Skip to content
Models · Aug 9, 2026

Auto mode becomes default in Claude Code for Pro, Max, and Team plans

Anthropic sets auto mode as the default for new Claude Code sessions starting August 14, citing internal and third-party evaluations showing strong safety performance against harmful actions and prompt injection.

Trust78
HypeLow hype

2 sources · cross-referenced

ShareXLinkedInEmail
TL;DR
  • Auto mode will be the default setting for new Claude Code sessions in Pro, Max, and Team plans beginning August 14, 2026.
  • Anthropic cites internal tests showing auto mode would have blocked 89% of harmful actions that 1,053 paid testers approved.
  • A third-party evaluation by Trajectory Labs found no successful indirect prompt injection attacks across 720 attempts against Claude Fable 5, Opus 5, or Sonnet 5 running auto mode.

Anthropic will make auto mode the default setting for new sessions in Claude Code’s Pro, Max, and Team plans starting August 14, 2026, according to an announcement covered by Simon Willison. The company describes this change as a reflection of its confidence in auto mode’s safety and reliability.

Anthropic shared internal evaluation results involving 1,053 paid testers, where a harmful action was substituted for a permission prompt mid-session. Only 13.6% of human participants refused the harmful action, whereas auto mode would have blocked 89% of those actions. Anthropic states that this demonstrates lower risk compared to average human reviewers for categories such as prompt injection and data exfiltration.

A third-party evaluation commissioned by Anthropic and conducted by Trajectory Labs tested indirect prompt injection scenarios using the latest publicly available versions of Claude Code and Codex as of July 17, 2026. Across 72 scenarios and 720 attack attempts, none succeeded against Claude Fable 5, Opus 5, or Sonnet 5 running auto mode.

Simon Willison notes that while these results are promising, residual risks remain, including scenarios involving malicious third-party packages that could exfiltrate data. He emphasizes the need for further independent confirmation and stronger agent isolation practices to mitigate potential harms.

Sources
  1. 01Simon Willison — everythingAuto mode is now the default in Claude Code for Pro, Max, and Team plans
  2. 02AnthropicAuto mode is now the default in Claude Code for Pro, Max, and Team plans
Also on Models

Stories may contain errors. Dispatch is assembled with AI assistance and curated by human editors; despite the trust-score filter, mistakes happen. We correct publicly — every article links to its revision history. Nothing here is financial, legal, or medical advice. Verify before relying on any claim.

© 2026 Dispatch. No ads. No sponsorships. No paid placement. Reader-supported via Ko-fi.

Built by a person who cares about honest AI news.