Anthropic is changing Claude Code so that Auto mode becomes the default setting for new sessions on Pro, Max, and Team plans starting August 14th. This shift follows internal adoption at Anthropic and new evaluation data demonstrating improved safety against prompt injection.
- A study of 1,053 paid testers found that while only 13.6% of humans refused a dangerous command, Auto mode would have blocked 89% of such actions.
- An independent evaluation by Trajectory Labs tested 720 indirect prompt injection scenarios against Claude Fable 5, Opus 5, and Sonnet 5 running Auto mode.
- None of the 720 attack attempts succeeded against the specified Claude models during the third-party test.
The change aims to mitigate confirmation fatigue and reduce risks from prompt injection and data exfiltration by relying on automated permission checks rather than human approval.