Skip to content

Build1 publisher3 min readPublished

Claude Code now opens in auto mode: a classifier, not you, approves the shell commands

New Pro, Max and Team sessions default to auto mode from August 14, routing each file write and shell command past a classifier model instead of the developer.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • Starting August 14, new Claude Code sessions on the Pro, Max and Team plans open in auto mode by default, per Anthropic's own announcement as reported by AI Dev Weekly.
  • Instead of the user approving every file write or shell command, each tool call now routes through a separate classifier model that decides whether the action is safe to run without asking.
  • The auto-mode default applies to Pro, Max and Team plans; Enterprise, the Claude API and cloud-partner deployments (Bedrock, Vertex, Foundry) stay opt-in for now.
  • Users who had already set a different permission default keep that choice; they receive a one-time prompt asking whether to switch, and the setting is not overridden silently.
  • In Anthropic's own controlled study, human reviewers manually approving each action missed 143 of 1,053 planted dangerous commands.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

New Claude Code sessions on the Pro, Max and Team plans now open in auto mode by default, as of August 14, according to the AI Dev Weekly writeup of Anthropic's own announcement [1]. In that mode, each tool call goes to a separate classifier model that decides whether a file write or shell command is safe to run without asking you, rather than surfacing every one for approval [2]. The approval gate has moved from a person to a model, and it moved without anyone on the affected plans filing a change request.

The scope is the interesting part. Enterprise, the Claude API and the cloud-partner deployments on Bedrock, Vertex and Foundry stay opt-in for now [3]. That is exactly backwards from where the review discipline usually lives: the tiers most likely to have a written policy about who may run `rm` against a repo are the ones left alone, while individual developers and small teams, who typically have no such policy, get flipped by default. If you had already chosen a different permission default, it is preserved, and you get a one-time prompt asking whether you want to switch instead of a silent override [4].

The justification is a controlled study run by Anthropic. Human reviewers manually approving each action missed 143 of 1,053 planted dangerous commands [5]; the classifier caught 937 of them, per reporting on that study via implicator.ai [6]. Do the subtraction and the humans caught 910, or 86.4 percent [9], against the classifier's 89.0 percent [10]. The classifier's edge is 27 commands, about 2.6 percentage points [11]. Its miss rate is 116 out of 1,053, or 11.0 percent [12].

Two things follow. First, this is Anthropic's study of Anthropic's classifier, and the AI Dev Weekly author, who uses the tools daily, says it is worth independent validation before "937 out of 1,053" is treated as settled [7]. Second, and more useful for anyone writing a control narrative: the human baseline in that study is a person clicking approve on every prompt in sequence [5]. Rubber-stamping 1,053 dialogs is not a code review, and beating it by 27 commands is a weaker claim than the framing suggests. An 11 percent miss rate on deliberately planted dangerous commands is the number to put in front of whoever signed off on your tooling policy [12].

The immediate work is inventory, not opinion. Run `/permissions` to see which mode a session is actually in [8], and decide the default deliberately rather than inheriting it. Anyone who documented "developer approves each write" as a control needs to check whether that sentence is still true on Pro, Max and Team seats [1][2].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories