Anthropic makes Auto Mode default in Claude code for Pro, Max and Team plans

Anthropic announced that, effective 14 August, Auto Mode will be the default setting in Claude’s code for Pro, Max and Team subscriptions. Previously the tool operated in manual mode, requiring user approval for each action—a step that often reduced to a routine “Accept All” click for developers who do not write code daily. The change aims to eliminate this bottleneck and let sessions run without the user staying at the screen.
In automatic mode, prompts to the user are replaced by a dedicated classification system that blocks irreversible, destructive, or out-of-bounds actions. Anthropic claims this system is “smart and cautious” compared with the average human, allowing the manual loop to be removed without sacrificing safety. Users who previously set a different default will receive a one-time prompt to adopt the new permanent setting.
The company conducted internal and external red-team exercises, Prompt Injection tests, and a study involving more than 1,000 human participants. The results show Auto Mode blocked 89 % of malicious commands submitted, while the human participants blocked only 13.6 % of the same commands. The figures come from Anthropic’s own research and have not yet been independently verified, but the gap is described as too large to ignore.
Access via the API, Enterprise plans, and integrations with cloud providers AWS, Azure and GCP will remain in manual mode by default. Anthropic emphasizes that conservatism in production and enterprise environments is maintained. Any user can still switch the setting manually at any time, but the new default reflects the company’s assessment that automated guardrails now meet the reliability threshold for daily use.