Anthropic on September 17, 2026 announced the Life Sciences Verification Program (LSVP), a beta program giving verified life science organizations access to its Mythos, Opus, and Sonnet models under a refined set of safeguards the company described as more permissive for biology-related work.
Anthropic said it has already onboarded dozens of organizations through an early access program and is opening applications to the broader life science community. The program is initially open to teams and institutions, and the company said it will expand access to individual Pro and Max plans over time. Anthropic said the program is designed to enable tasks currently blocked in its generally available Fable models, including drug discovery, research biology, clinical development, and manufacturing, for teams from academic labs to startups and pharmaceutical companies.
Verification and Access Grants
Each applicant passes through a verification process that reviews research credentials, security standards, and ethical research oversight. Verified teams may apply for two grant types, Standard Use or High-risk Use, which can be used across Claude Science, Claude.ai, Claude Code, and the API.
Standard Use grants cover most life science work, including the majority of biology research and development workflows, Anthropic said. They can be extended to entire teams for daily workloads, renew once a year, and apply to Mythos 5.1, Opus 5, and Sonnet 5 at launch and to future models as they launch. Anthropic said the grants are built for activity spanning basic science, research and development, supply chain and manufacturing, clinical development, quality assurance, regulatory affairs, and investing and diligence.
High-risk Use is an add-on grant for work blocked under Standard Use, and it removes all safeguards that block life sciences requests. It applies to a single research project rather than a full team and must be renewed every six months. Anthropic said a typical researcher with dual-use work would hold one Standard Use grant for daily activities plus one or more project-specific High-risk Use grants, giving the example of characterizing how one specific family of viral vectors is recognized by human immune pathways.
High-risk grants for Claude Opus 5 and Claude Sonnet 5 are available at launch. Anthropic said it is working with the US government to make high-risk grants more broadly available for Claude Mythos, where they remain limited at launch to a small set of entities with additional vetting. All other safeguards, such as the company’s cyber classifiers, remain in place under LSVP grants.
Monitoring, Threat Models, and Data Retention
Anthropic said it built the program’s safeguards against three threat models in particular: access compromise, in which malware or account takeover diverts access to a bad actor; insider threats from rogue or coerced employees; and agent misuse, in which agents working in swarms or on long-horizon tasks take unintended dangerous actions. In biology, the company said, valid work and malicious use are often indistinguishable at the level of a single request, so the most concerning threat models are those in which legitimate access is diverted or overtaken.
Developed in close collaboration with enterprise chief information security officers, the design ties each entity’s access to the use cases specified in its grant applications. Anthropic continuously monitors LSVP traffic for usage outside the stated scope and can flag incidents to organization admins, who act within pre-agreed timeframes to triage and remediate. The use-case descriptions are meant to read like job listings and to contain no sensitive information or intellectual property.
The program also shifts enforcement from real-time blocking of individual requests to offline monitoring across patterns of behavior, a change Anthropic said lets legitimate work proceed with fewer interruptions but requires retaining data associated with flagged activity. LSVP traffic therefore carries a 30-day data retention requirement. The company said the retained data is strictly compartmentalized and cannot be used for model training or accessed by members of Anthropic’s life sciences research teams. For qualifying organizations, Anthropic said it is also examining how LSVP can integrate with features of its Enterprise Frontier Safeguards systems.
Biological Misuse Cases Behind the Program
The announcement points to Anthropic’s September 2026 threat intelligence report, which the company said documents increasingly sophisticated misuse attempts on its platform, including attempts it assessed could support biological weapons development.
That report, covering activity Anthropic said it disrupted between December 2025 and August 2026, presents five biological misuse case studies. They include a gain-of-function grant application involving chikungunya virus research intended for a military research institute, blocked by Anthropic’s biological safety classifier in May 2026; a researcher in an unsupported region who spent weeks planning mammalian-adaptation experiments with highly pathogenic avian influenza, with classifiers confining the exchanges to Anthropic’s weakest models; a reseller relay serving more than a dozen customers, through which one customer used Claude Opus 5 to draft a complete orthopoxvirus immune-evasion grant application in about an hour; a state-supported researcher who built an atlas of venom toxin peptides and a generative optimization pipeline spanning analgesic and paralytic targets; and a researcher who computationally redesigned toxins under a national research program while directing Claude to keep the agents’ identities deliberately vague in progress reports.
Anthropic said it withheld the names of the institutions, countries, and biological agents involved, and does not assert that the scientists intended harm. In the same report, the company said a 30-day sweep of activity associated with adversarial state institutions identified roughly 35 distinct research efforts, most of them ordinary civilian science but some with notable dual-use potential. It concluded that classifiers cannot simultaneously enable benefit and prevent harm in highly technical dual-use areas, and that trusted user programs with verification and data retention are the necessary way to serve frontier biological capabilities.
Availability and Enrollment
At launch, LSVP is available in Anthropic’s first-party console for API usage and in Claude for Enterprise and Team plans, but not on third-party platforms. As a beta, it is also unavailable to organizations with a business associate agreement enabled, so customers holding protected health information should use separate non-BAA organizations. In the API and Claude Science, users can switch between grants natively; in Claude.ai and Claude Code, only a preselected default grant applies initially, except when Claude Code is used with API authentication.
Anthropic said it expects to enroll hundreds of organizations within the first week and to scale the program to support the majority of the life science community in the coming weeks. Statements published with the announcement from Xaira, Edison, and Manifold Bio described their planned use: Xaira said it will apply Anthropic’s frontier models across its drug discovery engine, Edison said the program lets it bring Anthropic’s most intelligent models to the discovery and development of new medicines, and Manifold Bio said it will apply frontier intelligence safely within its engine. Anthropic said it will share more about new products, research collaborations, and program improvements in the coming months.
Credit: Source link


























