Anthropic opened its Life Sciences Verification Program (LSVP) to beta applicants on Sept. 17, and says it expects to enroll hundreds of organizations in the first week alone. The pitch: vetted biology researchers, drug-discovery teams and manufacturers get access to Mythos, Opus and Sonnet models with safeguards that no longer block a wide swath of legitimate biology work -- research Claude's generally available models currently refuse outright.
Access comes in two tiers. A Standard Use Grant gives a whole team a year of access to models running “refined classifiers” -- still present, just more permissive for tasks like drug discovery, clinical development and manufacturing. A High-risk Use Grant goes further: for a single vetted project, it removes every life-sciences-specific safeguard on Opus 5 and Sonnet 5 (Mythos 5.1 stays restricted, pending coordination with government partners), renewed every six months rather than annually. Cyber-related classifiers and other non-biology protections stay active under both tiers.
What replaces the safeguards Anthropic turns off is not nothing: verified organizations must retain 30 days of their own traffic so Anthropic can look for misuse patterns *after the fact*, rather than blocking requests in real time. Anthropic frames the shift around three specific threat models -- an account whose access has been stolen, an insider misusing legitimate access, and an AI agent acting outside the scope its operator stated -- rather than around re-deciding, prompt by prompt, whether a biology question is inherently dangerous. (Anthropic says this monitoring data is 'strictly compartmentalized' and cannot be used to train future models.)
- Applies with research credentials, security standards and ethics-oversight documentation
- Reviews the application
- Team-wide access, renewed annually, refined but present biology classifiers
- Single-project access, renewed every 6 months, all life-science safeguards removed on Opus 5 and Sonnet 5
- Remains restricted pending government coordination
- Retains 30 days of traffic to flag misuse patterns after the fact
LSVP arrives eight days after a related disclosure. On Sept. 15, Anthropic detailed five cases -- spanning December 2023 through August 2024 -- in which users tried to get Claude's models to help with viral modification, gain-of-function work and toxin redesign, using VPNs and burner accounts to route around existing safeguards. That disclosure split biosecurity researchers. Gigi Gronvall (Johns Hopkins) and Philippa Lentzos (King's College London) called some of the online reaction “overheated” and said the report was still useful evidence for building future oversight. Kristian Andersen (Scripps Research) took a harder line, calling the underlying work “standard basic research” and noting that even routine tasks -- like comparing the genomes of two Ebola strains -- get blocked by the same blanket safeguards. David Gillum (Arizona State University) went further, warning that a company controlling model access this tightly could shape “the production of scientific knowledge itself.”
LSVP reads like a direct response to exactly that complaint: a credentialed virology lab that got blocked comparing two Ebola genomes is the kind of legitimate work a Standard grant's more permissive classifiers are built to let through. Whether it satisfies Gillum's deeper objection -- that a private company, not a regulator or the research community, decides who counts as trustworthy -- is a separate question the program doesn't answer.
The Mythos-family caveat has a recent precedent worth knowing. In June, the US government issued an export-control directive suspending all access -- including for Anthropic's own foreign-national employees -- to Mythos 5 and its extended-safeguards sibling Fable 5, after officials said they'd found a way to jailbreak Fable 5. Anthropic complied but publicly disputed the finding, saying the underlying flaw was a narrow, already-common vulnerability, and that recalling a commercial model over it would “halt industry-wide deployments” if applied evenly across the industry; Washington later lifted the controls. That dispute isn't the same one shaping today's biosecurity carve-out for Mythos 5.1 -- it isn't -- but it explains why Anthropic frames Mythos-family access as something still worked out with government partners, not a decision the company makes alone.
The two access tiers
| Standard Use Grant | High-risk Use Grant | |
|---|---|---|
| Scope | Whole team | Single vetted project |
| Renewal | Annual | Every 6 months |
| Biology safeguards | Refined, more permissive classifiers remain | All life-sciences-specific safeguards removed |
| Models covered | Mythos, Opus and Sonnet | Opus 5 and Sonnet 5 only -- Mythos 5.1 pending |
Anthropic isn't the only lab drawing this line somewhere. OpenAI similarly restricts its own GPT-5.6 Cyber model to approved partners -- but Anthropic's high-risk tier goes further than that comparison suggests, removing every life-sciences-specific safeguard for a vetted project rather than limiting access to one specialized model. Early customers quoted in Anthropic's own announcement -- Xaira Therapeutics, Edison Scientific and Manifold Bio -- each welcomed the trade explicitly: pairing access with accountability, in Manifold's phrasing, rather than access with no oversight at all.
Anthropic hasn't said how many applicants it expects to reject, or on what specific grounds a credential review could fail -- the two numbers that would show whether “vetted” is a meaningful bar or a formality for any lab that fills out the form. The program excludes individual Pro and Max subscribers, HIPAA Business Associate Agreement organizations, and third-party cloud deployments for now -- so the immediate effect is narrow, aimed at institutional labs and companies rather than solo researchers. Pairing access with accountability is Anthropic's own framing for the trade; whether it holds up depends on whether the monitoring side of that pairing ever becomes visible to anyone outside the company.
- Anthropic opened its Life Sciences Verification Program to beta applicants on Sept. 17, 2026.
- Vetted teams get a Standard grant (team-wide, annual) or a High-risk grant (single project, 6-month).
- High-risk grants remove all life-science safeguards on Opus 5 and Sonnet 5, but not Mythos 5.1.
- Real-time request blocking is replaced by 30-day offline monitoring for misuse patterns.
- Caveat: Anthropic alone decides who counts as vetted -- no independent body reviews those calls yet.