- Auto Mode becomes the default for new Pro, Max and Team sessions on August 14, while Enterprise and API deployments remain opt-in for now.
[[1]](https://claude.com/blog/auto-mode-default-in-claude-code) - Anthropic says Auto Mode blocked 937 of 1,053 dangerous commands, compared with 143 caught by human testers.
[[1]](https://claude.com/blog/auto-mode-default-in-claude-code) - Users can switch permission modes, and administrators can pin a different default or disable Auto Mode through managed settings.
[[1]](https://claude.com/blog/auto-mode-default-in-claude-code)[[2]](https://code.claude.com/docs/en/auto-mode-config)
Anthropic will make Auto Mode the default permission setting for new Claude Code sessions on Pro, Max and Team plans starting August 14, moving routine approval decisions from developers to a classifier that evaluates Claude’s tool calls. Enterprise, API, Amazon Bedrock, Google Cloud, Microsoft Foundry and AWS deployments remain opt-in while administrators review the change. [1]
Anthropic’s headline safety comparison comes from a controlled study of 1,053 paid professional testers. A dangerous command was substituted into a permission prompt during each session; testers caught 143 of the commands, or 13.6%, while Auto Mode blocked 937, or 89%. The test measured whether participants recognized a visibly dangerous command in a test environment, not how the system performs across live production codebases. [1][4]
How the default works #
Auto Mode routes tool calls through a classifier designed to block actions that are irreversible, destructive or outside the user’s trusted environment. Anthropic says blocked actions generally trigger a safer retry or a request for approval; after three consecutive blocks or 20 total blocks in one session, Claude Code falls back to manual approvals. [1][2]
The classifier is not a single static rule check. Anthropic’s technical account describes an input-layer probe for prompt-injection content and an output-layer transcript classifier that reviews user messages and tool calls. The deployed evaluation uses a fast first-stage filter followed by a more deliberate second stage when the first stage flags an action. [3]
Controls remain available #
The change does not remove manual review. Users can switch modes with Shift+Tab in the CLI or through the mode selector, while an existing user-set default remains unless the user accepts a one-time prompt to change it. Team administrators can set an organization-wide default or disable Auto Mode with managed settings. [1][2]
Anthropic says the classifier adds a small number of tokens to each tool call but will no longer charge Pro, Max and Team users for that overhead. It still recommends human review for high-stakes production infrastructure because Auto Mode reduces risk without eliminating it. [1]
Companies mentioned #
Further sources #
[[1] Anthropic’s August 7, 2026 announcement sets Auto Mode as the default for new P… ↗](https://claude.com/blog/auto-mode-default-in-claude-code)
[[2] Claude Code’s documentation describes Auto Mode’s classifier, default trust bou… ↗](https://code.claude.com/docs/en/auto-mode-config)
[[3] Anthropic’s technical account explains the two-layer design, two-stage classifi… ↗](https://www.anthropic.com/engineering/claude-code-auto-mode)
[4] The Decoder independently reported the August 14 rollout and reproduced Anthrop… ↗
The stories that matter, in one email. Free — unsubscribe anytime.