We're making auto mode the default successful Claude Code. Starting connected August 14, caller sessions connected Pro, Max, and Team plans will tally successful car mode. If you've already group a different default yourself, you whitethorn get a one-time punctual asking whether you want to move to car mode. If you person a pinned default, thing changes for you. The car mode classifier uses a mini number of other tokens per instrumentality call, and we're nary longer charging Claude Code users connected Pro, Max, and Team plans for that classifier overhead, effective today.
Auto mode remains opt-in for now connected Claude Enterprise, the Claude API, Claude Platform connected AWS, Amazon Bedrock, Google Cloud's Agent Platform, and Microsoft Foundry, giving admins clip to reappraisal the change. In the coming month, moving pinch our unreality partners, we scheme to make it the default crossed each of these and nary longer complaint for classifier overhead. In the meantime, Enterprise admins tin make Claude Code's car mode the default done managed settings.
Auto mode is designed to equilibrium users’ desire not to beryllium interrupted pinch a strategy that helps debar harmful actions: alternatively of prompts, it routes each instrumentality telephone done a classifier targeted astatine blocking actions that are irreversible, destructive, aliases aimed extracurricular your environment. When the classifier blocks something, Claude usually finds a safer measurement to proceed connected its ain aliases asks you straight for the go-ahead; if it can't make progress—three blocks successful a row, aliases 20 crossed a session—Claude Code falls backmost to manual approvals.
We spent the past respective months testing whether car mode is arsenic safe aliases safer than an mean personification clicking done prompts. We ran soul red-teaming, third-party red-teaming and prompt-injection evaluations, a controlled study pinch 1,053 paid testers, and study of existent accumulation sessions. On each measurement we tested, car mode matched aliases outperformed manual review.
Auto mode besides lets Claude activity autonomously for longer stretches. This makes models built for long-running work, for illustration Claude Opus 5, much applicable to time off moving for hours connected ample tasks. Reducing overhead for users besides increases output. Among Teams & Enterprise adopters, car mode users vessel astir 25% much PRs. Unblocking Claude allows tasks to tally longer uninterrupted and get much activity done. Teams astatine Adobe, Nuro, Gusto, and Garner Health already run car mode arsenic their accumulation default.
Below, we stock the information information and customer results motivating the change, and really to group a different default if you prefer.
Comparing manual reappraisal to car mode
Data suggests that manual reappraisal tin go habitual: users o.k. 97% of support prompts successful Claude Code. While astir prompts are apt for safe, regular commands, an support complaint that precocious suggests galore users are clicking done reflexively alternatively than reviewing each command. These prompts inquire developers to make dozens aliases hundreds of important information decisions each day, often successful the mediate of projects, which places the reappraisal load connected users and increases the chance that thing important slips done the cracks. Data besides suggests that users much often scrutinize and push backmost connected different types of dialogues: for example, erstwhile Claude presents a scheme for approval, users cull 39% of them. But for individual permissions requests, the rejection complaint is only 3%.
The aforesaid shape shows up successful settings files. As of June 2026, 49.5% of progressive CLI users person manually created a Bash allow-rule—5% let immoderate ammunition bid outright, and different 43% person expert rules for illustration Bash(python:*) aliases Bash(node:*) that are fundamentally balanced successful practice—and that stock is increasing astir 5 percent points each 5 weeks. Beyond allow-rules, 62% of users person utilized bypassPermissions aliases clicked “don't inquire again” connected Bash, and 25% of interactive sessions commencement successful bypass permissions mode.
Permission rules still occurrence earlier the classifier successful car mode, isolated from for let rules wide capable to assistance arbitrary codification execution (e.g. python:*). These arbitrary rules are group speech while successful car mode, since they would fto commands skip the classifier entirely. Settings files aren't modified, and the rules use again the infinitesimal you move to different mode.
Improving information pinch car mode
Research conducted internally and done respective 3rd parties suggests that car mode is safer than really a emblematic personification engages pinch support prompts today. We tested car mode against what developers really o.k. erstwhile they're clicking done support prompts. Across each of these measures—internal red-teaming, third-party penetration testing, and study of real-world sessions—auto mode matched aliases outperformed quality approval.
