AI 编程 5.0 · 必读 2026-08-07 · 文章

Auto mode is now the default in Claude Code for Pro, Max, and Team plans

Anthropic 官宣自 2026-08-14 起 Pro/Max/Team 新会话默认运行 auto mode:每个 tool call 先过分类器,拦截不可逆/破坏性/环境外动作,连续 3 次或单会话 20 次被拦后回落人工审批;Enterprise/API 暂 opt-in核心数据:用户批准率 97%;1053 人对照实验中人工只拦 13.6% 危险命令auto mode 拦 89%;长会话人工拦截率 17%5%,auto mode 持平...

打开原文回到归档

Auto mode is now the default in Claude Code for Pro, Max, and Team plans

  • ID: 15e161b5
  • 原文链接: https://claude.com/blog/auto-mode-default-in-claude-code
  • 作者: Anthropic(@claudeai)
  • 日期: 2026-08-07
  • 分类: coding
  • 来源类型: article
  • 标签: claude-code, anthropic, auto-mode, permission, classifier, human-oversight
  • 质量评分: 5/5
  • 抓取时间: 2026-08-15T13:05:00Z(官方 blog 全文 opencli 抓取)

中文导读

Anthropic 官宣:自 2026-08-14 起,Pro/Max/Team 新会话默认运行 auto mode——权限弹窗不再逐条问人,而是每个 tool call 先过分类器,拦截"不可逆、破坏性、指向环境外"的动作;连续 3 次或单会话累计 20 次被拦后回落人工审批。Enterprise/API/Bedrock 等暂保持 opt-in,未来一个月内跟进,分类器 token 开销对用户免费。官方公开的核心数据:用户对权限弹窗的批准率高达 97%(拒绝仅 3%;对比计划审批被拒 39%);1,053 名付费测试者对照实验中,人工只拦住 13.6% 的危险命令,auto mode 拦住 89%,且随会话变长人工拦截率从 17% 跌到 5%,auto mode 保持平稳;真实被标记会话中,人工批准路径的非预期严重危害是 auto mode 的两倍以上(生产级 7+ 危害 6.3% vs 2.4%)。第三方 Trajectory Labs 72 个间接 prompt injection 场景 ×10 次:Claude 系模型开 auto mode 720 次攻击全部失败,GPT-5.6 Sol Codex Auto-review 被打穿 5.83%。Apollo Research 红队两周期后,分类器对留出攻击集漏报率 12%→7%。

为什么值得关注

这是"人审疲劳"从厂商侧被坐实的标志事件:当 97% 弹窗被无脑批准时,human-in-the-loop 已经是装饰品,Anthropic 用受控实验直接给出"分类器 > 平均人审"的证据,并把默认行为改过来。注意 auto mode ≠ bypassPermissions:它保留策略层(宽到可任意执行代码的 allow-rule 如 Bash(python:*) 在 auto mode 下会被暂时搁置),拦截后模型会自找安全路径。与本库 Docker Sandboxes(microVM 默认隔离)构成同一周"默认隔离 vs 人点 Yes"叙事的两条腿。

关键信息

  • 生效:2026-08-14 新会话;Pro/Max/Team;已 pin 默认者一次性询问
  • 机制:classifier per tool call;irreversible / destructive / outside-environment 拦截;3 连拦或 20 次/会话回落人工
  • 数据:97% 批准率;人审 13.6% vs auto 89% 拦截;长会话人审 17%→5%;生产级危害 6.3% vs 2.4%
  • 注入防御:Trajectory Labs 720 次攻击 0 成功(Claude 全系 auto mode);Codex Auto-review 5.83% 成功
  • 红队:Apollo Research find-fix-verify,漏报 12%→7%(对抗集,非真实流量)
  • 生产力:Teams/Enterprise 采纳者 PR 产出 +25%;Adobe、Nuro、Gusto、Garner Health 生产默认
  • 管理:Shift+Tab 切换;managed settings defaultMode / disableAutoMode
  • 产出对比:auto mode 用户 ship 约 25% more PRs

正文存档(官方 blog 要点摘录)

We're making auto mode the default in Claude Code. Starting on August 14, new sessions on Pro, Max, and Team plans will run in auto mode.
The auto mode classifier uses a small number of extra tokens per tool call, and we're no longer charging Claude Code users on Pro, Max, and Team plans for that classifier overhead, effective today.
instead of prompts, it routes each tool call through a classifier targeted at blocking actions that are irreversible, destructive, or aimed outside your environment.
Data suggests that manual review can become habitual: users approve 97% of permission prompts in Claude Code.
In a controlled experiment with 1,053 paid professional testers, human review caught just 13.6% of dangerous commands, while auto mode caught 89%.
As sessions got longer, humans did worse: they blocked about 17% of dangerous commands early in a session, dropping to about 5% after 50 or more prior prompts, while auto mode's block rate stayed flat regardless of session length.
Permission rules still fire before the classifier in auto mode, except for allow rules broad enough to grant arbitrary code execution (e.g. python:*). These arbitrary rules are set aside while in auto mode.
In this evaluation, none of the 720 attack attempts succeeded against Claude Fable 5, Opus 5, or Sonnet 5 running auto mode. On the other hand, 5.83% of the attacks succeeded against GPT-5.6 Sol running Codex's Auto-review mode.

Obsidian Notes

  • 来源调研: 调研/2026-08-15-调研-默认隔离压过点Yes审批.md
  • 研究材料: DeepResearch/2026-08-15-evening-默认隔离与审批疲劳-dots3TEMPO-研究材料/01-dump-default-isolation-vs-approval.md