Anthropic launched the Life Sciences Verification Program on September 17, 2026. The beta program gives verified teams and institutions access to Claude Mythos, Opus, and Sonnet models with biology safeguards refined for legitimate scientific work that generally available models may block.
The program is designed for areas including drug discovery, research biology, clinical development, manufacturing, quality assurance, regulatory affairs, and diligence. It does not create unrestricted general access. Applicants are reviewed, access is tied to approved use cases, and Anthropic monitors activity for behaviour outside the declared scope.
Source note: This guide reflects Anthropic’s official announcement available on September 17, 2026. The Life Sciences Verification Program is in beta; availability, supported plans, model access, verification requirements, safeguards, monitoring, and retention rules may change. Organizations should complete their own scientific, legal, privacy, security, and regulatory review.
Claude Life Sciences Verification Program at a glance
| Detail | Standard Use | High-risk Use |
|---|---|---|
| Intended scope | Most legitimate life-science workflows | Specific projects blocked under Standard Use |
| Access level | More permissive biology classifiers | Removes safeguards that block life-science requests for the approved project |
| Assignment | Can cover an approved team | Applies to one research project |
| Renewal | Annual | Every six months |
| Models at launch | Mythos 5.1, Opus 5, and Sonnet 5 | Opus 5 and Sonnet 5; Mythos access initially limited to a small set of additionally vetted entities |
| Other safeguards | Remain active | Remain active, including cyber classifiers |
| Monitoring | Activity evaluated against approved use cases | Activity evaluated against the narrowly approved project scope |
Both access types depend on verification. High-risk Use is not a shortcut around organizational controls; it increases the need for clear project boundaries, account security, logging, review, and incident response.
What is the Life Sciences Verification Program?
The Life Sciences Verification Program, or LSVP, is Anthropic’s controlled-access pathway for professional biology and life-science work. It aims to reduce false blocks for legitimate researchers while preserving accountability for capabilities that may have dual-use risk.
Anthropic says it had already onboarded dozens of organizations through early access before opening beta applications to the wider life-science community. The initial program is for teams and institutions. The company plans to expand access to individual Pro and Max plans over time, but those individual plans are not included at launch.
The program can be used through Anthropic’s first-party API console, Claude Enterprise and Team plans, Claude Science, Claude.ai, and Claude Code, subject to the selected grant and product limitations. It is not initially available through third-party platforms.
Who can apply for verified Claude life-science access?
Anthropic describes the program as suitable for credible life-science organizations such as academic laboratories, biotechnology startups, pharmaceutical companies, and related research institutions.
The verification process reviews:
- research credentials and organizational legitimacy;
- security standards and access controls;
- ethical research oversight;
- the intended team or project use case;
- the level of capability required;
- the organization’s ability to identify and respond to misuse.
Approval should not be treated as a replacement for an organization’s own governance. A research institution still needs to determine what data may be used, who can access the models, how outputs are validated, which experiments require specialist review, and what actions an AI system may never take autonomously.
How Standard Use works
Standard Use is the broader team-level grant for most life-science work. Anthropic says it supports daily activities across basic science, research and development, supply chain and manufacturing, clinical development, quality assurance, regulatory affairs, investment, and diligence.
At launch, Standard Use applies to Claude Mythos 5.1, Opus 5, and Sonnet 5, with the intent that future models can be added as they launch. Grants renew annually.
The key change is a refined classifier policy that permits more legitimate biology work than generally available models. It does not remove every safeguard, and it does not guarantee that every scientific request, result, or workflow is valid.
How High-risk Use differs
High-risk Use is an additional, project-specific grant for approved work that remains blocked under Standard Use. Anthropic says it removes safeguards that block life-science requests for that one approved project.
The scope is deliberately narrower. A researcher may have one Standard Use grant for ordinary work and separate High-risk grants for specific dual-use projects. High-risk grants renew every six months and require additional vetting.
At launch, High-risk Use is available for Claude Opus 5 and Sonnet 5. Anthropic says it is working with the US government on broader Mythos access, while Mythos High-risk grants initially remain limited to a small set of entities with additional review.
Other safeguards remain. Anthropic explicitly says cyber classifiers continue to apply, even when an approved High-risk project receives more permissive biology access.
Why Anthropic uses monitoring instead of only real-time blocking
Anthropic says legitimate and malicious biological requests can look similar when evaluated one prompt at a time. Research on a viral pathogen, for example, may support vaccine development or harmful misuse depending on the actor, context, and sequence of activity.
The company identifies three threat areas:
- Access compromise: malware or account takeover diverts access to a bad actor;
- Insider threats: a rogue or coerced employee misuses approved access;
- Agent misuse: long-running agents or agent groups take unintended dangerous actions.
