ThinkFacility

News

Anthropic will stop blocking vetted labs' biology requests in real time and review them offline instead

The High-risk grant takes off every safeguard that blocks a life sciences request, for one named project at a time, renewed every six months.

On September 17, 2026, Anthropic opened the Life Sciences Verification Program, which gives vetted biology teams a Claude with the guardrails set differently. Drug discovery, research biology, clinical development and manufacturing are all work that Anthropic says its generally-available Fable models block today.

Dozens of organizations came through an early access program before this (Anthropic's count, in the post). What caught me is the machinery underneath: the check moves off the moment of the request and onto a review after the fact.

Program
Life Sciences Verification Program (LSVP)
Launched
Sep 17, 2026, in beta, for teams and institutions
Models
Mythos 5.1, Opus 5 and Sonnet 5 today
Grants
Standard Use, renewed once a year; High-risk Use, renewed every six months
Data retention
30 days for LSVP traffic
Expected
hundreds of organizations within the first week

The two grants

Every applicant goes through "a review of their research credentials, security standards, and ethical research oversight". Come out the other side and a team can apply for either of two grants, through the API, Claude Science, Claude.ai or Claude Code.

Standard Use covers most of the work, runs across a whole team, renews once a year, and carries classifiers Anthropic calls more permissive for science tasks than the ones everybody else gets. High-risk Use is the add-on for work that Standard Use still blocks.

It removes all safeguards that block life sciences requests. This grant applies to a single research project as opposed to a full team, and must be renewed every six months.

From Introducing the Life Sciences Verification Program \ Anthropic

The example Anthropic gives of such a project is "characterizing how one specific family of viral vectors is recognized by human immune pathways". High-risk grants cover Opus 5 and Sonnet 5 from today. For Mythos, Anthropic says it is "working with the US government" to widen them, and until that happens they stay with a small set of entities that clear extra vetting.

Blocking, then watching

Serious misuse gets spread across many requests and sessions so the pieces look disconnected, Anthropic says, and that's the thing a real-time block is worst at catching. So the program stops trying.

In the LSVP, we are shifting safeguards from real-time blocking, where we reject potentially harmful access at the time of each request, to offline monitoring, which allows us to more clearly identify potential misuse across patterns of behavior.

From Introducing the Life Sciences Verification Program \ Anthropic

Offline review needs something to review, so LSVP traffic is kept for 30 days. Anthropic says that data is "strictly compartmentalized and cannot be used for model training", and that its own life sciences researchers can't reach it either (the cyber classifiers stay on through all of this).

Each organization writes its own account of what safe usage means for its teams, at the level of detail you'd put in a job listing, and Anthropic watches the traffic against it. Anything outside that scope gets flagged to the organization's admins, who have pre-agreed timeframes to triage and remediate. Granted, that hands a fair amount of the enforcement to the customer, and I think it's the trade the whole program rests on.

insider threats and rogue-use have been major factors in significant biosafety incidents and scares

Introducing the Life Sciences Verification Program \ Anthropic

Who can get in

Teams and institutions, for now: the first-party console for API usage, plus Claude for Enterprise and Team. Individual Pro and Max plans aren't supported yet, and neither are third-party platforms or BAA-enabled orgs. Anthropic says it expects to enroll hundreds of organizations within the first week.