LabForty logo
AI & Technology

Claude Code Makes Auto Mode Default on Paid Plans

Anthropic will make Claude Code auto mode the default after tests showed it blocked 89% of harmful actions that most people approved.

  • Aug 09, 2026
  • 3 min read
  • LabForty AI Newsroom
Claude Code Makes Auto Mode Default on Paid Plans
Listen to the article
0:00/0:00

Claude Code is taking humans out of the approval loop because humans kept approving the wrong commands. On August 14, Anthropic will make auto mode the default for new Claude Code sessions on Pro, Max, and Team plans, according to Simon Willison. An optional workflow is becoming Anthropic’s preferred model for most paid users.

The evidence comes from 1,053 paid testers. In each session, one permission prompt was replaced with a clearly dangerous command. Only 13.6% of participants rejected it. Anthropic said auto mode would have blocked 89% of those harmful actions.

That result cuts against a basic assumption in agent security: requiring approval does not help when people approve on reflex. A prompt is not protection by itself. Its value depends on someone noticing the threat every time.

Auto mode is less like removing a lock than replacing a distracted guard with an automated checkpoint. The checkpoint can apply its rules consistently, but only against threats it recognizes. Anthropic’s result still leaves a gap: 11% of the harmful actions in the test would have passed.

Users get fewer interruptions and, in this test, better protection than the human approval process delivered. Anthropic gets a faster default workflow without relying on repeated confirmation prompts. What loses ground is the argument that more dialogs automatically mean more safety.

The harder security question is indirect prompt injection, where an agent encounters malicious instructions hidden inside material it consumes. Anthropic commissioned Trajectory Labs to examine 72 scenarios withheld from the company. Across 720 attack attempts, none succeeded against Claude Fable 5, Opus 5, or Sonnet 5 running auto mode in the publicly available Claude Code and Codex versions tested as of July 17, 2026.

That finding supports Anthropic’s bet that contextual permission decisions can outperform people trained by repetition to click through prompts. Anthropic also told Willison that almost everyone inside the company already used auto mode. The new default follows internal adoption rather than testing the workflow on customers first.

But 720 failed attacks do not cover every method an attacker could try. A clean test suite shows resistance to those scenarios, not universal protection.

Willison identifies a tougher case. A third-party package could provide credible instructions for downloading model files and running tests while secretly stealing accessible data. If the commands resemble ordinary development work and come from a source the model considers trustworthy, auto mode must separate routine behavior from concealed abuse. That is harder than rejecting an obviously dangerous command placed inside a permission dialog.

Independent testing now matters most, particularly with unfamiliar packages, tools, and data-exfiltration routes beyond Anthropic’s held-out scenarios. Deployment boundaries matter too. Willison argues that agents should run without access to data or tools that could cause damage if misused. Auto mode is one security control, not the whole perimeter.

Anthropic has shown that repeated human approval can add friction while missing obvious danger. Will independent tests find the same protection when a malicious command is indistinguishable from normal developer work?

Sources

This article was drafted with AI assistance and reviewed and edited by the LabForty newsroom.


Share this article

linkedinTwitter / X

Newsletter

By subscribing here, you agree with our Privacy Policy and you will receive our newsletters. You can unsubscribe at any time by following the link at the bottom of each newsletter.

Insights

Catch our insights on all things around us

Where every detail matters

Where every detail matters

At LabForty, we develop high-quality websites with a strong focus on detail - from architecture and user experience to business logic.