LSVP therefore shifts some enforcement from real-time request blocking to offline monitoring across activity patterns. Anthropic says access is connected to the use cases described in each grant and traffic is monitored for behaviour outside that safe scope.
This approach may reduce interruptions for legitimate work, but it creates an important data-governance tradeoff. Anthropic requires 30-day retention for LSVP traffic so flagged patterns can be reviewed. It says that data is compartmentalized, is not used for model training, and is not available to Anthropic’s life-science research teams.
Organizations should confirm that this retention and monitoring model is acceptable for their contracts, intellectual property, research protocols, data classifications, and jurisdiction before enabling access.
Important limitations at launch
The beta has several boundaries that research teams should understand before applying.
It is not currently for BAA-enabled organizations
Anthropic says LSVP is not available for BAA-enabled organizations during beta. It specifically advises customers with protected health information to use separate non-BAA organizations with non-HIPAA data.
That statement should not be interpreted as permission to move sensitive information into an unregulated environment. Teams working with health data should involve privacy, security, legal, and compliance owners and keep protected data outside the beta unless an appropriate approved pathway exists.
Grant switching differs by product
Anthropic says users can switch grants inside the API and Claude Science. In Claude.ai and Claude Code, a preselected default grant initially applies, except when Claude Code uses API authentication.
If one user works across several projects, the organization should make the active grant visible and verify it before each sensitive workflow. A default selected for convenience can become a scope error when the user changes projects.
Scientific outputs still require validation
More capable access does not make Claude a laboratory authority, clinician, biosafety committee, or regulatory reviewer. Outputs may contain errors, unsupported assumptions, or incomplete evidence. Use qualified human review, reproducible methods, validated tools, and documented acceptance criteria.
A responsible implementation checklist
Before granting LSVP access, establish controls that match the scientific and dual-use risk.
Define the approved scope
Document the team, project, research objective, data classes, models, tools, environments, and prohibited uses. Connect each account and grant to one accountable owner.
Protect the account and environment
Require phishing-resistant authentication where possible, managed devices, least-privilege roles, session controls, credential rotation, and rapid removal of access when a person’s role changes.
Separate analysis from action
Generating a hypothesis is different from modifying a laboratory protocol, controlling equipment, ordering materials, changing manufacturing parameters, or releasing a result. Require explicit human approval before a model crosses into consequential action.
Constrain agents and connected tools
Long-running agents should have bounded objectives, restricted tools, spending and time limits, traceable actions, and a reliable stop mechanism. Treat external documents, websites, messages, and tool output as untrusted data rather than instructions.
Monitor and rehearse response
Review unusual activity, failed safeguards, access anomalies, out-of-scope requests, and unexpected tool actions. Test how the organization suspends a grant, preserves evidence, investigates an incident, and notifies Anthropic or relevant authorities.
Validate the scientific outcome
Record sources, assumptions, model and grant selection, tool calls, reviewer decisions, experiments, and the evidence supporting the final conclusion. The accepted scientific result—not the model’s fluency—is the completion criterion.
How I can help design a controlled AI research workflow
I provide AI consulting and custom development for organizations evaluating model access, permissions, data boundaries, tool-enabled agents, monitoring, and human review.
I can also build the surrounding system through workflow automation, SaaS product engineering, website development, and mobile app development. The XReporter operations and reporting system illustrates how structured information, accountable workflows, and reporting can be combined.
Book a free strategy call to map one AI-assisted research or operational workflow, its data boundaries, approvals, monitoring, and measurable acceptance criteria.
Official source
Frequently asked questions
What is Anthropic's Life Sciences Verification Program?
The Life Sciences Verification Program is a beta access program for verified life-science teams and institutions. It provides Claude Mythos, Opus, and Sonnet models with biology safeguards refined to permit legitimate research and development work that generally available models may block.
Who can apply for the Life Sciences Verification Program?
Anthropic says academic labs, startups, pharmaceutical companies, and other credible life-science teams and institutions can apply. Verification reviews research credentials, security standards, ethical oversight, and the intended use before access is granted.
What is the difference between Standard Use and High-risk Use?
Standard Use supports broad team-level life-science work and renews annually. High-risk Use is a project-specific add-on for work blocked under Standard Use, removes life-science request safeguards for that project, requires more vetting, and must be renewed every six months.
Does the program remove every Claude safeguard?
No. Even High-risk Use changes life-science safeguards only for an approved project. Anthropic says other protections, including cyber classifiers, remain in place, and access is monitored against the use cases approved in the grant.
Can organizations use protected health information in the beta?
Anthropic says the beta is not available for BAA-enabled organizations. Customers working with protected health information should not assume the program is HIPAA-ready and should obtain appropriate legal, security, privacy, and vendor guidance before using sensitive data.
