Claude Code auto mode blocks 89% of dangerous commands by default

Anthropic is done asking Claude Code users to click “approve” every few minutes. Starting August 14, 2026, Claude Code auto mode becomes the default setting for new sessions across the Pro, Max, and Team plans, replacing the constant stream of permission prompts that have long defined how developers interact with AI coding agents. The company says it has the data to back the switch, but independent commentary — including from developer and researcher Simon Willison — suggests the story is more nuanced than a simple safety win.
Key takeaways
- Anthropic makes auto mode the default for Claude Code Pro, Max, and Team plans beginning August 14, 2026.
- In a test of 1,053 paid users, auto mode blocked 89% of dangerous commands, while human testers refused only 13.6% of the time.
- Independent evaluator Trajectory Labs ran 720 indirect prompt injection attacks against Claude Fable 5, Opus 5, and Sonnet 5 running auto mode — none succeeded.
- Anthropic will stop charging for the extra tokens the auto mode classifier uses per tool call.
- Analysts still flag unresolved risks, including malicious third-party packages that could exfiltrate data undetected.
Anthropic makes Claude Code auto mode the default
The shift answers a problem Anthropic engineers have talked about openly: confirmation fatigue. Asking a human to approve every step of an AI agent’s workflow sounds cautious, but in practice it trains people to click through prompts without really reading them. According to Anthropic, auto mode swaps that repetitive approval loop for a classifier that inspects each tool call for actions that are irreversible, destructive, or clearly out of bounds. If the classifier flags something, Claude either looks for a safer path or falls back to asking for permission — and if blocks keep piling up, the whole session reverts to manual approval.
… Continue reading the full article at the original source below.



