• Latest
  • Trending
  • All
Answer card: from 14 August 2026 auto mode becomes the default permission mode for new Claude Code sessions on Pro, Max and Team plans, replacing the per action approval prompt with a separate classifier model, with the classifier overhead no longer billed on those three plans while Enterprise and API accounts keep paying.

Claude Code auto mode is the default from August 14

10 August 2026
Answer card stating that Cognition released SWE-2 on 10 September 2026, a coding model post-trained from Kimi K3, scoring 50.0 percent on FrontierCode 1.1 Main against 50.9 percent for Claude Fable 5.1 and 27.3 percent on Terminal-Bench 4 against 55.8 percent, available only inside Devin.

SWE-2 trails Fable 5.1 by one point, and by 28 on Terminal-Bench 4

11 September 2026
Answer card for Meta Muse, free to 100 million tokens a week then $20 a month, launched 8 September 2026 for United States adults only, running in a dedicated per user virtual machine.

Does Meta Muse do enough to earn your inbox and a card on file?

9 September 2026
Answer card stating that the public download pages for the VMware Virtual Disk Development Kit on developer.broadcom.com began returning 404 errors on 25 August 2026 with no announcement or deprecation notice, that Broadcom support tells customers the kit is no longer available for use or download, and that release lines 7.0.3.1, 8.x and 9.x are all affected.

Broadcom pulled VDDK 8.0 and 9.0, and the 404 is the only notice

8 September 2026
Answer card stating that OpenAI published its research acceleration measurements on 6 September 2026, that as of mid August 2026 its research organisation logged 3.1 agent workdays of coding agent runtime for every workday of human labour normalised to a standard eight hour day, and that OpenAI states this should not be read as a 3.1 times productivity gain because it measures runtime rather than delivered output.

OpenAI’s 3.1 agent-workdays per human day is not a 3.1x gain

7 September 2026
Answer card stating that Mullvad announced on 3 September 2026 that it is shutting down its public encrypted domain name system servers on 2 November 2026 and sponsoring the Quad9 Foundation instead, with 194.242.2.2 and its five sibling addresses all going away, and virtual private network customers unaffected.

Mullvad’s DNS servers go dark on 2 November, and Quad9 blocks no ads

5 September 2026
OpenAI announcement image for GPT-6 Astra, a spiral galaxy of white, blue and amber points of light curling around a bright core on a near black star field.

GPT-6 Astra lists at $10 and $50, 2.5x what GPT-5.6 Sol costs

6 September 2026
Google's official announcement image for the release, reading Introducing Gemini 3.8 Flash and 3.8 Flash Cyber in black type over a pale blue background with a blurred white chevron and the four colour Gemini spark below.

Gemini 3.8 Flash keeps the price and the 1 January cliff

3 September 2026
Answer card stating that Anthropic announced Enterprise Frontier Safeguards on 1 September 2026, that activity data used for misuse monitoring moves into cloud storage the customer controls under the customer own encryption keys, that Anthropic charges nothing for the feature while the cloud provider bills storage and egress, and that the phased rollout starts later in autumn 2026 with interim zero data retention on Fable 5 and Fable 5.1 for eligible customers.

Anthropic moves retention into your own cloud, for 30 days

3 September 2026
Official Google diagram of a client connection in three numbered steps: a DNS lookup with a query and an address, a TLS ClientHello and ServerHello, then a content exchange with a website. A callout on the DNS step reads 25% of global web traffic is now protected by encrypted DNS, and a callout beside an Android phone on the ClientHello step reads Android 17 supports ECH GREASE by default.

Android 17 hides the SNI, not your DNS or destination

3 September 2026
Still frame from the Claude Fable 5.1 launch video showing model-designed protein binders in orange docked against twelve grey target proteins, rendered as ESMFold2 structure predictions.