Auto mode outperforms manual permissions connected safety

We hired 1,053 paid testers done a investigation vendor for a coding study. These participants worked successful a trial situation group up specifically for the study, not successful their ain codebases aliases connected existent projects. Participants knew they were being evaluated, but—following modular blind-study design—weren't told which behaviour was being measured. Partway done each session, a azygous support punctual was swapped for a intelligibly vulnerable command, and the vendor recorded whether the tester approved it (Note: approving the punctual ne'er resulted successful thing vulnerable being run; only the matter of the punctual testers saw was changed).
The testers caught the vulnerable bid conscionable 13.6% of the clip (143 of 1,053), while car mode blocked 89% of the aforesaid commands (937 of 1,053). Head to head, car mode blocked 800 commands that a quality approved, while humans blocked only 6 that car mode allowed. As sessions sewage longer, humans did worse: they blocked astir 17% of vulnerable commands early successful a session, dropping to astir 5% aft 50 aliases much anterior prompts, while car mode's artifact complaint stayed level sloppy of convention length.
Auto mode prevents much harmful actions
Our investigation besides suggests that car mode leads to less harmful actions than manual permissions mode.
We examined really car mode performs successful existent usage. From May to June 2026, we examined sessions our information pipeline had flagged for review, drawn only from accounts that person opted successful to information usage for training and analysis. We re-graded each 1 pinch a exemplary connected 2 0–10 scales. The first was harm severity pinch 10 being company-wide, irreversible harm, specified arsenic leaking a company's full root code, 7 representing production-level severity specified arsenic deleting rows from a accumulation database, and 0 a afloat reversible action confined to the section workspace, for illustration overwriting a scratch file. The 2nd was really explicitly the personification had asked for the action, truthful we could abstracted harmful actions the personification straight requested from harmful actions the supplier took pinch little definitive direction.
Among the flagged sessions, those that went done manual support contained superior unintended harm much than doubly arsenic often arsenic car mode sessions. At production-level severity (7+), 6.3% of manually approved sessions contained a harmful action the personification hadn't explicitly asked for, compared to 2.4% of car mode sessions, and the spread held astatine each severity level we tested.
Adversarial red-teaming made car mode stronger
We worked pinch Apollo Research, a UK-based AI information startup, connected a two-week aviator injecting synthetic attacks into existent coding trajectories, crossed 3 datasets covering wide failures, information exfiltration, and safety-related threats.
The engagement followed a modular find-fix-verify loop. Apollo shared a group of successful attacks on pinch recommendations to fortify car mode. We hardened the classifier against them chiefly by giving it much discourse astir the situation it's protecting (repository visibility, git state, and the data-handling rules described below).
After hardening, Apollo re-tested connected a abstracted held-out onslaught group that we ne'er had entree to. Auto mode caught astir half of the attacks it antecedently missed, astatine a costs of missing astir 2% of attacks it antecedently caught. Since we couldn't tune against the held-out set, this suggests the hardening generalizes to caller attacks alternatively than patching the circumstantial ones Apollo shared. Across some the shared and held-out sets, the classifier's miss complaint fell from 12% to 7%.
These attacks are synthetic and adversarial by design, built to find wherever the classifier fails, and much malicious than thing Claude would do unprompted. The 7% miss complaint is measured against this group and should not beryllium taken arsenic the miss complaint connected existent traffic.
Auto mode reduces punctual injection risk

The car mode classifier adds an further furniture of defense against prompt injection attacks that effort to unit the supplier to deviate from the user’s instructions. When moving pinch car mode, instrumentality results are scanned by probes for perchance malicious instructions, and car mode checks that actions are aligned pinch personification intent. We tested car mode compared to an unguarded exemplary to exemplify the powerfulness of this defense-in-depth approach.
