Anthropic Broadens Claude Code's Control, Retains a Leash

For developers relying on AI, the current approach to "vibe coding" often involves either closely monitoring every action or giving the model free rein. Anthropic claims its latest update to Claude removes that dilemma by allowing the AI to autonomously decide which actions are safe to execute — within certain boundaries.
This move mirrors a wider industry trend where AI tools are being built to act without requiring human approval at every step. The key challenge is striking a balance between speed and oversight: excessive safeguards slow progress, while too few can lead to unpredictable and risky behavior. Anthropic's new "auto mode," currently in research preview — meaning it's available for testing but not yet a finalized product — is its latest effort to navigate this balance.
Auto mode employs AI safeguards to examine each action before execution, looking for unrequested risky behavior and signs of prompt injection — an attack technique where malicious instructions are embedded in the content being processed, tricking the AI into performing unintended actions. Actions deemed safe are carried out automatically, while risky ones are blocked.
This is essentially an extension of Claude Code's existing "dangerously-skip-permissions" command, which delegates all decision-making to the AI, but with an additional safety layer on top.
The feature builds on the recent surge of autonomous coding tools from companies like GitHub and OpenAI, which can carry out tasks on behalf of developers. However, it goes a step further by moving the decision of when to request permission from the user to the AI itself.
Anthropic has not disclosed the specific criteria its safety layer uses to differentiate safe from risky actions — details that developers will likely want to understand more clearly before widely adopting the feature. (TechCrunch has contacted the company for further information on this matter.)
Auto mode follows Anthropic's launch of Claude Code Review, an automatic code reviewer that catches bugs before they reach the codebase, and Dispatch for Cowork, which enables users to assign tasks to AI agents to handle work on their behalf.
Auto mode will be rolled out to Enterprise and API users in the coming days. The company states it currently works exclusively with Claude Sonnet 4.6 and Opus 4.6, and recommends using the new feature in "isolated environments" — sandboxed setups that are separate from production systems, minimizing potential damage if something goes wrong.
Related article
Anthropic Enters AI Legal Tech Market as Competition Intensifies
Anthropic unveiled a suite of new chatbot capabilities on Tuesday, aimed at delivering automated support to legal practices. These enhancements expand upon Claude for Legal, the firm-specific platform introduced earlier this year, by adding specializ
OpenAI Closes Gap With Anthropic Among Business Users, New Data Shows
With OpenAI and Anthropic still distant from their anticipated IPOs and the release of detailed financial reports, we must turn to alternative indicators to gauge their business performance. Ramp, a corporate credit card and expense management platfo
Anthropic launches Opus 4.8 featuring new dynamic workflow tool
Anthropic unveiled Opus 4.8 on Thursday, marking the latest iteration of its premier public model. Priced identically to its predecessor, this update is now accessible across all platforms.Releasing just 41 days after Opus 4.7, Anthropic has accelera
Related Special Topic Recommendations
Comments (0)
0/500

For developers relying on AI, the current approach to "vibe coding" often involves either closely monitoring every action or giving the model free rein. Anthropic claims its latest update to Claude removes that dilemma by allowing the AI to autonomously decide which actions are safe to execute — within certain boundaries.
This move mirrors a wider industry trend where AI tools are being built to act without requiring human approval at every step. The key challenge is striking a balance between speed and oversight: excessive safeguards slow progress, while too few can lead to unpredictable and risky behavior. Anthropic's new "auto mode," currently in research preview — meaning it's available for testing but not yet a finalized product — is its latest effort to navigate this balance.
Auto mode employs AI safeguards to examine each action before execution, looking for unrequested risky behavior and signs of prompt injection — an attack technique where malicious instructions are embedded in the content being processed, tricking the AI into performing unintended actions. Actions deemed safe are carried out automatically, while risky ones are blocked.
This is essentially an extension of Claude Code's existing "dangerously-skip-permissions" command, which delegates all decision-making to the AI, but with an additional safety layer on top.
The feature builds on the recent surge of autonomous coding tools from companies like GitHub and OpenAI, which can carry out tasks on behalf of developers. However, it goes a step further by moving the decision of when to request permission from the user to the AI itself.
Anthropic has not disclosed the specific criteria its safety layer uses to differentiate safe from risky actions — details that developers will likely want to understand more clearly before widely adopting the feature. (TechCrunch has contacted the company for further information on this matter.)
Auto mode follows Anthropic's launch of Claude Code Review, an automatic code reviewer that catches bugs before they reach the codebase, and Dispatch for Cowork, which enables users to assign tasks to AI agents to handle work on their behalf.
Auto mode will be rolled out to Enterprise and API users in the coming days. The company states it currently works exclusively with Claude Sonnet 4.6 and Opus 4.6, and recommends using the new feature in "isolated environments" — sandboxed setups that are separate from production systems, minimizing potential damage if something goes wrong.
Anthropic Enters AI Legal Tech Market as Competition Intensifies
Anthropic unveiled a suite of new chatbot capabilities on Tuesday, aimed at delivering automated support to legal practices. These enhancements expand upon Claude for Legal, the firm-specific platform introduced earlier this year, by adding specializ
OpenAI Closes Gap With Anthropic Among Business Users, New Data Shows
With OpenAI and Anthropic still distant from their anticipated IPOs and the release of detailed financial reports, we must turn to alternative indicators to gauge their business performance. Ramp, a corporate credit card and expense management platfo
Anthropic launches Opus 4.8 featuring new dynamic workflow tool
Anthropic unveiled Opus 4.8 on Thursday, marking the latest iteration of its premier public model. Priced identically to its predecessor, this update is now accessible across all platforms.Releasing just 41 days after Opus 4.7, Anthropic has accelera





Home






