Claude Code turns on auto mode by default Aug 14
It will act on its own more often, catching risky commands before they run instead of asking permission for each step.
Starting August 14, Claude Code will act on its own more often instead of asking permission for every step, and it is worth knowing what that switch actually does before it turns on for you.
Claude Code is Anthropic's coding tool, and up to now it has stopped to ask permission before many actions, like running a command or editing a file. From August 14, new sessions on the Pro, Max, and Team plans will run in auto mode by default. The feature stays opt-in for now on Claude Enterprise, the Claude API, and the big cloud platforms, AWS Bedrock, Google Cloud's Agent Platform, and Microsoft Foundry, giving admins on those plans time to review it first.
Mechanically, auto mode replaces most permission prompts with a classifier, a small AI check that looks at each action before it runs and blocks risky ones. When it blocks something, Claude usually finds a safer way to do the same task, or asks you directly. If it keeps hitting blocks, three in a row, or twenty across one session, it falls back to asking for manual approval again. Anthropic is also dropping the extra charge for running that classifier on Pro, Max, and Team plans, effective today.
The reason Anthropic gives for making this the default is that people were not really reviewing the prompts anyway. Its own data shows users approve 97% of permission prompts, which reads less like careful review and more like reflexive clicking. People do push back on other kinds of AI decisions: when Claude proposes a plan for approval, users reject it 39% of the time. But for individual permission requests in the middle of a task, the rejection rate drops to just 3%. As of June 2026, 49.5% of active users had manually created a rule that lets certain commands run without asking, called a Bash allow-rule; 5% allow any shell command outright, and another 43% have rules like Bash(python:*) that are close to the same thing in practice. That share is growing roughly 5 percentage points every five weeks, and 62% of users have at some point clicked don't ask again for shell commands entirely.
To test whether the classifier actually catches more than a human would, Anthropic ran a study with 1,053 paid testers. Partway through each session, one routine permission prompt was swapped for a clearly dangerous command. The testers caught the dangerous command just 13.6% of the time (143 of 1,053), while auto mode blocked 89% of the same commands (937 of 1,053).
The upside Anthropic points to is speed: unblocked from constant prompts, Claude can work on its own for longer stretches, which matters more with slower, more capable models like Opus 5 that are meant to run for hours. Among its Teams and Enterprise customers already using auto mode, including Adobe, Nuro, Gusto, and Garner Health, adopters ship about 25% more pull requests, proposed code changes, than those still on manual approval.
The testers caught the dangerous command just 13.6% of the time (143 of 1,053), while auto mode blocked 89% of the same commands (937 of 1,053).via Claude →