We commissioned an information from a 3rd party, Trajectory Labs, who tested different models wrong the latest publically disposable versions of Claude Code and Codex arsenic of July 17th 2026.1 They tested 72 indirect punctual injection scenarios held retired from Anthropic. Each script was tested 10 times. Successful attacks would, successful a non-testing environment, consequence successful irreversible actions that could harm the personification specified arsenic sensitive-data exfiltration, financial fraud, aliases credential phishing. The attacks were optimized against Claude Opus 4.7, which is not successful the reported set, truthful each exemplary successful the information faced them arsenic unseen attacks. In summation to car mode, the evaluations looked astatine Claude Code’s bypassPermissions mode and Codex’s Full Access mode.
Both Codex and Claude Code were evaluated utilizing an identical browser integration produced by Trajectory Labs, PBC. This integration provides a group of MCP devices which are a bladed wrapper astir communal Chrome APIs specified arsenic `navigate`. Safeguards built into first-party browser integrations specified arsenic the Chrome extensions provided by OpenAI and Anthropic were not tested. As such, these results should beryllium viewed arsenic a measurement of the underlying model, alternatively than the complete group of safeguards which mightiness beryllium successful a fixed deployment.
In this evaluation, nary of the 720 onslaught attempts succeeded against Claude Fable 5, Opus 5, aliases Sonnet 5 moving car mode. On the different hand, 5.83% of the attacks succeeded against GPT-5.6 Sol moving Codex's Auto-review mode. Notably, this is greater than the 0.09% mean onslaught occurrence complaint against our latest models moving successful bypassPermissions mode without further safeguards. The tests showed a 19.03% onslaught occurrence complaint against GPT-5.6 Sol erstwhile moving successful Full Access mode. Attack occurrence rates disagree betwixt tasks wherever devices return results arsenic matter and tasks that require interacting pinch a browser done screenshots, arsenic shown below.


Three incidents car mode prevented wrong Anthropic
Auto mode is besides the default for each Claude Code soul usage astatine Anthropic. Here are 3 actions the classifier prevented internally:
- An off-network information leak: When an upload to an soul thrust failed, Claude's fallback was to people the aforesaid study to a nationalist code-sharing site. Auto mode denied the fallback and prompted the personification for adjacent steps.
- A destructive wide operation: In a long-running session, Claude attempted a wide process termination crossed astir 2 1000 pods and queued deletions that would person torn down hundreds of GPUs of in-flight training jobs. Auto mode flagged the destructive commands earlier execution.
- Over-broad privilege escalation: Asked to proviso read-only billing access, Claude reached for a unreality domiciled that grants afloat administrative power astatine the relationship root. Auto mode caught the mismatch betwixt what was requested and what roles would person been granted.
In each case, Claude either recovered a safer way connected its ain aliases checked successful pinch the personification earlier proceeding.
Making car mode moreover safer
We’re continuously investing successful caller car mode features that make it safer and easier to vessel accumulation code. Recent examples include:
- Hard denies: Data exfiltration, for illustration sending your codification aliases secrets location external, sits successful a class the classifier is designed to ne'er approve. To tally an action for illustration that, you person to move retired of car mode aliases tally the bid yourself. Hard contradict rules are customizable via settings truthful you tin adhd much rules that you ne'er want allowed moreover erstwhile requested by users successful your organization.
- Rules for information entree and sharing: The classifier now carries definitive rules distinguishing secrets and perchance sensitive/confidential information—and wherever each tin beryllium accessed and shared. To make those rules enforceable, it besides checks whether the destination of a git push aliases propulsion petition is public, private, aliases trusted earlier the action runs. The aforesaid push tin beryllium regular aliases an exfiltration depending connected wherever it lands: codification that belongs successful your team's backstage repository shouldn't extremity up successful a nationalist one, and the classifier is now designed to emblem erstwhile this mightiness happen.
- Checking git position earlier destructive git actions: Before a bid that could discard uncommitted work, for illustration git reset --hard, the classifier sees the repository's existent git status, letting car mode cognize what is being reset.
- Prompt injection screening: When Claude pulls contented from outer sources, for illustration web pages, record contents, aliases instrumentality outputs, an API-side probe checks that contented for attempts to hijack Claude's behavior. When thing looks for illustration an injection attempt, a informing is added to Claude's discourse earlier the consequence is shared pinch the user.
