Starting August 14, Anthropic will activate Auto Mode by default for new Claude Code sessions for users on Pro, Max and Team licenses. In this mode, the AI coding tool executes shell, Git and tool calls autonomously instead of asking for permission at every step.
Auto Mode is not unrestricted access: a classifier evaluates each tool call for whether the change is potentially irreversible, destructive or aimed at targets outside the intended environment. Doubtful steps are blocked, and the system either seeks safer alternatives or requests user approval. After three consecutive blocks or 20 blocks in a session, Claude Code automatically reverts to manual approvals. Anthropic explicitly recommends human review for changes to production infrastructure.
The company cites "permission fatigue" as the motivation: users approved 97 percent of Claude Code's permission prompts and rejected only 3 percent, while in higher-level planning dialogs they rejected 39 percent of suggestions. In a controlled study, humans spotted only 13.6 percent of deliberately injected, clearly dangerous commands, whereas Auto Mode blocked 89 percent. An analysis of sessions flagged by Anthropic's safety pipeline found harmful, not explicitly requested actions of at least production-relevant severity in 6.3 percent of manually approved sessions, versus 2.4 percent with Auto Mode.
Protective mechanisms include Hard Denies the classifier never overrides, such as potential data exfiltration like copying source code to external destinations. For Git actions the classifier considers context such as uncommitted changes, and it checks whether a target repository is public, private or trusted. Prompt injection screening is also performed. Anthropic points to internal and external red-teaming tests as further evidence of the classifier's reliability.
On productivity, Anthropic claims Auto Mode users deliver around 25 percent more pull requests, referencing deployments at Adobe, Nuro, Gusto and Garner Health. However, pull request counts alone say little about final quality; figures on cycle times, error rates, review effort and production incidents are absent from the announcement.
The switch is default unless customers have set a different preference. The classifier consumes additional tokens, but Anthropic will no longer charge this extra cost for Pro, Max and Team plans. Claude Enterprise, the Claude API and Claude Code via AWS, Amazon Bedrock, Google Cloud Agent Platform and Microsoft Foundry are unaffected for now, but Anthropic plans to move them to Auto Mode by default over the coming month.
Comments
No comments yet — be the first.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Nothing arrived? Check your spam folder — and mark the mail as "Not spam" so it lands in your inbox next time.