Auto mode becomes default in Claude Code for Pro, Max, and Team plans
Anthropic sets auto mode as the default for new Claude Code sessions starting August 14, citing internal and third-party evaluations showing strong safety performance against harmful actions and prompt injection.
2 sources · cross-referenced
- Auto mode will be the default setting for new Claude Code sessions in Pro, Max, and Team plans beginning August 14, 2026.
- Anthropic cites internal tests showing auto mode would have blocked 89% of harmful actions that 1,053 paid testers approved.
- A third-party evaluation by Trajectory Labs found no successful indirect prompt injection attacks across 720 attempts against Claude Fable 5, Opus 5, or Sonnet 5 running auto mode.
Anthropic will make auto mode the default setting for new sessions in Claude Code’s Pro, Max, and Team plans starting August 14, 2026, according to an announcement covered by Simon Willison. The company describes this change as a reflection of its confidence in auto mode’s safety and reliability.
Anthropic shared internal evaluation results involving 1,053 paid testers, where a harmful action was substituted for a permission prompt mid-session. Only 13.6% of human participants refused the harmful action, whereas auto mode would have blocked 89% of those actions. Anthropic states that this demonstrates lower risk compared to average human reviewers for categories such as prompt injection and data exfiltration.
A third-party evaluation commissioned by Anthropic and conducted by Trajectory Labs tested indirect prompt injection scenarios using the latest publicly available versions of Claude Code and Codex as of July 17, 2026. Across 72 scenarios and 720 attack attempts, none succeeded against Claude Fable 5, Opus 5, or Sonnet 5 running auto mode.
Simon Willison notes that while these results are promising, residual risks remain, including scenarios involving malicious third-party packages that could exfiltrate data. He emphasizes the need for further independent confirmation and stronger agent isolation practices to mitigate potential harms.
- Aug 7, 2026 · Simon Willison’s Weblog
Accenture flags PDF-to-markdown conversion as a major driver of AI token costs
Trust74 - Aug 6, 2026 · Simon Willison — everything
Meta unveils Muse Spark 1.2 with Muse Code co-training and long-horizon coding benchmarks
Trust79 - Aug 6, 2026 · Simon Willison’s Weblog
Claude Fable 5 autonomously builds a browser-based 3D raccoon heist game from a 2022 prompt
Trust84