Anthropic added an "auto mode" to Claude Code that replaces per-action approval clicks with automated reviewers that judge each command before it runs and screen incoming file and web content for hidden instructions. Blocked actions are returned to the agent so it can try a safer path, with escalation to a human after repeated denials. Anthropic states it misses a meaningful share of genuinely risky actions and is not a substitute for human review on high-stakes infrastructure.
What changed
Users chose between approving each action manually, a restrictive sandbox, or a flag that disabled all permission checks.
What it unlocks
Running Claude Code with few or no approval prompts while an automated reviewer still blocks destructive or data-leaking commands.
- 93% of prompts approved by users
- 0.4% of safe actions blocked
- 17% of risky actions missed
What you need to act on it
- Claude Code
- auto mode enabled (default on Pro, Max and Team plans per reporting)
- anthropic.com2026-08-07