AIToday
AI Coding AssistantsAI Safety & AlignmentSimon Willison's WeblogPublished: Aug 9, 2026, 10:00 JST

Claude Code auto mode now default for Pro, Max, Team plans

Claude Code auto mode now default for Pro, Max, Team plans

3 Key Points

  1. What happened

    Anthropic is making auto mode the default setting for new Claude Code sessions starting August 14th across Pro, Max, and Team plans. The company commissioned an evaluation from Trajectory Labs testing prompt injection attacks, reporting that none of 720 attack attempts succeeded against Claude Fable 5, Opus 5, or Sonnet 5 running auto mode.

  2. Why it matters

    Auto mode automatically approves or blocks code actions without requiring manual confirmation at each step. In Anthropic's test of 1,053 paid testers, when a harmless permission prompt was swapped for a dangerous command, only 13.6% of humans refused it while auto mode would have blocked 89% of those actions. This suggests auto mode may be more reliable than human judgment, which suffers from confirmation fatigue.

  3. What to watch

    Auto mode still left 11% of potentially harmful actions unblocked in the human test. Independent security researchers have raised concerns about whether auto mode can defend against sophisticated attacks such as malicious third-party packages that hide data exfiltration instructions in seemingly legitimate development workflows.

Not sure about something? Ask the AI

Questions and answers are published on this page.

Summaries like this, in your inbox every morning.

FAQ
When does auto mode become the default?
Auto mode becomes the default setting for new Claude Code sessions starting August 14th for Pro, Max, and Team plans.
What did the safety tests show?
In a test of 1,053 paid testers where a permission prompt was replaced with a dangerous command, only 13.6% of humans refused the harmful action while auto mode would have blocked 89% of those actions. Trajectory Labs also tested 720 indirect prompt injection scenarios against Claude Fable 5, Opus 5, and Sonnet 5 running auto mode, reporting none of the attacks succeeded.
Simon Willison's WeblogRead Original Article

Get the latest AI Coding Assistants news every morning

For example, today's edition would include:

  • Developer builds Jev Bookmarks to start Jev from Chrome historyZenn AI/ML · 8h ago
  • Shoma Endo leans on Claude Code hooks, not rules, for a beginner-built appZenn AI/ML · 8h ago
  • ~/develop umbrella setup puts AI agents at center of devZenn AI/ML · 8h ago

AI-summarized, only the topics you pick: one digest a day via Email, LINE, or Slack.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.

Questions and answers are published on this page.

Related Articles

Next articleTSMC developing Intel-rivaling chip packaging tech, shares rise