Claude Fable 5.1 breaks forced tool use, cuts cache 75%

1 September 2026
Answer card stating that on 31 August 2026 the European Commission designated ChatGPT a Very Large Online Search Engine under the Digital Services Act, the first conversational AI service classified that way, because it answers user prompts and queries including by searching the web, with OpenAI having declared roughly 159.1 million average monthly users in the European Union for ChatGPT search.

The EU now calls ChatGPT a very large search engine

3 September 2026
Answer card stating that on 31 August 2026 the Department of War added OpenAI ChatGPT Mil and Starshield AI Grok for Government to the GenAI.mil portal alongside Google Gemini, all three accredited at Impact Level 5 for Controlled Unclassified Information, with 1.7 million unique users onboarded out of roughly 3 million eligible personnel, and ChatGPT Mil currently serving GPT-5.4 Terra with GPT-5.6 Terra said to be rolling out.

ChatGPT Mil and Grok reached IL5 on GenAI.mil

3 September 2026
  • About
  • Contact
  • Privacy
  • Legal
Friday, September 11, 2026
  • Login
Packet Nebula
  • Home
  • Articles
    • Security
    • Network
    • Dev
    • Sysadmin
    • SEO
    • Email & DNS
  • Tools
    • Network tools: free, fast, no signup
    • Security tools: free, fast, no signup
    • Developer tools: free, fast, no signup
    • Sysadmin tools: free, fast, no signup
    • SEO tools: free, fast, no signup
    • Email & DNS tools: free, fast, no signup
  • Download
  • About
No Result
View All Result
Packet Nebula
No Result
View All Result
Home Dev

Claude Code auto mode is the default from August 14

by stephane
10 August 2026
in Dev
0
Answer card: from 14 August 2026 auto mode becomes the default permission mode for new Claude Code sessions on Pro, Max and Team plans, replacing the per action approval prompt with a separate classifier model, with the classifier overhead no longer billed on those three plans while Enterprise and API accounts keep paying.
493
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter

You know the rhythm. Claude Code stops, shows you a shell command, waits. You hit yes. You have hit yes forty times today and you quietly stopped reading around the twelfth. That reflex is exactly what Anthropic designed around: from 14 August, auto mode becomes the default permission mode for new Claude Code sessions on Pro, Max and Team plans, so a separate classifier model vets each tool call instead of interrupting you. The announcement went up on 7 August with a study attached, and the stat everyone is repeating says the classifier blocked 89% of planted dangerous commands against 13.6% for the humans. We think the more honest number sits further down that post. There's also a billing change nobody put in a headline.

The short answer

From 14 August, new Claude Code sessions on Pro, Max and Team plans start in auto mode: a classifier model reviews each tool call and blocks anything irreversible, destructive or aimed outside your environment, instead of asking you to approve it. Anthropic also stopped billing the classifier overhead on those plans. Enterprise and API accounts keep their current default and keep paying for the checks. You can still switch with Shift+Tab, and a default you set yourself survives the change.

14 Augauto mode becomes the default on Pro, Max, Team
89%of planted dangerous commands blocked, per Anthropic
13.6%caught by the humans clicking approve
Answer card: Anthropic announced on 7 August 2026 that from 14 August auto mode becomes the default permission mode for new Claude Code sessions on Pro, Max and Team plans, replacing the per action approval prompt with a separate classifier model that reviews each tool call, with the classifier overhead no longer billed on those three plans while Enterprise and API accounts keep paying.
One date, three plans, and a billing change that went unmentioned in most coverage.

What changes, precisely

Not much, if you already picked a mode. That’s the part worth saying first.

Sessions on Pro, Max and Team that have never had a default set will start in auto mode from 14 August, with an in-app notification when it happens. Set a default yourself at some point? You get a one-time prompt asking whether you want to move, and declining leaves you where you are. Managed defaults pushed by an organisation don’t move at all.

Auto mode itself isn’t new. It has been available for months, and Boris Cherny, who runs Claude Code, told TechCrunch the team has used it exclusively “for many months”. What changed on 7 August is the default, plus the bill.

