2 min read

Claude Code will make auto mode the default

Claude Code will make auto mode the default for Pro, Max, and Team users on August 14, using a classifier to screen tool calls.

Image: 9to5Mac

Claude Code will switch auto mode on by default for paid users on August 14, replacing repeated approval prompts with an automated safety check. The change applies to Pro, Max, and Team sessions unless a user or administrator has pinned a different permission setting.

How Claude Code auto mode works

Instead of asking for confirmation before every tool call, Claude Code will run each request through a classifier that checks for irreversible, destructive, or out-of-bounds actions. When the classifier blocks a request, Claude can attempt a safer approach or ask the user for permission. If it encounters repeated blocks, the session falls back to manual approval.

Anthropic will also stop charging for the “small number of extra tokens per tool call” used by the classifier. That removes one of the practical costs of leaving the feature enabled during long-running coding sessions.

The policy change follows an earlier episode in which Claude Code automatically continued unanswered questions for 60 seconds. Anthropic later reversed that default in version 2.1.200, as we reported in Claude Code’s earlier auto-answer reversal. Auto mode is different: it is designed to replace routine approvals while retaining checks for potentially dangerous operations.

Anthropic’s safety and productivity figures

Anthropic says a study involving 1,053 paid testers found that people caught 13.6% of dangerous commands, compared with 89% for auto mode. Human performance dropped to about 5% after 50 prompts, according to the company.

Recommended reading

Kimi K3 reportedly bypassed AI safety sandbox via GitHub

Anthropic still warns that classifiers cannot eliminate risk and recommends human review for production changes. The company also says Team and Enterprise customers using auto mode ship about 25% more pull requests, though the report does not provide the study methodology, the definition of a “dangerous command,” or independent verification of either result.

9to5Mac additionally pointed to auto mode as part of Claude Code’s broader push toward long-running work, alongside routines, voice mode, and the in-app Mac browser. It contrasted Anthropic’s decision with OpenAI’s choice to opt out of auto mode for its most powerful version of GPT-5.6 at one point as an extra precaution.

For experienced users, making auto mode the default is a practical move: the supplied numbers suggest automated checks outperform humans at spotting dangerous commands, while the fallback to manual approval limits the damage from repeated blocks. But the evidence remains entirely Anthropic’s, and the company did not say when—or whether—the same default will apply to Enterprise users. That missing rollout detail matters more than the token savings for organizations making production changes.

Ava Chen

AI Editor

Ava covers the rapidly evolving world of artificial intelligence, from foundational models and research labs to the real-world economics of intelligence. With a background in computational linguistics, she cuts through the hype to find out what actually works. She firmly believes that benchmarks are just marketing until reproduced in the wild.

via 9to5Mac

/ Keep reading