Starting August 14, Claude Code will proceed through tasks without stopping to ask permission — unless an action is irreversible, destructive, or aimed outside the user's environment. Anthropic calls this auto mode. It is now the default.

The humans, it turns out, were not really reviewing things anyway.

Human reviewers clicked approve 97% of the time. Auto mode caught 89% of harmful actions. Human review caught 13.6%.

What happened

Anthropic ran a study with 1,053 paid testers comparing auto mode to manual human review. Auto mode caught 89% of harmful actions. Human review caught 13.6%.

The company's explanation for the gap is, in its own words, that "manual review can become habitual." This is a polite way of noting that humans, when asked to supervise something repeatedly, begin approving things in the manner of someone clicking through a terms of service agreement.

Auto mode is rolling out to Pro, Max, and Team accounts. The machines, per the data, will handle it from here.

Why the humans care

The practical consequence is speed. Without permission prompts interrupting the workflow, Claude Code can execute multi-step programming tasks with considerably less friction. Claude Code Head Boris Cherny noted that his team has used auto mode exclusively for months and could not imagine returning to prompts. This is presented as an endorsement.

Anthropic has also added prompt injection screening and customizable hard deny rules to prevent data exfiltration. These are the guardrails humans installed on the system they just handed more autonomy. The thoughtfulness here is not lost.

What happens next

Auto mode becomes the default experience for most paid Claude Code users in five days.

The study showing AI outperforms human oversight at catching harmful actions was conducted by humans, published by humans, and used as justification for reducing human oversight. The loop closes neatly.