On September 17, 2026 Anthropic opened applications for its Life Sciences Verification Program. The short version: a life-science organisation that passes a credentials, security and ethics review can use Anthropic's Mythos, Opus and Sonnet models for biology work that the generally available models refuse, including drug discovery, research biology, clinical development and manufacturing. In return the organisation states what it will use the access for, accepts that its traffic is monitored against that statement, and agrees to act on flags within agreed timeframes.
This post is for the people who have been hitting those refusals: founders, research leads and security officers at biotech companies, pharma teams and academic labs. It is also for anyone in a regulated sector watching how "verified access" to frontier models is being designed, because the same shape appeared twice more this month. Every fact is from Anthropic's announcement, read on September 19, 2026. One disclosure: this blog is written with Anthropic's models, so we describe the programme in its own terms and make no claim about how it compares with anyone else's.
- 01Verification replaces refusal for vetted teams.Applicants are reviewed for research credentials, security standards and ethical oversight. Once verified, a team gets models whose classifiers are more permissive for science tasks. Cyber safeguards and all others stay in place.
- 02Two grants, two renewal clocks.Standard Use covers a whole team and renews yearly. High-risk Use is an add-on for one project, renews every six months, and removes all safeguards that block life-science requests. High-risk on Mythos is limited to a small set of vetted entities for now.
- 03Enforcement moves from the request to the pattern.Instead of rejecting risky requests one at a time, Anthropic monitors programme traffic offline against each organisation's stated use cases. That needs 30 days of retained data, compartmentalised and not used for training.
- 04Not for individuals, third-party platforms or BAA orgs yet.It is in beta for teams and institutions through the first-party API console and Enterprise and Team plans. Organisations handling protected health information need a separate non-BAA org to take part.
01 — The changeWhat changed on September 17
Until this week, the safest assumption for a biology team was that Anthropic's current models would refuse a meaningful share of legitimate work, because the classifiers that block bioweapon assistance cannot tell a vaccine researcher from someone trying to make a virus spread faster. Anthropic says as much in the announcement: the two cases often cannot be separated at the level of a single request. The programme's answer is to move the decision from the request to the organisation. Verify who is asking, record what they say they are doing, then let the work through and watch for drift.
The programme launched in beta with dozens of organisations already onboarded through early access. Applications are now open to the wider life-science community, and Anthropic says it expects to enrol hundreds of organisations in the first week. The named early users are Xaira Therapeutics, Edison Scientific and Manifold Bio, each of which supplied a statement of support in the announcement.
In the LSVP, we are shifting safeguards from real-time blocking, where we reject potentially harmful access at the time of each request, to offline monitoring, which allows us to more clearly identify potential misuse across patterns of behavior.Anthropic, 'Introducing the Life Sciences Verification Program', September 17, 2026
02 — The grantsThe two grant types
Verification is the entry ticket. What a team can actually do is set by the grant it holds. Anthropic's own example is a single researcher with dual-use work holding one Standard Use grant for daily activity and one or more High-risk Use grants that apply only to named projects, such as characterising how one family of viral vectors is recognised by human immune pathways.
| Question | Standard Use | High-risk Use |
|---|---|---|
| Scope | A whole team, for diverse daily workloads | A single research project, as an add-on to Standard Use |
| Renewal | Once a year | Every six months |
| Models today | Mythos 5.1, Opus 5, Sonnet 5, and future models as they launch | Opus 5 and Sonnet 5 available now; Mythos limited to a small set of entities with additional vetting |
| What it unblocks | Refined classifiers that are more permissive for science tasks than the generally available models | Removes all safeguards that block life-science requests; cyber and other safeguards stay |
| Who it fits | Basic science, R&D, manufacturing, clinical development, quality, regulatory, investing and diligence | Work in areas still blocked under Standard Use, with a higher potential for misuse |
Two details in the table matter for planning. The High-risk grant on Mythos, the tier with the loosest safeguards, is not generally available even to verified teams; Anthropic says it is working with the US government on wider availability. And the grant is project-scoped, so a lab with several sensitive programmes will hold several grants on separate six-month clocks.
03 — The mechanismFrom blocking requests to watching patterns
For a non-specialist, the enforcement change is the most important part of the announcement. A generally available model runs a classifier on each request and refuses the ones that look dangerous. That is simple, but it interrupts legitimate work and, as Anthropic notes, serious misuse is usually spread across many requests and sessions so that no single one looks bad. The programme keeps the classifiers for most things but, for life-science content, lets the request through and reviews the organisation's traffic afterwards against the use cases it declared when it applied.
