Skip to content
← All news
4 min read

Anthropic is turning Claude Code's auto mode on by default

From August 14, Claude Code stops asking permission for most actions on Pro, Max, and Team plans. Anthropic's own study says the prompts were theater: humans caught 13.6% of dangerous commands, the classifier caught 89%.

Anthropic checked what human review catches: 13.6%. Its classifier caught 89%. So the default changed.

Anthropic announced on August 9 that Claude Code, its terminal coding agent, will ship with auto mode on by default starting August 14 for Pro, Max, and Team accounts. Instead of asking permission per action, a classifier lets work proceed unless it judges the action irreversible, destructive, or aimed outside your environment. We run Claude Code every day at the studio, so a change to its default safety posture is a change to ours.

The numbers behind the decision

Anthropic's study followed 1,053 testers and found that manual review catches 13.6% of dangerous commands. The classifier caught 89%. The reason is not that people are careless, it is that approval fatigue is real: users approve 97% of permission prompts, which turns the prompt into a click, not a review. Testers with auto mode on also produced about 25% more pull requests.

What still gets blocked

Auto mode is not the same as no brakes. Actions the classifier flags as irreversible or destructive still stop for approval, prompt injection screening ships alongside the change, and teams can write hard deny rules that no classifier judgment can override. Anthropic cites internal cases where the system blocked confidential file uploads and halted roughly 2,000 processes that would have disrupted GPU training runs. In its published audit, 0 of 720 prompt injection attempts landed against Claude models. Enterprise plans keep manual mode unless an admin opts in.

The honest tradeoff

Less intervention means less reading. If the agent proceeds on its own for hours, the human in the loop understands the diff less deeply than the one who clicked through every step, and that cost lands later, in review and debugging. The counterargument in Anthropic's data is that the clicking was not producing understanding either, just friction. Both can be true.

Why a build studio cares

Claude Code is listed on our /tools page because it is part of how GattyWorks ships. Defaults matter more than settings: most people never change them, so August 14 changes the real-world behavior of thousands of coding agents at once, ours included. Our plan is to keep auto mode on, write deny rules for deploys and anything credential-shaped, and treat the change the way we treat any dependency bump: read the changelog, then verify the behavior ourselves.

Next step: read TechCrunch's report and The Decoder's writeup, then check your own approval habit: if you said yes to the last ten prompts without reading them, the study is about you. If you want agent guardrails scoped for your team, write to us at hello@gattyworks.com.

AI ToolingClaude CodeAnthropicClaudeCodeAnthropicAIAgentsAutoModeDeveloperToolsAICodingPromptInjectionAISafetyDevToolsCodingAgents

Ready to know?

Send what you want checked or built. Fixed scope, price, and date in writing inside 24 hours, or the website or audit fee on your first project is refunded in full.

24 clock hours. Weekends included.