Simon WillisonSunday · August 9, 2026FREE

Auto mode is now the default in Claude Code for Pro, Max, and Team plans

claudeagentssecurityauto-mode

Anthropic is making auto mode the default setting for new sessions in Claude Code for Pro, Max, and Team plans, effective August 14th. This change was discussed in a Fireside Chat with Cat Wu and Thariq Shihipar at the AI Engineer World’s Fair. Wu stated that within Anthropic, almost every person uses auto mode, and that they have "pretty much mitigated every attack" for main risk categories like prompt injection and data exfiltration, with risks "far lower than the average human reviewer." The article references evals, including a test with 1,053 paid testers where a single permission prompt was swapped for a clearly dangerous command. Only 13.6% of humans refused the harmful action, while auto mode would have blocked 89% of those actions. Anthropic also commissioned an evaluation from Trajectory Labs, which tested 72 indirect prompt injection scenarios held out from Anthropic across the latest publicly available versions of Claude Code and Codex as of July 17th, 2026. In that evaluation, none of the 720 attack attempts succeeded against Claude Fable 5, Opus 5, or Sonnet 5 running auto mode. Simon Willison, the author, expresses skepticism, noting that auto mode still leaves 11% of cases where it would not prevent harmful actions, and questions how auto mode could protect against malicious third-party packages that instruct agents to run commands that exfiltrate data. He calls for more independent confirmation of Anthropic's claims.

// why it matters

Auto mode becoming default in Claude Code changes how developers interact with coding agents, potentially reducing manual approval but raising security questions.

Sources

Primary · Simon Willison
▸ Read original at simonwillison.net

Like this? Get the next digest.