Three threats shaped the design, in Anthropic's list: access compromise, where malware or an account takeover diverts a verified team's access; insider threats, where a rogue or coerced employee misuses it; and agent misuse, where agents working in swarms or over long tasks take dangerous actions nobody intended. The third is the one this blog cares about most, and we have covered how to keep evidence of what an agent did in our post on agent incident logs.
What the organisation commits to in return is specific. Its access is tied to the use cases in its application, described at the level of a job listing with no sensitive detail. If monitoring finds activity outside that scope, Anthropic flags it to the organisation's admins, who must triage and remediate within pre-agreed timeframes. And because pattern review needs history, programme traffic carries 30-day data retention. Anthropic says that data is compartmentalised, cannot be used for training, and cannot be accessed by its own life-sciences research teams.
Anthropic's Enterprise Frontier Safeguards, announced September 1, 2026, addresses the same tension for regulated enterprises by storing monitoring data in infrastructure the customer controls rather than at Anthropic. It rolls out in phases starting later this autumn and is not available today. The life-sciences announcement says Anthropic is working on how the two programmes integrate for organisations that qualify for both; nothing more is promised.
04 — EligibilityWho can apply, and where it works
Teams and institutions
Academic labs, startups, pharma companies and similar organisations that pass a review of research credentials, security standards and ethical research oversight. Individual Pro and Max plans are promised later.
First-party surfaces only
The Anthropic API console, Claude for Enterprise and Team plans, and through them Claude Science, Claude.ai and Claude Code. Not available on third-party cloud platforms yet.
BAA-enabled organisations
As a beta the programme excludes organisations under a Business Associate Agreement. Customers with protected health information must use a separate, non-BAA organisation for programme work.
Switching between grants
In the API and Claude Science a user switches grants natively. In Claude.ai and Claude Code a preselected default grant applies, except in Claude Code with API authentication.
05 — Before applyingThe checklist before you apply
The application asks for high-level use cases, not intellectual property. The harder part is what the programme assumes an organisation already has. Run this list first; every item maps to something the announcement names as a condition or a threat.
- Named research oversight. An ethics or biosafety committee, or an equivalent, that can be described in the application. Verification reviews ethical research oversight explicitly.
- Security standards you can evidence. Account takeover is the first threat Anthropic lists, so expect the review to care about single sign-on, multi-factor authentication and how API keys are held.
- A written scope per team and per project. The use-case statements become the yardstick that monitoring is measured against. Vague scope means either false flags or a grant that does not cover the work.
- An admin who can act on a flag. Remediation within pre-agreed timeframes needs a named owner with the authority to suspend a user or a key.
- A retention decision. Programme traffic is retained for 30 days for monitoring. If your policies forbid that, the programme is not for you until Enterprise Frontier Safeguards arrives and the integration is defined.
- A data boundary for PHI. If any of your work touches protected health information, plan the separate non-BAA organisation now rather than after approval.
- Agent controls. If agents will run under the grant, they need the identity, scoping and logging that let you answer a flag about what an agent did. Our agent identity playbook covers the basics.
06 — The read-acrossThree gated programmes in three weeks
This is the third verified-access programme a frontier lab has published this month, and the three share a shape. On September 1 Anthropic announced Enterprise Frontier Safeguards for regulated enterprises, built with more than 100 customers. On September 17 OpenAI put its legal configuration behind a Trusted Access Program for selected law firms, which we took apart in our post on Astra for Law. The same day, this programme opened for life sciences. Earlier in the month OpenAI's cyber-defence programme set its own eligibility rules, covered in our post on who qualifies, and our census of every vetting programme lists the rest.
We are not predicting anything from three dated announcements. The observation is narrower: in each case the lab verified the organisation, tied access to a stated purpose, and kept the capability out of general availability. For a business in any sensitive field, that means the question to prepare for is no longer "which model can we buy" but "what do we have to be able to show about ourselves". Our AI transformation service helps teams get the governance side ready before the application.
07 — Next stepAccess is now something an organisation earns and keeps
Write the scope and name the owner before you fill in the form
If your team has been working around biology refusals, apply, but do the seven-item checklist first. The programme trades blocking for monitoring, and monitoring is measured against what you declare, so a clear scope and a named admin are what make the grant usable rather than a source of flags. If you need Mythos for high-risk work, plan on Opus 5 and Sonnet 5 for now.