aiminute. ← All AI news
Tools 2026-08-10

Anthropic studied 1,053 developers clicking 'approve'. They caught 13.6% of the dangerous commands — so the robot gets the wheel on 14 August

Anthropic studied 1,053 developers clicking 'approve'. They caught 13.6% of the dangerous commands — so the robot gets the wheel on 14 August

From 14 August, Claude Code will run in auto mode by default for anyone on a Pro, Max or Team plan. Auto mode means the coding agent stops asking permission before each file write and each shell command, and instead passes every tool call through a classifier that blocks anything irreversible, destructive or aimed outside your machine. Anthropic published the numbers behind the decision. In a controlled study with 1,053 paying testers, people reviewing prompts by hand spotted 13.6 per cent of the dangerous commands put in front of them; auto mode blocked 89 per cent. In live production sessions, manually approved work contained unintended harmful actions at more than twice the rate of auto mode work — 6.3 per cent against 2.4 per cent. The explanation is in one statistic: developers approve 97 per cent of the prompts they are shown, which is not review, it is clicking. Alongside the switch Anthropic added hard deny rules against data exfiltration, checks on whether a git push is heading to a public or a private repository, git status checks before destructive operations, and screening of external content for prompt injection. Blocked actions send Claude looking for a safer route; enough blocks in a row and the session drops back to asking. The classifier's own token cost is no longer billed on those three plans. Enterprise, the API, Bedrock, Google Cloud and Microsoft Foundry stay opt-in for now, with Anthropic saying it expects to make auto mode the default there within a month.

Why it mattersThe interesting part is not that a company shipped a more autonomous default. It is the argument used to justify it, which inverts the usual one. Permission prompts were meant to keep a human in the loop; Anthropic's own telemetry says the human in the loop is a rubber stamp, and that a machine reading the same commands is roughly six times better at catching the bad ones. That reasoning generalises well beyond one product — every consent dialog, every 'are you sure?', every approval queue in software rests on the assumption that being asked makes you look. If you use Claude Code on a paid plan, the practical matter is that your default changes on 14 August whether or not you read the announcement, and you should decide now rather than discover it later: you can pin a different permission mode, and administrators can pin one for a whole team. The honest caveat is that 89 per cent is not 100, and the failures are now silent. Under the old default a mistake needed you to click through it. Under the new one it needs nobody at all.
#Coding#AI Agents

✓ Verified · 4 sources

▶ Related video: How auto mode works with Claude Code
WhatsApp X Telegram
Read in the app — free, in 9 languages

Related stories

Apple Music will tell you when a song was made by a machine — but the uploader decides whether to say so
2026-08-21
Rumour: the anonymous model that just topped a coding benchmark, for free, is said to be Zhipu's unreleased flagship
2026-08-21
DeepSeek's cheap workhorse can now see — and on agent tasks that need eyes it says it is close to Anthropic's best
2026-08-21
Nvidia is paying $6 billion for the machine that builds a rival's models — and hiring 109 of the people who ran it
2026-08-21
Stripe has just paid $7.5 billion for a model router. Days later Ramp built one and is giving it away until January.
2026-08-21