The number worth arguing about

Everyone quoted the 89%. Here’s the official framing, from the product account:

Starting August 14, auto mode will be the default permission mode in Claude Code for Pro, Max, and Team users. Auto mode reviews shell commands and actions with a separate classifier. In testing, it caught 89% of dangerous commands. Manual approval caught 14%.

@ClaudeDevs on X, 7 August 2026

The study behind it: 1,053 paid testers recruited through a research vendor, each handed a session where one permission prompt was swapped for an obviously dangerous command. The classifier blocked 937 of them. The humans caught 143. Put differently, auto mode blocked 800 commands a person had waved through, while people blocked 6 that auto mode allowed.

Take that with the appropriate salt. Anthropic ran this study on its own feature, and nobody has replicated it.

Bar chart comparing the share of planted dangerous commands blocked: the auto mode classifier at 89 percent, human testers at roughly 17 percent early in a session, 13.6 percent across the whole study, and about 5 percent after fifty or more prior prompts.
The classifier line is flat. The human line falls off a cliff as the prompts pile up.

But the finding that survives the conflict of interest is the one further down: testers blocked about 17% of dangerous commands early in a session, dropping to roughly 5% after fifty or more prompts. The classifier’s rate held steady. That’s approval fatigue with a number attached, and honestly it’s the only part of the study I’d defend without hedging. Anyone who has run a two hour agent session knows the feeling of approving things on autopilot. Now there’s a measurement of it.

Anthropic also reports that users approve 97% of permission prompts. A gate you pass 97% of the time isn’t really a gate.

What it blocks

The classifier trusts your working directory and the git remotes that were configured when the session started. Everything else is external until you say otherwise. Remotes added mid-session with git remote add aren’t trusted, which is a nice touch.

The default block list is more specific than the marketing suggests. Force push. curl | bash. Production deploys and migrations. terraform destroy and its Pulumi, CDK and Terragrunt equivalents. Mass deletion on cloud storage. Granting IAM or repo permissions. Anything that irreversibly destroys files that existed before the session started. Plus a set of git commands the classifier presumes would discard uncommitted work, including git reset with the hard flag and git clean -fd.

There’s a subtler one. Entering auto mode drops your broad allow rules: blanket Bash(*), wildcarded interpreters like Bash(python*), package manager run commands, Agent allow rules. They come back when you leave. Narrow rules such as Bash(npm test) carry over untouched. So if you’ve built up a permissive allowlist over months, auto mode is stricter than what you had, not looser.

Checklist of what the Claude Code auto mode classifier blocks by default, including force push, downloading and executing code, production deploys, infrastructure destroy commands, mass cloud storage deletion and IAM permission grants, set against the gaps that remain the user's responsibility including conversational boundaries lost to context compaction, fixed fallback thresholds, headless session aborts and classifier tokens still billed on Enterprise and API accounts.
Five things it handles. Five things it does not, and the last one is a bill.

The parts still on you

Three details we’d want anyone to know before 14 August.

A boundary you state in conversation isn’t a rule. Tell Claude “don’t push until I review” and the classifier does honour it, but it re-reads that instruction from the transcript on every check. Context compaction can remove the message that stated it, and the boundary goes with it. For a guarantee, write an actual deny rule.

The fallback thresholds are fixed. Three blocks in a row or twenty across a session pauses auto mode and returns you to prompts. Neither number is configurable. That’s mostly sensible, though in headless runs with -p there’s nobody to prompt, so repeated blocks kill the session outright. Worth knowing if you drive Claude Code from CI.

And the classifier runs on Sonnet 5 by default rather than whatever you picked with /model, falling back to an Opus model when your session is on Fable 5.

Who actually pays

This is the bit that got lost. Pro, Max and Team users stopped being charged for classifier overhead on 7 August. Everyone else did not.

On Enterprise plans, and on accounts using the Claude API, Claude Platform on AWS, Amazon Bedrock, Google Cloud’s Agent Platform or Microsoft Foundry, classifier calls still count toward your token usage. Each check ships a slice of the transcript plus the pending action, so there’s latency on top of the tokens. Reads and working-directory edits skip the classifier entirely, meaning the overhead concentrates on shell commands and network operations, which is exactly the traffic an agentic session generates most of.

