One email each morning — yesterday's AI, sortedGet it in your inbox

METAL LAB

Claude Code switches to auto mode by default

Anthropic to enable auto-approval mode by default for Pro, Max, and Team accounts starting August 14

노트북 화면에서 디지털 손이 나오는 사이버 보안 이미지

이미지: TechCrunch AI

Summary

  • Anthropic will switch Claude Code's auto mode to the default setting for Pro, Max, and Team accounts starting August 14
  • In auto mode, actions run without human approval unless they are judged "irreversible, destructive, or aimed outside your environment"
  • In testing with 1,053 users, auto mode caught 89% of harmful actions, while manual review caught only 13.6%
적용 시작일
2026년 8월 14일
적용 대상
Claude Code Pro, Max, Team 계정
오토 모드 최초 공개
2026년 3월 테스트 버전으로 공개
유해 행동 포착률
오토 모드 89% vs 수동 검토 13.6% (1,053명 유료 테스터 대상)
수동 승인 관행
사용자들이 권한 요청 프롬프트의 97%를 승인
추가 안전 기능
프롬프트 인젝션 스크리닝, 커스터마이즈 가능한 하드 거부 규칙

Anthropic announced that it will switch the auto mode of its coding tool Claude Code to the default setting for Pro, Max, and Team accounts starting August 14. Auto mode was first introduced as a test feature back in March, framed as an attempt to balance speed and control.

No approval required, except for 'destructive' actions

According to Anthropic, auto mode proceeds without requesting human approval at every step, unless an action is judged to be "irreversible, destructive, or aimed outside your environment."

The company also shared results from its own testing. In a study involving 1,053 paying testers, auto mode caught 89% of harmful actions, while manual human review caught only 13.6%. Anthropic attributed this gap to the fact that "manual review becomes habitual, with users approving 97% of Claude Code's permission request prompts."

Development team already uses only auto mode

Boris Cherny, head of Claude Code, wrote on X that "my team and I have been using only auto mode for months. I don't think I can go back to permission prompts." Anthropic said that alongside this switch, it has added safety features including prompt injection screening and customizable hard-deny rules to prevent data leaks.