AI

Developers approve 97% of Claude Code’s permission prompts. Anthropic just took the prompts away.

Auto mode became the default for Pro, Max and Team plans on 14 August. The evidence: in a controlled study of 1,053 paid testers, humans caught 13.6% of dangerous commands and the classifier caught 89% — and human attention got worse the longer the session ran.

N Noah · The Sharp Brief · August 23, 2026 · 4 min read

Every AI coding agent ships with the same safety feature: a prompt that asks before it does something. Anthropic just published the number that makes the whole design look like theatre. Developers approve 97% of the permission prompts Claude Code puts in front of them. The rejection rate on an individual permission request is 3%.

As of 14 August, new Claude Code sessions on Pro, Max and Team plans start in auto mode by default. Instead of asking, every tool call gets routed through a classifier trained to block actions that are irreversible, destructive, or aimed outside your environment. If the classifier blocks three things in a row, or twenty across a session, Claude Code drops back to manual approvals.

The evidence behind the switch is the interesting part. Anthropic hired 1,053 paid testers through a research vendor and, partway through each session, swapped one permission prompt for a clearly dangerous command. The testers caught it 143 times — 13.6%. Auto mode blocked the same command 937 times, or 89%. Head to head, auto mode stopped 800 commands a human waved through; humans stopped 6 that auto mode allowed.

Attention decays; the classifier doesn’t

The fatigue curve is the finding that generalises beyond one product. Early in a session, testers blocked roughly 17% of dangerous commands. After fifty or more prior prompts, that fell to about 5%. Auto mode’s block rate stayed flat regardless of how long the session ran.

People clearly know the difference between a decision and a formality. When Claude presents a plan for approval, users reject 39% of them. When it asks permission for a single command, 3%. The prompt has stopped being a decision point and become a keystroke.

The settings data says the same thing louder. As of June, 49.5% of active CLI users had hand-written a Bash allow-rule — 5% permitting any shell command outright — and 62% had used bypassPermissions or clicked “don’t ask again” on Bash. A quarter of interactive sessions now start in bypass mode. Users were already switching the guardrail off. Anthropic replaced it rather than watched it erode.

Our take: This is not really a story about Claude Code. It is a measurement of every approve/deny dialog your company relies on — in agent tooling, in security software, in expense workflows. A 97% approval rate is not consent, it is muscle memory, and any control with that number attached is decoration. Go find yours before someone else does.

The caveats Anthropic put in writing

Two numbers cut the other way. Apollo Research red-teamed the classifier over a two-week pilot; after hardening, its miss rate on adversarial attacks fell from 12% to 7% — better, not zero, and measured against attacks built specifically to break it. Anthropic says plainly that auto mode “relies on classification systems and therefore does not eliminate risk,” and still recommends reviewing changes to production infrastructure yourself.

On prompt injection, a commissioned evaluation by Trajectory Labs ran 72 held-out scenarios ten times each. None of the 720 attacks succeeded against Claude models in auto mode. The same set landed 5.83% of the time against GPT-5.6 Sol in Codex’s Auto-review mode, and 19.03% in Full Access. Vendor-commissioned, single-benchmark, so treat it as directional.

There is a commercial number in here too: among Teams and Enterprise adopters, auto mode users ship about 25% more pull requests. Safety and throughput pointing the same way is what makes a default change stick.

What to watch

Advertisement

Get the day, decoded — at 7 PM ET

The Sharp Brief: AI, money, business & performance in five sharp minutes. Free.

Free bonus: subscribe today and The 2026 AI Playbook lands with your welcome email.

Recommended by 5+ newsletters across AI, markets & business.