If you run Claude Code on the API for a team, that’s a real line item, and it’s arriving alongside a default change that makes the feature more visible.

Would we leave it on

Yes, with one caveat, and I might be wrong about the caveat.

The fatigue data convinced us. We were not carefully reading approval prompt number forty either, and pretending otherwise would be dishonest. A classifier that stays at 89% while our attention decays to 5% is a better guard than the one we were actually providing.

The caveat is scope. Anthropic’s own warning says auto mode reduces prompts without guaranteeing safety, and that’s not boilerplate. The classifier reasons about what your request implies, so it’s strongest on the catastrophic and weakest on the merely wrong. It will stop rm -rf ~. It won’t stop a confidently bad refactor across forty files, because nothing about that looks dangerous to a safety classifier.

So: auto mode for the work where you trust the direction, manual for anything touching things you cannot rebuild. Which is roughly what the docs say, and for once that advice isn’t hedging.

Sources

  • Anthropic, “Auto mode is now the default in Claude Code for Pro, Max, and Team plans”, 7 August 2026, for the 14 August date, the 1,053 tester study, the 89% and 13.6% figures, the 937 and 143 counts, the 800 versus 6 comparison, the decay from 17% to 5%, and the end of classifier billing on those three plans.
  • TechCrunch, “Anthropic is turning Claude Code’s auto mode on by default”, 9 August 2026, for the 97% prompt approval rate, the prompt injection screening and hard deny rules, and the Boris Cherny quote.
  • Claude Code documentation, “Choose a permission mode”, for the default block list, the dropped broad allow rules, the conversational boundary behaviour and its interaction with context compaction, the three and twenty fallback thresholds, the headless abort, the Sonnet 5 classifier default, the settings file rules for defaultMode, and the token billing split across plans and providers.
  • 9to5Mac, 7 August 2026 and Dataconomy, 10 August 2026, for independent confirmation of the date and the affected plans.

Frequently asked questions

What exactly happens on 14 August 2026?

New Claude Code sessions on Pro, Max and Team plans start in auto mode instead of the manual approval mode. If you never set a default yourself, you get an in-app notification and the switch happens. If you did set one, you get a one-time prompt asking whether you want to move, and your choice stands if you decline. A default your organisation manages through managed settings is left alone. Enterprise, the Claude API and the cloud platform deployments keep their current default for now.

How do I turn auto mode off?

Press Shift+Tab in the CLI to cycle modes, or use the mode dropdown in the desktop app and the editor extensions. To make it stick, set permissions.defaultMode in your user settings file at ~/.claude/settings.json. One gotcha worth knowing: Claude Code ignores defaultMode auto in project settings and local settings, so a repository you clone cannot switch itself into auto mode. Administrators can remove it entirely for an organisation with permissions.disableAutoMode set to disable in managed settings.

Is auto mode actually safer than approving prompts myself?

On Anthropic's own numbers, yes, and you should weigh who produced those numbers. In a study of 1,053 paid testers recruited through a research vendor, the classifier blocked 89% of planted dangerous commands while the testers caught 13.6%. The part we find convincing is the decay rather than the headline: the same people blocked around 17% early in a session and about 5% once fifty or more prompts had gone by. That is approval fatigue measured, and it matches what anyone who has run a long agent session already suspects about their own attention.

Does auto mode cost me extra tokens?

It depends entirely on how you pay. Anthropic stopped charging Pro, Max and Team users for the classifier overhead as of 7 August. On Enterprise plans and on accounts using the Claude API, Claude Platform on AWS, Amazon Bedrock, Google Cloud's Agent Platform or Microsoft Foundry, classifier calls still count toward your token usage. Each check sends part of the transcript plus the pending action, so it adds a round trip too. Reads and edits inside your working directory skip the classifier, which means the cost lands on shell commands and network calls.

What happens when the classifier keeps blocking things?

