Anthropic is making auto mode the default setting for new sessions in Claude Code for Pro, Max, and Team plans starting on August 14th. This change reflects the company's confidence in the feature's ability to mitigate risks like prompt injection and data exfiltration more effectively than human review.
- A controlled study of 1,053 paid testers found that auto mode would have blocked 89% of harmful actions, compared to only 13.6% refused by humans.
- An evaluation by Trajectory Labs tested 720 indirect prompt injection scenarios against Claude Fable 5, Opus 5, and Sonnet 5 running auto mode.
- None of the 720 attack attempts succeeded against the specified Claude models during the third-party evaluation.
Anthropic considers this shift important because confirmation fatigue leads to unsafe behavior in human reviewers, whereas auto mode significantly reduces exposure to malicious instructions.