Enterprise & Security

Life Sciences Verification Program: Anthropic opens the biology blocks for vetted labs

3 min read AI-generated

The vetted organisations decide for themselves what counts as safe use for their teams — written at the level of detail of a job listing, and explicitly without any of their own IP.

Featured image for "Life Sciences Verification Program: Anthropic opens the biology blocks for vetted labs"

Anyone doing serious biology with Claude knows the problem from the wrong end: the safeguards built to stop an attacker also stop vaccine work. Anthropic launched a programme for that today.

Two kinds of grant

The Life Sciences Verification Program, LSVP for short, gives vetted professionals access to Mythos, Opus and Sonnet with classifiers that block far less on biology than the generally available Fable models. It is meant for drug discovery, research biology, clinical development and manufacturing — the work that keeps running into a wall today.

Applicants go through a review of research credentials, security standards and ethical oversight. After that, there are two shapes of grant.

Standard Use covers most of the work, according to Anthropic, applies to whole teams and is renewed once a year. Basic science, supply chain and manufacturing, regulatory affairs, investing and diligence. Today that means Mythos 5.1, Opus 5 and Sonnet 5, plus future models as they land.

High-risk Use is an add-on that removes every life sciences safeguard. It covers a single research project rather than a team, and has to be renewed every six months. Anthropic’s example: working out how one specific family of viral vectors is recognised by human immune pathways. For Opus 5 and Sonnet 5 it is available now. For Mythos it is not — Anthropic says it is working with the US government there, and until then only a small set of additionally vetted entities gets in.

Shared responsibility means the lab defines what is allowed

The interesting half isn’t the access, it’s what you give back. Because Anthropic vets organisations for their scientific credibility, those organisations get to specify for themselves what counts as safe use for their teams and projects. Each grant is tied to the use cases in the application — written at the level of detail of a job listing, explicitly without sensitive information or IP.

Three threat models drive the design: access compromise through malware or account takeover, insider threats from rogue or coerced staff, and agent misuse, especially in swarms or over long-horizon tasks. Anthropic described the last two in its own September threat report.

The price is 30 days

Inside the LSVP, Anthropic shifts enforcement away from blocking at request time and towards offline monitoring. The reasoning: serious misuse spreads across many requests and sessions so that each one looks harmless on its own. Spotting the pattern means being able to look across sessions.

That requires keeping data tied to flagged activity for 30 days. Anthropic says it is strictly compartmentalised, never used for training, and off limits to its own life sciences researchers. When something falls outside the stated scope, the flag goes to the organisation’s admins, with triage and remediation timeframes agreed in advance. Everything else, cyber classifiers included, stays in place.

That Anthropic offers this trade at all fits a week in which virologists pushed back on its own weapons report. The criticism, roughly, was that the company overstates what a model contributes in biology. The LSVP doesn’t answer that with an argument. It answers with an offer: prove who you are, and the blocks come off — while Anthropic watches what happens next.

Sources:

AnthropicSafetyResearchClaude