All posts
4 min read

Anthropic Just Made Its AI Stop Asking Permission

From 14 August, Claude Code runs in auto mode by default for paid users. Anthropic's own testing found the AI caught 89 per cent of harmful actions, while human reviewers caught 13.6 per cent. ---

By TechMoose
Anthropic Just Made Its AI Stop Asking Permission

The click that was protecting nobody

Anthropic is turning on auto mode by default in Claude Code, its AI coding tool, for Pro, Max and Team accounts from 14 August 2026. Auto mode lets the AI carry out programming work without stopping to ask a human at each step. It still pauses for actions it considers irreversible, destructive, or aimed outside your environment.

Auto mode has existed since March as an opt in test. What changed is the default, and defaults are where real behaviour lives.

The reason Anthropic gave is the interesting part. In testing with 1,053 paying users, the company found auto mode caught 89 per cent of harmful actions. Human review caught 13.6 per cent. Anthropic also found that users approve 97 per cent of the permission prompts Claude Code shows them.

Read those two numbers together and the picture is uncomfortable. The safety step was not really a safety step. It was a habit.

Boris Cherny, who heads Claude Code, put it plainly. "The team and I use Auto mode exclusively, and have been for many months. I couldn't imagine going back to permission prompts."

Anthropic says it has added prompt injection screening and customisable hard deny rules to block data exfiltration alongside the change.

Why this is bigger than a coding tool

Most readers do not write software, so it would be easy to skip this one. Do not. This is the clearest example yet of a shift that will reach every business using AI.

For two years the standard answer to "is AI safe to use in my business" has been "we keep a human in the loop". One of the most safety focused labs in the world has now published numbers arguing that a human in the loop, when that loop is a stream of approval pop ups, does close to nothing.

That is not an argument for removing humans. It is an argument that the humans were never really reviewing.

Anyone who has clicked through a cookie banner, a terms update or a software permission screen already knows the mechanism. Approval fatigue is not a character flaw. It is what happens when a system asks a person to make a hundred low context decisions a day and expects the hundred and first to be careful.

What this means for how you buy and run AI

Three things worth taking from it.

Stop counting approvals as a control. If your AI process ends with a person clicking yes, ask what would actually happen if they clicked yes on something bad. If the honest answer is "it would go through", the click is theatre, not governance.

Move the control earlier. The controls that survive contact with reality are the boring structural ones. What systems can the tool reach. What can it never do without a second pair of eyes. What is logged. What can be undone. Those hold when attention does not.

Ask vendors what their defaults are, not what their settings allow. Almost every AI tool can be configured safely. Very few are, because almost nobody changes a default. The default is the product.

The TechMoose take

We build AI voice agents and chatbots, and this change lines up with something we see constantly.

Businesses ask for a human approval step, then never use it. A voice agent books a job, the owner gets a notification, and by week three the notification is unread. The approval was real for a fortnight and decorative after that.

The version that actually works looks different. Instead of asking a human to bless every action, you decide in advance which actions the AI can take alone, which ones require a person, and which ones simply never happen. Then you log everything so you can check the pattern weekly rather than the pop up hourly.

Anthropic's numbers say the same thing in a harsher way. Design the boundary, not the interruption.

The businesses that get burnt over the next year will mostly not be the ones that gave AI too much freedom. They will be the ones that thought a confirmation dialogue counted as supervision.

Sources

AnthropicAI agentsautomationAI governancebusiness risk

TECHMOOSE AI

Ready to put AI to work in your business?

TechMoose AI builds voice agents and chatbots that answer calls, take bookings and handle support, live in minutes, not months.

Try TechMoose AI