Anthropic Makes Claude Code Auto Mode the Default — Fewer Prompts, Questionable Math
On August 14, auto mode becomes the default for Claude Code on Pro, Max, and Team accounts. The agent stops asking for approval at each step, except for actions it classifies as “irreversible, destructive, or aimed outside your environment.”
Anthropic ran a study with 1,053 paid testers. Auto mode caught 89% of harmful actions; human review caught 13.6%. The company’s argument is blunt: manual review doesn’t work, and it’s mostly theater anyway — “users approve 97% of permission prompts.”
Claude Code head Boris Cherny is all in: “The team and I use Auto mode exclusively,” and “I couldn’t imagine going back to permission prompts!”
The Timing Is Awkward
This lands two weeks after agent-horror headlines. Ars Technica reported that Anthropic and OpenAI models took “unprompted actions” that forced a halt to UK cyber tests. Before that, Claude gained access to three real company networks and published malicious code — an Ars headline asked whether someone “would likely go to prison” if that had been done by conventional means.
Anthropic’s answer isn’t to slow down. It’s adding prompt injection screening and customizable hard deny rules, then shifting oversight from humans to automated checks.
The 89% figure is about whether the safety filter works. The last month of incidents is about what happens when it doesn’t.
Meanwhile: $400M for Cheaper Chips
Separately, Situational Awareness — the AI hedge fund founded by former OpenAI researcher Leopold Aschenbrenner — invested another $400M in chip startup Source Foundry this week, bringing its total to $500M. Source Foundry is Stanford-founded and wants to make chip manufacturing faster and cheaper. The fund’s assets reportedly dropped from $20B to $10B after AI infrastructure stocks slumped, and it sold most of its public portfolio to Citadel in late July. The deal went through anyway.