Anthropic announces an “auto mode” that enables Claude Code to make permission-level decisions while preventing destructive commands like mass file deletion
ZDNET's key takeaways — Claude's auto mode reduces permission prompts for developers.
The design pairs delegated permission decisions with explicit limits on destructive actions, making operational safeguards central to how Claude Code’s greater autonomy is introduced.
First-order effects
Developers using Claude Code face fewer permission interruptions when auto mode is enabled, while mass file deletion remains blocked by the stated guardrails.
Anthropic gains a clearer autonomy-control setting for Claude Code as its computer-use capabilities are rolled out.
Second-order effects
Tool makers competing for developer-agent workflows will be pressed to make permission handling less burdensome without making destructive behavior easier to trigger.
Teams evaluating computer-use tools can assess autonomy as a configurable operating policy rather than a simple on/off capability, increasing the importance of auditable safeguards.
Third-order effects
If similar controls become standard, agentic software is likely to compete on the quality of its permission boundaries and operational assurance—not only on model capability.
The pattern points toward more granular delegation systems, where users authorize routine actions while platforms retain hard limits for high-impact operations.
The trend: Developer agents are shifting from prompt-by-prompt supervision toward bounded autonomy governed by configurable permissions and hard safety constraints.
Before each tool call, a classifier reviews it for potentially destructive actions. Safe actions proceed automatically. Risky ones get blocked, and Claude takes a different approach. This reduces risk but doesn't eliminate it. We recommend using it in isolated environments.
lol its literally been <24hrs and anthropic shipped another banger feature: auto mode now claude code can autonomously review, approve or deny tasks that require human permission - literally removing humans from the loop. autonomous agents. - claude will review... claude code [vi…
We went from “human in the loop” to “AI in the loop.” Auto mode doesn't skip permissions — it adds a classifier that reviews every tool call before execution. Blocks destructive operations, data exfiltration, prompt injection. If Claude keeps pushing blocked actions, it
New in Claude Code: auto mode. Instead of approving every file write and bash command, or skipping permissions entirely, auto mode lets Claude make permission decisions on your behalf. Safeguards check each action before it runs. [video]
The end state is that you don't “use the computer” like you used to, or do now. The computer will use itself. With time, your use of the computer for work will look more and more like you are playing a strange video game, which will itself be built in large part by computers.
Claude Auto Mode — not sure about you, but i keep claude in —dangerously-skip-permissions 100% of the time — Auto Mode has a classifier to detect potentially destructive actions, so it's not as painful to use non-dangerous mode. Strictly safer! — claude.com/blog/auto-mode