Claude Code Torna o Modo Automático Padrão

Anthropic logoAnthropicImportante9 de agosto de 2026Ferramentas de programação
O que aconteceu
Anthropic makes auto mode the default for Claude Code Pro, Max, and Team starting Aug 14 — the first agentic coding tool where autonomous execution is the normal interaction mode.
Porque é importante
Safety data from 1,053 paid testers shows auto mode catches 89% of dangerous commands vs 13.6% for human reviewers. Independent Trajectory Labs testing: 0/720 prompt injection attacks succeeded against Claude models in auto mode. Classifier overhead is now free.
O que fazer
Pro/Max users: the toggle flips Aug 14. Review your CLAUDE.md and MCP permissions now — auto mode trusts them. Enterprise admins: auto mode stays opt-in temporarily; review the 25% productivity gain from early adopters and managed rollout controls.

Anthropic is making auto mode the default for Claude Code Pro, Max, and Team subscribers on August 14, 2026. This is the first agentic coding tool to ship autonomous execution as the normal interaction mode — not an opt-in beta. And the safety data backing it is the most comprehensive ever published: 1,053-person controlled study, third-party prompt injection red-teaming, and internal production analysis all point the same direction.

What happened

Starting August 14, new Claude Code sessions on Pro ($20/mo), Max ($100/mo), and Team Premium plans will run in auto mode by default. Users who already set a different default get a one-time prompt asking whether to switch. Enterprise, API, and cloud-platform users stay opt-in for now — Anthropic plans to flip the default there in the coming month.

Two things ship alongside:

  1. Classifier overhead is now free (effective August 7). The safety classifier that inspects each tool call no longer counts against your token usage. Anthropic is eating the compute cost.
  2. Enterprise admin controls for rollout. Teams that adopted auto mode early shipped 25% more PRs — and admins can control which users and repos get it via managed settings.

Why it matters

This isn't a product tweak. It's the moment agentic coding sheds the "beta feature" label.

The safety numbers are the story. Anthropic hired 1,053 paid professional testers through a research vendor. Mid-session, a single permission prompt was swapped for a clearly dangerous command. Human reviewers caught the dangerous command 13.6% of the time. Auto mode's classifier caught 89% (Anthropic(abre num novo separador), 2026). That's 800 dangerous commands that a human approved but the classifier blocked.

Critically, auto mode's block rate stayed flat regardless of session length, while human catch rates dropped from ~17% early to ~5% after 50+ prior prompts. Confirmation fatigue is real — and it gets worse the longer a session runs.

Real-world production data reinforces the controlled study. From May–June 2026, Anthropic examined flagged sessions from opt-in accounts and re-graded them on a 0–10 harm-severity scale. At production-level severity (7+), 6.3% of manually approved sessions contained serious unintended harm the user hadn't asked for, compared to 2.4% of auto-mode sessions (Anthropic(abre num novo separador), 2026).

The prompt-injection results are the strongest signal. Trajectory Labs ran an independent adversarial evaluation: 720 prompt injection attacks across 72 scenarios, held out from Anthropic, against Claude Fable 5, Opus 5, and Sonnet 5 in auto mode. Zero attacks succeeded. The same suite against GPT-5.6 Sol + Codex Auto-review mode achieved a 5.83% success rate (Anthropic(abre num novo separador), 2026).

Simon Willison called it right — cautiously. Willison, who predicted a "challenger disaster for coding agents security"(abre num novo separador) for 2026, wrote(abre num novo separador) that he would "dearly like to be proved wrong." But he's not declaring victory. He flags the 11% of dangerous commands auto mode still misses and warns that attacks using malicious third-party packages — where the classifier can't easily distinguish legitimate from malicious — remain an open concern. His preferred solution: OS-level sandboxing that deterministically restricts what agents can access, rather than relying solely on a classifier (Simon Willison(abre num novo separador), 2026).

What changes for you

For Pro and Max subscribers: the toggle flips automatically on August 14. The time to review your CLAUDE.md instructions and MCP server permissions is now — auto mode trusts them by default. Switch modes anytime with Shift+Tab in the CLI.

For Enterprise admins: auto mode remains opt-in temporarily. Anthropic plans to make it the default in the coming month. Early adopters at Adobe, Nuro, Gusto, and Garner Health already run auto mode as their production default. Across Teams & Enterprise adopters broadly, auto mode users shipped about 25% more PRs (Anthropic(abre num novo separador), 2026). Roll out incrementally using managed settings.

For everyone watching the space: Anthropic just shipped the first agentic coding default backed by independent safety data. Cursor, Copilot, and Codex will have to answer whether their agentic modes can match this bar — and whether they'll publish the data to prove it.

O que fazer

  1. 1 Enterprise admins: review managed settings to control rollout by user and repository
  2. 2 Review your CLAUDE.md instructions and MCP server permissions before Aug 14 — auto mode trusts them by default
  3. 3 Switch modes anytime with Shift+Tab in the CLI if you prefer manual approval

Ferramentas e modelos afetados

Nunca mais precisas de te pôr a par

O resumo semanal — apenas mudanças de veredicto e ações urgentes. Sem enchimento.

Ao subscreveres, aceitas a nossa Política de Privacidade. Cancela a subscrição quando quiseres.