Anthropic has changed how permissions work in its coding tool, Claude Code. As of August 14, new sessions on the Pro, Max, and Team plans start in auto mode. Instead of asking for approval on every action, a classifier now steps in only when something looks risky. The company published its testing data, including a controlled study with 1,053 participants, and says the classifier stopped dangerous commands more reliably than people reviewing prompts by hand.

A new default for new sessions

The change applies to the Pro, Max, and Team plans. Anyone who never picked a permission mode will find that sessions started on or after August 14 run in auto mode. Users who had set a different default get a one-time prompt asking whether they want to switch. Nothing changes for people whose admin has pinned an organization-wide default.

Auto mode consumes extra tokens because every tool call passes through a classifier. Anthropic has stopped charging Pro, Max, and Team users for that overhead.

Auto mode stays opt-in for now on Claude Enterprise, the Claude API, Claude Platform on AWS, Amazon Bedrock, Google Cloud's Agent Platform, and Microsoft Foundry. The idea is to give admins time to review the change, and Anthropic plans to make it the default on those surfaces within about a month.

Approval prompts had already stopped working

The reasoning behind the switch is that the confirmation dialog was no longer functioning as a safety mechanism. Users approve 97 percent of Claude Code permission prompts, and reject only 3 percent. The same users reject 39 percent of the plans Claude presents for approval, which suggests individual permission requests are being clicked through reflexively.

Settings files tell a similar story. As of June 2026, 49.5 percent of active CLI users had written their own Bash allow-rule. Of those, 5 percent allow shell commands outright, and another 43 percent have rules that permit whole interpreters such as python or node, which amounts to much the same thing in practice. That share is growing by roughly 5 percentage points every 5 weeks. On top of that, 62 percent have used bypassPermissions or clicked the option to stop being asked, and 25 percent of interactive sessions begin in bypass mode.

Permission rules still run ahead of the classifier in auto mode. The exception is allow-rules broad enough to grant arbitrary code execution, which are set aside so commands cannot skip the classifier entirely. Settings files are left untouched, and the rules apply again as soon as the user switches modes.

In a study of 1,053 people, humans caught 13.6 percent

Anthropic recruited 1,053 paid testers through a research vendor and had them work in a purpose-built test environment. Partway through each session, one permission prompt was swapped for a clearly dangerous command, and the vendor recorded whether the tester approved it. Participants knew they were being evaluated but were not told what was being measured.

The testers stopped the dangerous command 13.6 percent of the time (143 of 1,053). Auto mode blocked the same commands 89 percent of the time (937 of 1,053). Head to head, auto mode blocked 800 commands that a human approved, while humans blocked only 6 that auto mode let through. Human accuracy also fell as sessions ran longer, from around 17 percent early on to roughly 5 percent after 50 or more prompts. Auto mode's block rate stayed flat regardless of session length.

Production data shows a similar gap. Reviewing sessions flagged by its safety pipeline between May and June 2026, Anthropic found that harmful actions at production-level severity that the user had not explicitly requested appeared in 6.3 percent of manually approved sessions, compared with 2.4 percent of auto mode sessions.

External red-teaming tightened the defenses

Apollo Research, a UK-based AI safety startup, spent two weeks probing the classifier by injecting synthetic attacks into real coding trajectories and sharing the ones that got through. Anthropic hardened the classifier largely by giving it more context about the environment it protects, such as repository visibility and git state, then retested against a held-out attack set it never had access to. Across the shared and held-out sets, the miss rate fell from 12 percent to 7 percent.

For prompt injection, Anthropic commissioned an evaluation from a third party, Trajectory Labs. The test used 72 indirect prompt injection scenarios, each run 10 times. None of the 720 attempts succeeded against Claude Fable 5, Opus 5, or Sonnet 5 running auto mode. Under the same conditions, 5.83 percent of attacks succeeded against GPT-5.6 Sol in Codex's Auto-review mode, and 19.03 percent succeeded in Full Access mode.

Anthropic also described three actions auto mode blocked internally. In the first, Claude failed to upload a report to an internal drive and fell back on publishing the same document to a public code-sharing site. In the second, during a long-running session, Claude attempted a mass process kill across roughly 2,000 pods along with deletions that would have taken down in-flight training jobs. In the third, asked to provision read-only billing access, Claude reached for a cloud role with full administrative control at the account root. In each case Claude either found a safer path on its own or checked in with the user.

Switching back takes one keystroke

Modes can be changed with Shift+Tab in the CLI or from the dropdown in the desktop app. Organizations can pin a default with defaultMode in managed settings, or turn the feature off entirely with disableAutoMode.

Anthropic is explicit that auto mode relies on classification and therefore does not eliminate risk. For high-stakes changes to production infrastructure, the company still recommends reviewing Claude's actions yourself.

Summary

Auto mode became the default for Claude Code on the Pro, Max, and Team plans on August 14. The decision replaces permission prompts that users were approving 97 percent of the time with a classifier that, in a controlled study of 1,053 testers, caught 89 percent of dangerous commands against 13.6 percent for human review. Enterprise and API users keep auto mode opt-in for now, with a default switch planned within about a month. Anyone who prefers the old workflow can change it with Shift+Tab or through managed settings.