{"id":4773,"date":"2026-08-10T17:41:40","date_gmt":"2026-08-10T17:41:40","guid":{"rendered":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/08\/10\/anthropic-makes-claude-codes-auto-mode-the-default-betting-automation-beats-manual-review\/"},"modified":"2026-08-10T17:41:40","modified_gmt":"2026-08-10T17:41:40","slug":"anthropic-makes-claude-codes-auto-mode-the-default-betting-automation-beats-manual-review","status":"publish","type":"post","link":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/08\/10\/anthropic-makes-claude-codes-auto-mode-the-default-betting-automation-beats-manual-review\/","title":{"rendered":"Anthropic Makes Claude Code\u2019s Auto Mode the Default, Betting Automation Beats Manual Review"},"content":{"rendered":"<div><img data-opt-id=2142302558  fetchpriority=\"high\" decoding=\"async\" width=\"770\" height=\"300\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/08\/claude_code_auto_mode_with_text_770x300.jpg\" class=\"attachment-large size-large wp-post-image\" alt=\"\" \/><\/div>\n<p><img data-opt-id=308969097  fetchpriority=\"high\" decoding=\"async\" width=\"150\" height=\"150\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/08\/claude_code_auto_mode_with_text_770x300-150x150.jpg\" class=\"attachment-thumbnail size-thumbnail wp-post-image\" alt=\"\" \/><\/p>\n<p><span>Anthropic is removing a step most developers were skipping anyway. Starting August 14, Claude Code will run in auto mode by default for Pro, Max, and Team plan users, cutting back the steady stream of permission prompts that ask developers to approve each action the AI agent wants to take.<\/span><\/p>\n<p><span>The company first tested auto mode back in March, framing it as a middle ground between speed and control. Instead of stopping to ask permission for every command, auto mode routes each tool call through a classifier that only interrupts when an action looks irreversible, destructive, or aimed outside the user\u2019s own environment. Everything else runs without a pause.<\/span><\/p>\n<p><span>The timing tracks with a pattern Anthropic says it\u2019s seeing across its own usage data: People don\u2019t actually review most permission prompts. According to the company\u2019s blog post announcing the change, users approve 97% of permission requests in Claude Code. That\u2019s not evidence people are carefully checking each command. It\u2019s evidence they\u2019ve stopped reading them.<\/span><\/p>\n<p><span>Anthropic backs this up with numbers from a controlled study of 1,053 paid testers. Partway through each coding session, researchers swapped in a genuinely dangerous command disguised as a routine permission prompt. Human reviewers caught it 13.6% of the time. Auto mode caught it 89% of the time. The gap widened as sessions ran longer \u2014 human catch rates dropped to around 5% after 50 or more prior prompts, while auto mode\u2019s detection rate held steady no matter how long the session ran.<\/span><\/p>\n<p><span>\u201cA 13.6% catch rate tells you per-action approval stopped working long before anyone turned it off,\u201d said Mitch Ashley, VP and practice lead for software lifecycle engineering and AI-native software engineering at <a href=\"https:\/\/futurumgroup.com\/\" target=\"_blank\" rel=\"noopener\">The Futurum Group<\/a>. \u201cTeams counted clicks because clicks were easy to count. Nobody measured whether the click caught anything.\u201d<\/span><\/p>\n<p><span>Anthropic paired that testing with real production data. Looking at flagged sessions from May and June, the company found that sessions using manual approval contained serious unintended harm more than twice as often as auto mode sessions \u2014 6.3% versus 2.4% at production-severity levels, like accidentally deleting rows from a live database.<\/span><\/p>\n<p><span>The company also ran auto mode through adversarial testing with Apollo Research, an AI safety firm, injecting synthetic attacks into real coding trajectories. After a find-fix-verify cycle, auto mode\u2019s miss rate on a held-out attack set dropped from 12% to 7%. A separate third-party evaluation from Trajectory Labs tested 72 prompt injection scenarios against Claude Code and OpenAI\u2019s Codex. None of the 720 attack attempts succeeded against Claude Code running auto mode. Codex\u2019s comparable auto-review mode had a 5.83% success rate on the same attacks.<\/span><\/p>\n<p><span>None of this means auto mode approves everything. Anthropic built in specific guardrails it calls hard denies \u2014 data exfiltration, for instance, is a category the classifier is designed to never approve, full stop. The classifier also checks git status before destructive commands like <\/span><span>git reset \u2013hard<\/span><span>, distinguishes between public and private repositories before allowing pushes, and screens content pulled from external sources for prompt injection attempts. If the classifier blocks something three times in a row, or twenty times across a session, Claude Code drops back into manual approval mode.<\/span><\/p>\n<p><span>There\u2019s a productivity angle here too. Anthropic says teams using auto mode ship about 25% more pull requests than those using manual review. Nuro, one of the companies quoted in Anthropic\u2019s announcement, described kicking off an agent at 10 p.m. and getting three finished PRs by morning \u2014 something that wasn\u2019t realistic under a model that stopped for permission at every step. Adobe, Gusto, and Garner Health are also running auto mode as their production default, with Garner pushing it to all 550 employees through managed settings.<\/span><\/p>\n<p><span>That shift doesn\u2019t remove the human from the process. It moves them earlier. \u201cHuman in the loop isn\u2019t scalable and must become human engineering the loop, with the person defining what an agent may touch before the session starts,\u201d Ashley said. \u201cTeams still owe auditors a record of what ran unattended and why.\u201d<\/span><\/p>\n<p><span>For now, the change only applies to Pro, Max, and Team plans. Auto mode stays opt-in on Claude Enterprise, the Claude API, and the major cloud platforms \u2014 AWS, Google Cloud, and Microsoft Foundry \u2014 giving admins time to evaluate it before Anthropic plans to flip the default there too within the next month. Enterprise admins who want to move now can already set auto mode as the default through managed settings.<\/span><\/p>\n<p><span>Anthropic is also dropping the token surcharge tied to the classifier\u2019s overhead for Pro, Max, and Team users, effective immediately. Users who\u2019ve already set a different permission mode manually won\u2019t be switched automatically \u2014 they\u2019ll get a one-time prompt asking if they want to opt in.<\/span><\/p>\n<p><span>Claude Code Head Boris Cherny put it plainly in a post on X: He and his team have used auto mode exclusively for months and don\u2019t want to go back to permission prompts. Anthropic\u2019s data suggests that\u2019s less an endorsement than a description of what happens to most users\u2019 vigilance over time anyway \u2014 the company is just betting that a classifier trained on it does the job better than tired humans clicking \u201capprove.\u201d<\/span><\/p>\n<p><a href=\"https:\/\/devops.com\/anthropic-makes-claude-codes-auto-mode-the-default-betting-automation-beats-manual-review\/\" target=\"_blank\" class=\"feedzy-rss-link-icon\">Read More<\/a><\/p>\n<p>\u200b<\/p>","protected":false},"excerpt":{"rendered":"<p>Anthropic is removing a step most developers were skipping anyway. Starting August 14, Claude Code will run in auto mode [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":4774,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[5],"tags":[],"class_list":["post-4773","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-devops"],"_links":{"self":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/4773","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/comments?post=4773"}],"version-history":[{"count":0,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/4773\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media\/4774"}],"wp:attachment":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media?parent=4773"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/categories?post=4773"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/tags?post=4773"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}