Build1 publisher3 min readPublished
Claude Code's new default is a confession: the approval prompt was never a control
Anthropic's own study found users approved 97% of prompts and caught 13.6% of harmful actions. From August 14 the click stops being the safeguard, and deny rules become the job.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- On August 14, 2026, auto mode becomes the default permission mode for new Claude Code sessions on Pro, Max and Team plans.
- In auto mode the agent stops asking before each step and simply proceeds, unless the action it wants to take is judged irreversible, destructive, or aimed outside the user's environment.
- In a 1,053-action study by Anthropic, auto mode blocked 89% of harmful actions while humans clicking through approval prompts caught 13.6%.
- In the same testing, users habitually approved 97% of the prompts they were shown.
- A 97% approval rate means the prompt was declined about 3% of the time.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
On August 14, 2026, auto mode becomes the default permission mode for new Claude Code sessions on the Pro, Max and Team plans, meaning the agent proceeds without asking unless it judges an action irreversible, destructive, or aimed outside your environment [1][2]. The justification Anthropic published is also an admission about the control it is replacing: in a 1,053-action study, auto mode blocked 89% of harmful actions while humans clicking through approval prompts caught 13.6%, because users habitually approved 97% of the prompts they were shown [3][4].
Read that second number as an engineering finding rather than a scolding. A control that is exercised correctly 3% of the time is not a control [5]. Anthropic's term for it is permission fatigue, and its argument is that a model checking each action against a policy beats a human who has stopped reading [6]. If you have run a coding agent for a week, you have felt the prompt turn from a decision into a keystroke [7].
Three narrower facts survive the framing. The flip applies only to new sessions; existing sessions keep the mode they are running in [8]. Auto mode is not approve-everything: deleting data, force-pushing over history, and reaching for a remote system you did not point the agent at still surface a prompt [2][9]. And the rollout ships two controls that matter more than the default, prompt-injection screening on incoming content and hard deny rules you configure so certain actions can never be taken regardless of what the model concludes [10].
The deny rules are the only item on that list whose behaviour does not depend on a model's judgement [11]. That distinction earns its keep once you do the subtraction. Blocking 89% of harmful actions leaves 11% unblocked [12], which is a good trade against 13.6% on any single action [3] but is not a rounding error across a long-running session that takes hundreds of actions, a point independent commentary raised immediately [13].
The injection result is stronger and worth quoting precisely: none of 720 attack attempts succeeded against Claude Fable 5, Opus 5, or Sonnet 5 running auto mode [14]. It is also a result against a fixed attack set, which is a narrower claim than prompt injection being solved [15]. It matters here because the two most widely reported attacks on coding agents in the past year both arrived through content the agent read rather than code the user wrote: text inside a GitHub issue that steered Claude Code and Gemini CLI into actions their operator never asked for, and a compromised npm package in the dependency chain that reached developer machines through the editor [16][17][18]. In both, the last thing between the agent and the damage was a human deciding whether a prompt made sense [19].
So the work moves from the click to the policy layer. Pick the default per surface, since a laptop holding production credentials and a scratch container running throwaway branches do not deserve the same one [20]. Write static deny rules for credential files and secret stores, anything that pushes to a remote or a package registry, network calls outside your allowlist, and deletion outside the working tree [21]. Scope what the agent can reach, not only what it can do, because screening reduces the odds and scoping reduces the damage [22].
Watch the managed settings path if you run a team: administrators can set a different default or disable auto mode centrally, and that is the only lever that applies before Thursday rather than after an incident [23].