Auto mode gives up and hands the session back to you. Three blocks in a row, or twenty across the whole session, pauses auto mode and Claude Code starts prompting again. Approving the prompted action resumes it. Those thresholds are fixed and you cannot configure them. In headless runs with the -p flag there is nobody to prompt, so repeated blocks abort the session instead. Persistent blocking usually means the classifier lacks context about your infrastructure rather than that your work is dangerous.

Tags: agentsaiclaude-codedevtoolsnewspermissions
Share197Tweet123
stephane

stephane

  • Trending
  • Comments
  • Latest
The Agentic Coding section of the official Hy4 preview benchmark appendix published by Tencent, a table comparing Hy3 and Hy4 preview against DeepSeek V4 Pro 0813, Qwen 3.8 Max, GLM 5.3, Kimi K3, GPT 5.6 Sol and Claude Opus 5 across SWE-bench Multilingual, SWE-bench Pro, DeepSWE, three SWE Atlas tasks, SWE-Marathon, Terminal-Bench 2.1, NL2Repo-Bench, CyberGym, ProgramBench, PostTrainBench and Harbor-Index.

Tencent’s 770B Hy4 tops one benchmark row in 46

3 September 2026
Answer card: Proton Lumo 2.0 is private by policy, not by locality. Saved history is locked so even Proton cannot read it, but the prompt is decrypted on a Proton EU server to answer it, then forgotten.

Proton Lumo 2.0 review: how private is it, really?

3 September 2026
Answer card: Apple released iOS 26.6 and iPadOS 26.6 on 27 July 2026 with a release note covering bug fixes, security updates and an optimized Spotlight index to prepare for iOS 27, the index the rebuilt Siri reads for personal context.

iOS 26.6 is out: the Spotlight index it quietly builds

27 July 2026
Answer card: JWTs are not encrypted, anyone can read them; the signature proves who issued the token, not who may read it.

Are JWTs encrypted? No, and the difference will bite you

0
Answer card: a random 8 character password falls in under 2 hours offline, while 16 random characters hold for 1.4 trillion years at the same speed.

How long does it take to crack a password in 2026?

0
Answer card: three DNS records decide if your mail lands or bounces; SPF lists allowed senders, DKIM signs messages, DMARC sets the failure policy.

SPF, DKIM and DMARC explained: the records your email needs

0
Answer card stating that Cognition released SWE-2 on 10 September 2026, a coding model post-trained from Kimi K3, scoring 50.0 percent on FrontierCode 1.1 Main against 50.9 percent for Claude Fable 5.1 and 27.3 percent on Terminal-Bench 4 against 55.8 percent, available only inside Devin.

SWE-2 trails Fable 5.1 by one point, and by 28 on Terminal-Bench 4

11 September 2026
Answer card for Meta Muse, free to 100 million tokens a week then $20 a month, launched 8 September 2026 for United States adults only, running in a dedicated per user virtual machine.

Does Meta Muse do enough to earn your inbox and a card on file?

9 September 2026
Answer card stating that the public download pages for the VMware Virtual Disk Development Kit on developer.broadcom.com began returning 404 errors on 25 August 2026 with no announcement or deprecation notice, that Broadcom support tells customers the kit is no longer available for use or download, and that release lines 7.0.3.1, 8.x and 9.x are all affected.

Broadcom pulled VDDK 8.0 and 9.0, and the 404 is the only notice

8 September 2026
  • About
  • Contact
  • Privacy
  • Legal

Copyright © 2026 Stephane Cardon.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Articles
    • Security
    • Network
    • Dev
    • Sysadmin
    • SEO
    • Email & DNS
  • Tools
    • Network tools: free, fast, no signup
    • Security tools: free, fast, no signup
    • Developer tools: free, fast, no signup
    • Sysadmin tools: free, fast, no signup
    • SEO tools: free, fast, no signup
    • Email & DNS tools: free, fast, no signup
  • Download
  • About

Copyright © 2026 Stephane Cardon.