Auto mode is now the default in Claude Code for Pro, Max, and Team plans
Starting August 14th, auto mode becomes the default setting for new sessions in Claude Code across Pro, Max, and Team plans. Anthropic transitioned to this default because nearly everyone at the company uses auto mode internally, driven by high confidence in its safety and threat mitigation capabilities.
To support this change, Anthropic published evaluations comparing human decision-making against auto mode. In a test involving 1,053 paid human testers facing a clearly dangerous command, only 13.6 percent of humans refused the harmful action, whereas auto mode would have blocked 89 percent of those actions. Additionally, a third-party evaluation by Trajectory Labs tested 72 indirect prompt injection scenarios across 720 attack attempts against newer models running auto mode, resulting in zero successful attacks.
Despite these findings, questions remain regarding safety against complex threats. While confirmation fatigue makes human approval unreliable, auto mode still leaves an 11 percent failure margin in certain tests. Complex attacks involving malicious third-party packages that masquerade as standard test setup steps continue to pose potential risks, leading to calls for independent confirmation and careful restriction of agent access to sensitive data and tools.