constant human intervention. Anthropic developers argue that relying on users to manually approve every action leads to confirmation fatigue, which ultimately compromises security more than letting the AI manage its own guardrails.
To support this transition, Anthropic released evaluation data highlighting the limits of human oversight. In a study involving 1,053 paid testers, researchers secretly swapped a standard permission prompt for a hazardous command. Only 13.6 percent of the human participants noticed and rejected the dangerous action. In contrast, Claude Code's auto mode successfully blocked 89 percent of those same harmful commands, though that still leaves an 11 percent failure rate where the system failed to prevent the action.
Anthropic also commissioned Trajectory Labs to conduct independent security evaluations on versions of Claude Code and Codex available as of July 17, 2026. The firm subjected the setup to 72 indirect prompt injection scenarios held out by Anthropic. Across 720 total attack attempts, not a single exploit succeeded against Claude Fable 5, Opus 5, or Sonnet 5 when running in auto mode.
Despite these perfect marks against indirect prompt injections, security experts remain cautious. Critics point out that sophisticated attacks, such as malicious third-party packages that trick the system into fetching compromised files, could still bypass these automated defenses. While Anthropic claims to have mitigated the primary risks of data exfiltration and prompt injection, practitioners are advised to maintain isolated environments to ensure autonomous agents cannot access sensitive production databases or critical tools.
This is our own summary of reporting by Simon Willison



