Anthropic Opens Applications for Its Life Sciences Verification Program - Loosened Biology Safeguards for Vetted Organizations
On September 17, 2026, Anthropic began accepting beta applications for its Life Sciences Verification Program (LSVP). Vetted teams and institutions can use Mythos 5.1, Opus 5, and Sonnet 5 with classifiers relaxed for biology work. In exchange, 30-day data retention is required, and BAA-enabled organizations cannot join.
On September 17, 2026, Anthropic started taking applications, in beta, for its Life Sciences Verification Program (LSVP), a credentialing program for professionals in the life sciences1. Organizations that pass review can use the Mythos, Opus, and Sonnet models under safeguards that have been loosened for biology work. An early-access phase has already brought in dozens of organizations; this step opens applications to the life sciences field as a whole. The first eligible applicants are teams and institutions, and Anthropic says it will extend access to individual Pro and Max plans later.
Anthropic describes the program as a way to allow work that its generally available Fable models currently block, such as drug discovery, research biology, clinical development, and manufacturing. It names academic labs, startups, and pharmaceutical companies among the intended users.
Two tiers: “Standard Use” and “High-risk Use”
The review covers each applicant’s scientific credentials, its security practices, and how its research is ethically overseen1. Verified applicants can then apply for one or both of two kinds of “grant” (access permission) depending on what they need. Both are said to work across Claude Science, Claude.ai, Claude Code, and the API.
Standard Use targets most life sciences work. It can cover an entire team and is renewed annually1. Its classifiers let through more scientific requests than the ones on the generally available models. The eligible models today are Mythos 5.1, Opus 5, and Sonnet 5, and the grant will also apply to models released later. The listed areas include basic science, R&D, supply chain and manufacturing, clinical development, quality assurance, regulatory affairs, and investing and diligence.
High-risk Use is a supplementary grant covering areas that Standard Use still blocks. It lifts every safeguard that blocks life sciences requests, but it is issued per research project rather than per team, and it has to be renewed every six months1. The typical pattern Anthropic describes is one Standard Use grant for everyday work plus High-risk Use grants attached only to specific dual-use projects. High-risk Use is available from launch for Opus 5 and Sonnet 5. For Mythos, Anthropic is cooperating with the US government on wider availability, and for now it is limited to a small number of organizations that have gone through additional vetting.
Under either grant, safeguards outside biology, such as the cyber classifiers, stay in place.
Monitoring after the fact instead of blocking up front
The design philosophy also shifts. Anthropic explains that in biology a single request often cannot reveal whether the work is legitimate or harmful, and that the most worrying scenarios involve legitimate access being diverted or taken over by someone with bad intent1. It names three main threat models: compromised access (malware or account takeover), insider threats, and agent misuse (including agents operating in swarms or on long-running tasks).
The core countermeasure is a move away from real-time blocking of each request toward offline monitoring that looks at patterns of behavior. Anthropic’s reasoning is that serious misuse tends to be split across many requests and sessions so that the pieces look unrelated. Access is bound to the use cases each organization declared when applying; if usage outside that scope is detected, the organization’s administrators are flagged and are expected to respond within a timeframe agreed in advance. Anthropic frames this as a “shared responsibility” model designed together with enterprise CISOs. The use-case descriptions only need to be high level, roughly what a job posting would say, and should not contain sensitive information or intellectual property.
The price of this approach is 30-day data retention, which is mandatory for LSVP traffic1. The retained data is said to be strictly compartmentalized, excluded from model training, and off-limits to Anthropic’s own life sciences research teams. For eligible organizations, Anthropic says it is also exploring integration with Enterprise Frontier Safeguards (EFS), which keeps monitoring logs in the customer’s own cloud.
Where it works, and where it does not yet
Availability comes with several constraints1.
- For now it is offered through Anthropic’s own console for API use and through the Claude for Enterprise and Team plans. Individual plans and third-party platforms are not supported yet
- Because it is in beta, organizations with a BAA enabled cannot use it. Customers handling PHI (health data) need to set up a separate organization without a BAA
- The API and Claude Science let users move between grants, whereas Claude.ai and Claude Code initially honor just one default grant chosen in advance (Claude Code used with API-key authentication is the exception)
On scale, Anthropic expects to enroll hundreds of organizations in the first week and to grow the program over the coming weeks to a size that can support most of the life sciences community.
A staged opening after an Opus-only period
The announcement extends a line of decisions about biology that Anthropic has been drawing since the summer. On August 7 it recalibrated Fable 5’s biology safeguards, reducing fallbacks for everyday health and education questions while still routing virology, toxicology, and molecular design to Opus 5. Its expanded support for researchers on August 27 likewise stated that biology and chemistry researchers would, for the time being, be limited to Opus-class models.
At the time of the Fable 5.1 / Mythos 5.1 announcement on September 1, the LSVP had enrolled its first participants in partnership with the US government, and broader expansion was described as a future plan2. The new announcement sets out concrete terms: what the review covers, the grant tiers and their renewal cycles, data retention, and the supported plans.
Misuse is part of the backdrop. In the announcement, Anthropic points to its threat report as showing a rise in sophisticated misuse attempts, including attempts that might aid the development of biological weapons1. The threat intelligence report published on September 10 covered cases across seven areas, biological misuse among them. Rather than loosening the classifiers on its public models across the board, Anthropic appears to have chosen to loosen them only for specific organizations, on the condition of vetting and monitoring.
For pharmaceutical and biotech companies weighing adoption, the points to check are clear. Access is limited to Team and Enterprise plans and to the API through Anthropic’s own console; 30-day data retention is a precondition; organizations with a BAA cannot use it, so work involving PHI has to sit in a separate organization; and in Claude Code only the default grant applies (except with API-key authentication). Research that needs High-risk Use will also have to build per-project applications and six-month renewals into its operations.
Sources
- Introducing the Life Sciences Verification Program - Anthropic official announcement (September 17, 2026)
- Introducing Claude Fable 5.1 and Claude Mythos 5.1 - Anthropic official announcement (September 1, 2026)
Was this article helpful?
Thank you!
Received. Thank you!