Anthropic is changing how Claude Code works. Programming with the tool will soon require even less human oversight. The company announced that auto mode will become the default setting. This applies to Pro, Max, and Team accounts. The change takes effect on August 14.
This isn’t a brand-new feature. Anthropic first introduced a test version of auto mode back in March. At the time, the company described it as a way to balance speed and control. Anthropic explained more details in an announcement on Friday. When Claude Code runs in auto mode, it behaves differently than before.
Normally, the tool pauses and asks for human approval at each step. In auto mode, it skips that step. Instead, it proceeds automatically. The only exception is when an action is judged to be irreversible, destructive, or aimed outside the user’s own environment.
Anthropic also shared results from internal testing. According to the company, auto mode actually proved safer than manual review. The study involved 1,053 paid testers. In that study, auto mode caught 89% of harmful actions.
Read More: Anthropic signs $10 billion deal with AI cloud company Volta
Manual human review, by comparison, caught only 13.6%. Anthropic offered a possible explanation for that gap. The company noted that manual review can become habitual over time. In practice, users approve 97% of permission prompts in Claude Code, often without scrutiny.
Boris Cherny, who leads Claude Code, shared his own experience in a post on X. He said he and his team use auto mode exclusively. According to Cherny, they’ve been doing this for many months already. He added that he couldn’t imagine going back to constant permission prompts.
Anthropic also addressed safety improvements tied to this rollout. The company said it’s been adding new protective features. That includes prompt injection screening, designed to catch manipulation attempts hidden in inputs. It also includes customizable hard deny rules. These rules are meant to help prevent risks like data exfiltration, where sensitive information could be leaked or extracted without authorization.






