Skip to main content

People approve 97% of the prompts. What that says about your controls

Agents2 min read

From 14 August, Claude Code runs on its own by default. Anthropic's reason comes down to a single number, and it is worth reading even if you have never written a line of code.

On 14 August, Anthropic makes auto mode the default in Claude Code for Pro, Max and Team accounts. Until now the tool stopped and asked permission for nearly every action. From that date it carries on by itself, stopping only before something judged irreversible, destructive, or aimed outside your environment.

I teach Claude Code in workshops, so the change lands close to home. But it isn't the tool that made me write this. It's one number in the announcement.

A manual review that became a ritual

Anthropic published a study of 1,053 paying users. Auto mode caught 89% of harmful actions. Human review caught 13.6%. Their explanation for the gap is simple, and uncomfortable.

Manual review can become habitual: users approve 97% of permission prompts.

Sit with that number, because it stopped being about programming. Every "human in the loop" you have defined in your business lives in exactly the same place: the manager approving discounts, the controller approving invoices, whoever is meant to read each email before the bot sends it. Ask a person to approve everything and they stop reading. That isn't negligence — it's predictable human behaviour.

What to do with it in your own system

The lesson is not "remove the brakes". It's that a brake pressed 97 times out of 100 is not a brake, it's a ritual. A few stopping points people genuinely read, plus a full action log for everything else, beats an approval on every step that nobody looks at.

Alongside the change Anthropic added two things: prompt-injection screening, and hard deny rules you configure yourself. That is roughly the right shape for an agent running in your business too — permissions defined up front, a red line it never crosses, and a record of everything it did.

It's too early to know how this behaves in the wild. The change takes effect on 14 August, and the study is Anthropic's own, on Anthropic's own product. But the question it raises about your business is no longer theoretical: how many of the approvals you ask your team for are actually read?

Sources

This piece was written from the reporting below, not copied from it. Read the originals for the full detail.

Want this working for you, not just in the headlines?

Everything written here is, in the end, a tool. If any of it sounds relevant to your process, talk to me and we'll see what's worth building.