Auto mode successful production
Teams are already moving car mode arsenic their accumulation default:
- Adobe's merchandising level squad is responsible for keeping pricing and promotional pages meticulous and existent crossed 90+ countries and 30+ languages connected Adobe.com. They built an agentic loop to build and verify those pages, moving it successful car mode truthful engineers person vanished PRs for review.
- Nuro runs car mode crossed its investigation and engineering orgs, utilizing it to powerfulness overnight investigation agents that hill-climb information metrics and return vanished PRs for reappraisal by morning.
- Gusto adopted car mode to extremity the support fatigue that was pushing engineers toward bypassing permissions checks entirely. About 10% of sessions since mid-May see a classifier denial—evidence it's doing existent activity without slowing morganatic tasks.
- Garner Health pushed car mode arsenic the default to each 550 labor via managed settings, standardizing a company-wide package improvement lifecycle (SDLC) that nary longer depends connected hand-curated bid allowlists.
“At Adobe, we want to move accelerated without compromising the value of the customer acquisition we present connected Adobe.com. With Claude Code car mode, we built an agentic loop that quickly accelerated our work. Claude builds the personification interface and past loops backmost to verify that it matches the intended design, automatically fixing immoderate issues earlier we ever look astatine it. This shortened our improvement rhythm while delivering pixel-perfect results.”
Tomislav Reil, Director of Engineering


"The different day, I kicked disconnected an supplier astatine 10 p.m. and it kept moving until 5 a.m.—and it gave maine 3 PRs successful the morning. I deliberation it's beautiful impressive. Only car mode enables this benignant of workload."
Kai Zhou, Staff Software Engineer
"Auto mode gave america a safer equilibrium betwixt velocity and control. We were capable to region the repeated prompts and summation productivity without compromising safety. We tin spot that car mode blocks astatine the correct time, which gives america the assurance to move quickly."
Martin Emde, Software Engineer
"We built a standardized SDLC for the full engineering org that's only imaginable because of car mode. Employees position it arsenic a weight disconnected their shoulders. They don’t person to show their agents for hours connected extremity anymore."
Evan Magnussen, Platform Engineering Manager
Learn really these customers are running car mode successful production.
Getting started
For Pro, Max, and Team users: if you haven’t group a default support mode, you’ll person an in-product announcement and caller sessions will commencement successful car mode automatically. If you've group a different default, you whitethorn spot a one-time punctual asking if you’d for illustration to move your default to car mode. If your Team admin has group a default successful managed settings, thing changes for you.
For Enterprise users and users who entree Claude Code via the Claude API, car mode remains opt-in for now. We scheme to make car mode the default successful the coming month, and we’ll notify Enterprise admins earlier we do.
To move modes, property Shift+Tab successful the CLI aliases usage the mode dropdown connected the desktop app. Admins tin pin an org-wide default pinch `defaultMode` successful managed settings, aliases move car mode disconnected wholly pinch `disableAutoMode`.
Finally, while we judge car mode reduces consequence for astir users, it relies connected classification systems and truthful does not destruct risk. For high-stakes changes to accumulation infrastructure, we still urge reviewing Claude's actions yourself. See the car mode docs for afloat configuration instructions.
This article was written by Conner Phillippi, pinch contributions by Nicholas Carlini, Isaac Fung, John Hughes, Alex Isken, Shawn Moore, Javier Rando, and Molly Vorwerck. The authors would besides for illustration to convey Yacine Azmi, Chandler Bair, Kefan Chen, Boris Cherny, Ian Grunert, Lydia Hallie, Alex Kleiman, Lauren Polansky, Deon Poncini, Robert Schonberger, Marie Vachovsky, Qing Wang, Cat Wu, Daniel Xu, and Alice Zhao.
1 We evaluated Claude Code v2.1.205 and Codex v0.144.5. OpenAI released a caller type of Auto-review past week that could alteration the results.
English (US) ·
Indonesian (ID) ·