2026-08-10-Mon · Anthropic · ClaudeCode

From Issue 9 (2026-08-10) · 10 stories in this issue

❯ Claude Code Defaults to Auto Mode Starting August 14; Anthropic Says It Blocks Harmful Actions More Accurately Than Human Review

CHANGEAnthropic announced that starting August 14, Claude Code will enable auto mode by default for Pro, Max, and Team subscribers: the model will no longer request human approval at every step, pausing to ask only when an action is deemed irreversible, destructive, or directed outside the environment. Users who have pinned a different default mode are unaffected.

DATABehind the decision is comparative data Anthropic published: in an earlier experiment with 1,053 paid testers, auto mode’s classifier blocked 89% of harmful actions, while step-by-step human approval caught only 13.6% — people habitually clicked “approve” and let dangerous actions slip through. The company says teams with auto mode enabled also produced roughly 25% more code merge requests.

PACKAGEAlso shipping alongside are prompt-injection screening and customizable hard refusal rules; Anthropic announced it will no longer charge subscribers for the extra tokens the classifier consumes on each tool call.

SHIFTThis amounts to Anthropic publicly declaring the safety ritual of step-by-step human approval obsolete — developer attention is the real scarce resource, so rather than burn it on confirmation dialogs, hand it to the classifier. What enterprise security teams will have to verify next is whether that set of hard refusal rules can catch their own compliance red lines.

▪ SIGNAL13.6% vs. 89% — that pair of numbers reclassifies “human-in-the-loop” from safety guarantee to security vulnerability.