Anthropic announced that Claude Code's automatic mode will become the default for new sessions in the Pro, Max and Team plans starting August 14. The company says the decision aims to reduce security failures caused by repetitive human approval of commands.
According to data released by the company, a study with 1,053 paid developers showed that only 13.6% of participants refused a clearly dangerous action when it was presented in the middle of a session. In the same scenario, automatic mode would block 89% of harmful actions.
Anthropic also commissioned an independent evaluation from Trajectory Labs, which applied 720 indirect prompt-injection attacks to models used in Claude Code and Codex, based on the public versions of July 17. According to the company, none of the attempts succeeded against the Claude Fable 5, Opus 5 and Sonnet 5 models running in automatic mode.
Executive Cat Wu said during an event last month that the risks of attacks such as prompt injection and data exfiltration are 'much lower than those of an average human reviewer.' Meanwhile, Thariq Shihipar said that almost all Anthropic employees use automatic mode.
Independent skepticism
Developer Simon Willison, who published an article on the subject, said he wants to see independent confirmation of the performance. He cited the case of a malicious package that instructs the agent to download files and execute commands, which could exfiltrate data. 'I don't know how any version of automatic mode could protect against that kind of action,' he said.



