i
DATAIST
News · 2026-09-17

Anthropic unblocks biology for vetted labs, logs it for 30 days

@neuronium_ai @neuronium_ai

Anthropic has opened a vetting programme that lets approved life sciences organisations past the safety classifiers that normally refuse biology questions. The Life Sciences Verification Program issues two kinds of grant after a review of an applicant's research credentials, security standards and ethical oversight: Standard Use, which covers a whole team and renews annually, and High-risk Use, which is tied to one research project, renews every six months, and lifts every restriction blocking life sciences requests. The trade underneath it is the real news. For LSVP traffic Anthropic stops refusing in real time and starts watching after the fact.

Cover: Anthropic unblocks biology for vetted labs, logs it for 30 days

Anthropic has opened a vetting programme that lets approved life sciences organisations past the safety classifiers that normally refuse biology questions. The Life Sciences Verification Program issues two kinds of grant after a review of an applicant's research credentials, security standards and ethical oversight: Standard Use, which covers a whole team and renews annually, and High-risk Use, which is tied to one research project, renews every six months, and lifts every restriction blocking life sciences requests. The trade underneath it is the real news. For LSVP traffic Anthropic stops refusing in real time and starts watching after the fact.

Both grant types work across Claude Science, Claude.ai, Claude Code and the API. Standard Use currently covers Mythos 5.1, Opus 5 and Sonnet 5 with updated classifiers that treat scientific queries more leniently than the publicly available models, and Anthropic says it will extend to new models as they ship. The intended scope is deliberately wide: basic science, R&D, supply chain and manufacturing, clinical development, quality control, regulatory work, and investment analysis and project diligence. The company expects it to cover most of what researchers actually need.

High-risk Use is for teams whose work is still blocked at the Standard tier. It is granted per project rather than per team, and the pattern Anthropic describes is a researcher working with dual-use technology holding one Standard Use grant for daily work plus one or more High-risk grants for specific projects. Its own illustration is studying how a particular family of viral vectors is recognised by human immune pathways.

High-risk grants for Claude Opus 5 and Claude Sonnet 5 are live now. For Claude Mythos they are barely live at all: Anthropic says it is working with the US government to widen them, and at launch access is limited to a small number of organisations that cleared additional vetting. That is the sentence to read twice. On the most capable model in the lineup, an outside government sits inside the approval loop, and the announcement does not say what that government's criteria are or who at Anthropic can override them.

The architectural change matters more than the tiering. Serious misuse is usually distributed across many requests and sessions, which makes individual actions look unrelated and lets them slip past a filter judging one prompt at a time. Anthropic's answer is to drop real-time blocking for LSVP traffic in favour of offline monitoring that analyses behavioural patterns across requests. That removes friction for legitimate work, and it creates an obligation: flagged activity has to be retained to be reviewed later. So LSVP traffic carries mandatory 30-day data retention. Anthropic says the data is strictly isolated, cannot be used to train models, and is not accessible to the staff on its own life sciences research teams. For eligible organisations it is also exploring integration with Enterprise Frontier Safeguards.

The governing idea, developed with enterprise CISOs, is shared responsibility. Because organisations are vetted for life sciences competence and oversight, they are allowed to write their own description of safe use for their teams and projects. Access is then bound to the use cases declared in the grant application, LSVP traffic is continuously checked for actions and behavioural patterns outside that declared envelope, and when unauthorised activity appears Anthropic can notify the organisation's administrators to act within pre-agreed investigation and remediation windows. The use case description has to stay generic — Anthropic's comparison is the wording of a job advert — and must not contain confidential information or intellectual property.

The stated justification is that Anthropic's recent threat report found increasingly sophisticated abuse attempts on the platform, including some connected to possible bioweapons development, and that biology often makes benign and malicious work indistinguishable: studying a viral pathogen to build a vaccine looks like deliberately increasing a virus's transmissibility. The company says the most dangerous scenarios are ones where legitimate access is intercepted or redirected, and notes that insider threats and rogue employees have already been significant factors in serious biosecurity incidents. It designed LSVP against three cases: access compromise, where malware or account takeover hands access to an attacker; insider threats, where an employee acts maliciously or under coercion or passes access on; and AI agent misuse, particularly agents working in swarms or on long-running tasks that take unintended dangerous actions.

The honest reading of shared responsibility is that Anthropic has moved part of the liability onto the customer. The organisation writes the safe-use description, the organisation's administrators take the call, the organisation is on the clock to investigate. Anthropic keeps the classifier keys and the logs. That is a defensible design — an institution genuinely does know its own researchers better than a classifier does — but it is also how a model provider converts an unsolvable content-moderation problem into a contractual one. The vetting is real, and so is the offloading.

Notably absent from the announcement is the individual scientist. LSVP is available in Anthropic's own console for API work and in Claude on Enterprise and Team plans. Individual plans are not supported, and third-party platforms are not covered at all. The beta additionally excludes organisations with a BAA enabled, so customers handling PHI are told to run separate organisations without a BAA and without HIPAA — which pushes some of the most clinically grounded users out of the programme they would seem to be built for. The net effect is that relaxed classifiers follow institutional affiliation. The same researcher gets the science model inside a funded company and keeps hitting the same refusals as everyone else working alone. Anthropic says it is working on access for individual users, which is an acknowledgement that the gap is real rather than a fix for it.

Other limits survive the grants, including cybersecurity classifiers. In the API and Claude Science users can switch between grants directly; Claude.ai and Claude Code initially apply only a preselected default grant, with Claude Code the exception when authorised through the API. Anthropic expects most users to need only Standard Use and says it plans to improve LSVP's support and portability later.

The named early participants say what early participants say. Xaira Therapeutics, which describes its work as making biology computable by generating biological data at unprecedented scale and building foundation models of cell, protein and medical biology, expects Anthropic's frontier models to carry that into drug development. Edison Scientific says its job is accelerating research and the discovery and development of new medicines. Manifold Bio, building a scalable parallel interface to living systems meant to let AI design drugs, says it welcomes an approach that couples access with responsibility.

Anthropic expects to onboard hundreds of organisations in the first week and to reach most of the life sciences community in the weeks after. At that scale the 30-day window stops being a technicality. Every unblocked biology query from every vetted lab lands in a retained store that exists precisely because the model was instructed not to refuse, and the safety case now depends on catching weeks later what the system deliberately chose not to stop.