The default for Pro, Max, and Team accounts takes effect August 14; Anthropic's own study says auto mode caught 89% of harmful actions vs. 13.6% for human review.
Starting August 14, Anthropic is making auto mode the default for Claude Code on Pro, Max, and Team accounts, removing the per-step permission prompt that has defined the assistant since launch. In its place: Claude proceeds unless an action is "irreversible, destructive, or aimed outside your environment," per Anthropic's product blog.
Underpinning the change is a 1,053-tester study Anthropic is publishing alongside it. By the company's own numbers, auto mode caught 89% of harmful actions. Human review, the prompt a user clicks through, caught 13.6%. The gap, Anthropic says, traces to approval fatigue: users approve 97% of permission prompts in Claude Code, which makes the human gate closer to a rubber stamp than a checkpoint.
Two new safety features ship with the change: prompt-injection screening on inputs, and customizable hard-deny rules for actions like data exfiltration. Claude Code head Boris Cherny posted on X that his team "uses Auto mode exclusively" and would not want to return to permission prompts.
Anthropic paid the 1,053 testers, defined the harm categories, and measured "safer" against habitual approval rather than attentive review. Simon Willison and Zvi Mowshowitz had already flagged the vendor-study framing before the rollout date was set. Cursor shipped a parallel auto-review capability in May, so the default-on question is no longer only Claude's to answer.