Build1 distinct publisher3 min readUpdated
New Pro, Max and Team sessions default to auto mode from August 14, routing each file write and shell command past a classifier model instead of the developer.
The Engineer · Build desk
Compiled by The EngineerSomething wrong?How this is made
New Claude Code sessions on the Pro, Max and Team plans now open in auto mode by default, as of August 14, according to the AI Dev Weekly writeup of Anthropic's own announcement [1]. In that mode, each tool call goes to a separate classifier model that decides whether a file write or shell command is safe to run without asking you, rather than surfacing every one for approval [2]. The approval gate has moved from a person to a model, and it moved without anyone on the affected plans filing a change request.
The scope is the interesting part. Enterprise, the Claude API and the cloud-partner deployments on Bedrock, Vertex and Foundry stay opt-in for now [3]. That is exactly backwards from where the review discipline usually lives: the tiers most likely to have a written policy about who may run `rm` against a repo are the ones left alone, while individual developers and small teams, who typically have no such policy, get flipped by default. If you had already chosen a different permission default, it is preserved, and you get a one-time prompt asking whether you want to switch instead of a silent override [4].
The justification is a controlled study run by Anthropic. Human reviewers manually approving each action missed 143 of 1,053 planted dangerous commands [5]; the classifier caught 937 of them, per reporting on that study via implicator.ai [6]. Do the subtraction and the humans caught 910, or 86.4 percent [9], against the classifier's 89.0 percent [10]. The classifier's edge is 27 commands, about 2.6 percentage points [11]. Its miss rate is 116 out of 1,053, or 11.0 percent [12].
Two things follow. First, this is Anthropic's study of Anthropic's classifier, and the AI Dev Weekly author, who uses the tools daily, says it is worth independent validation before "937 out of 1,053" is treated as settled [7]. Second, and more useful for anyone writing a control narrative: the human baseline in that study is a person clicking approve on every prompt in sequence [5]. Rubber-stamping 1,053 dialogs is not a code review, and beating it by 27 commands is a weaker claim than the framing suggests. An 11 percent miss rate on deliberately planted dangerous commands is the number to put in front of whoever signed off on your tooling policy [12].
The immediate work is inventory, not opinion. Run `/permissions` to see which mode a session is actually in [8], and decide the default deliberately rather than inheriting it. Anyone who documented "developer approves each write" as a control needs to check whether that sentence is still true on Pro, Max and Team seats [1][2].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Starting August 14, new Claude Code sessions on the Pro, Max and Team plans open in auto mode by default, per Anthropic's own announcement as reported by AI Dev Weekly.
Instead of the user approving every file write or shell command, each tool call now routes through a separate classifier model that decides whether the action is safe to run without asking.
The auto-mode default applies to Pro, Max and Team plans; Enterprise, the Claude API and cloud-partner deployments (Bedrock, Vertex, Foundry) stay opt-in for now.
Users who had already set a different permission default keep that choice; they receive a one-time prompt asking whether to switch, and the setting is not overridden silently.
In Anthropic's own controlled study, human reviewers manually approving each action missed 143 of 1,053 planted dangerous commands.
The classifier caught 937 of the 1,053 planted dangerous commands, per reporting on Anthropic's study via implicator.ai.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single publisher relaying a vendor-run study
The behavioral facts (default flip, plan scope, preserved settings, /permissions) are specific and internally consistent, but the entire safety case is one Anthropic study of Anthropic's own classifier, reached second-hand via another outlet, with no methodology, false-positive rate or independent replication in the supplied material.
Default-on for paid consumer tiers, scale undisclosed
Adoption is not voluntary uptake but a shipped default change reaching every new session on Pro, Max and Team, which is a real deployment signal; however no user counts, session volumes or post-change usage or incident data are disclosed, and the enterprise and API surfaces are explicitly untouched.
Modest margin carrying a large framing
The 'classifier beats humans' result is a 27-command, roughly 2.6-point difference in a single vendor-run test, and the classifier still missed 116 of 1,053 dangerous commands -- a thinner basis than a default-on permission change implies. The overstatement is mild rather than severe because the sole source itself foregrounds the vendor-study caveat and the missing independent validation.
Vendor measuring its own guardrail
The safety evidence is produced by the party shipping the default, and the change removes friction from the vendor's own agentic product; the cluster contains no independent measurement to offset that. The disclosing source is a developer newsletter that names the attribution chain and links its own guides, a mild promotional interest relative to the vendor's.
One publisher, second-hand numbers
Product-behavior claims are unambiguous and easy to verify in-product, so the story's core is likely sound; but a single publisher, second-hand safety statistics and no primary vendor document or independent corroboration in the cluster cap confidence in the quantitative and safety-effectiveness portions.
build
A session that read "finished" and "still executing" was a slow queue, not a dropped handshake1 distinct publisher
leadership
Slack Code makes the chat window a coding surface, and a platform call for engineering leaders1 distinct publisher
invest
Three Claude agents, one task, and a malware turf war: the multi-agent bill arrives1 distinct publisher
build
Anthropic's CCAR-F puts a scaled score on "can build agents"1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
dev.to
1 article · August 20, 2026