Anthropic will stop blocking vetted labs' biology requests in real time and review them offline instead
The High-risk grant takes off every safeguard that blocks a life sciences request, for one named project at a time, renewed every six months.
On September 17, 2026, Anthropic opened the Life Sciences Verification Program, which gives vetted biology teams a Claude with the guardrails set differently. Drug discovery, research biology, clinical development and manufacturing are all work that Anthropic says its generally-available Fable models block today.
Dozens of organizations came through an early access program before this (Anthropic's count, in the post). What caught me is the machinery underneath: the check moves off the moment of the request and onto a review after the fact.
- Program
- Life Sciences Verification Program (LSVP)
- Launched
- Sep 17, 2026, in beta, for teams and institutions
- Models
- Mythos 5.1, Opus 5 and Sonnet 5 today
- Grants
- Standard Use, renewed once a year; High-risk Use, renewed every six months
- Data retention
- 30 days for LSVP traffic
- Expected
- hundreds of organizations within the first week
The two grants
Every applicant goes through "a review of their research credentials, security standards, and ethical research oversight". Come out the other side and a team can apply for either of two grants, through the API, Claude Science, Claude.ai or Claude Code.
Standard Use covers most of the work, runs across a whole team, renews once a year, and carries classifiers Anthropic calls more permissive for science tasks than the ones everybody else gets. High-risk Use is the add-on for work that Standard Use still blocks.
It removes all safeguards that block life sciences requests. This grant applies to a single research project as opposed to a full team, and must be renewed every six months.
The example Anthropic gives of such a project is "characterizing how one specific family of viral vectors is recognized by human immune pathways". High-risk grants cover Opus 5 and Sonnet 5 from today. For Mythos, Anthropic says it is "working with the US government" to widen them, and until that happens they stay with a small set of entities that clear extra vetting.
Blocking, then watching
Serious misuse gets spread across many requests and sessions so the pieces look disconnected, Anthropic says, and that's the thing a real-time block is worst at catching. So the program stops trying.
In the LSVP, we are shifting safeguards from real-time blocking, where we reject potentially harmful access at the time of each request, to offline monitoring, which allows us to more clearly identify potential misuse across patterns of behavior.
Offline review needs something to review, so LSVP traffic is kept for 30 days. Anthropic says that data is "strictly compartmentalized and cannot be used for model training", and that its own life sciences researchers can't reach it either (the cyber classifiers stay on through all of this).
Each organization writes its own account of what safe usage means for its teams, at the level of detail you'd put in a job listing, and Anthropic watches the traffic against it. Anything outside that scope gets flagged to the organization's admins, who have pre-agreed timeframes to triage and remediate. Granted, that hands a fair amount of the enforcement to the customer, and I think it's the trade the whole program rests on.
insider threats and rogue-use have been major factors in significant biosafety incidents and scares
Who can get in
Teams and institutions, for now: the first-party console for API usage, plus Claude for Enterprise and Team. Individual Pro and Max plans aren't supported yet, and neither are third-party platforms or BAA-enabled orgs. Anthropic says it expects to enroll hundreds of organizations within the first week.