Claude Loosens Biology Blocks—but Flagged Research Data Stays for 30 Days

Anthropic’s September 17, 2026 launch notice opened applications for the beta Life Sciences Verification Program, offering verified teams more permissive Claude biology safeguards while requiring data associated with flagged activity to be retained for 30 days. Applicants face checks covering research credentials, security standards and ethical oversight.
The exchange is fewer interruptions for legitimate biology work in return for tighter organizational accountability. Anthropic shifts part of its enforcement from immediate refusals to offline monitoring against each grant’s approved scope, while cyber controls and other safeguards outside life sciences remain active.
Standard Use or High-risk Use: the access decision
Standard Use is designed for most life-science work. It can cover an entire team and varied daily workloads across basic science, research and development, supply chains, manufacturing, clinical development, quality assurance, regulatory affairs, investing and diligence. Approval is renewed annually.
High-risk Use is a project-specific add-on for work still blocked under Standard Use. It requires additional vetting, applies to a single research project and must be renewed every six months. Within that approved project, it removes safeguards that block life-science requests, but it does not disable cyber classifiers or unrelated safety controls.
- Choose Standard Use when the organization needs broad access for routine work that fits a declared life-science scope.
- Choose High-risk Use when a defined project requires capabilities that remain unavailable under Standard Use.
- Stop at the eligibility check if the deployment depends on an individual plan, a third-party platform or a BAA-enabled organization.
An independent review of the grant structure supports the annual and six-month renewal periods and stresses that program approval is permission to operate within a defined scope, not proof of HIPAA, GxP, FDA, scientific or validation compliance.
Supported models depend on the grant
A Tech Beat summary of the launch terms reports that Standard Use supports Mythos 5.1, Opus 5 and Sonnet 5, while High-risk Use is generally available for Opus 5 and Sonnet 5; High-risk Mythos access remains limited to a small group of additionally vetted entities. Anthropic is working with the US government on broader access to the latter model.
The program can be used through Claude Science, Claude.ai, Claude Code and the API, but enrollment at launch is confined to Anthropic’s first-party API console and Claude for Enterprise and Team plans. Individual Pro and Max subscriptions are excluded, and an approval does not transfer to third-party model platforms.
Grant controls also differ by product surface. The API and Claude Science permit native switching between grants. Claude.ai and Claude Code initially apply one preselected default grant, except when Claude Code is authenticated through the API. A researcher approved for Standard Use and several project grants therefore may not have the same selection options in every interface.
Offline monitoring changes where enforcement happens
The beta does not simply remove biology controls. It moves part of the safety decision from a single request to patterns across requests and sessions, allowing approved work to proceed while looking for activity outside an organization’s declared use case.
Organizations submit high-level descriptions of their intended work without sensitive information or intellectual property. Traffic is then assessed against that scope. Activity considered unauthorized can be flagged to organization administrators, who are responsible for triage and remediation within pre-agreed timeframes.
The program is designed around three broad threat paths: compromised access, malicious or coerced insiders, and agents taking unintended dangerous actions. These scenarios explain why verification alone is insufficient: a legitimate organization can still lose control of an account, an employee or an automated workflow.
Retained information tied to flagged activity is compartmentalized, cannot be used for model training and is unavailable to Anthropic’s life-sciences research teams. The practical tradeoff is therefore narrower real-time blocking but continuing surveillance of approved traffic, backed by mandatory retention when activity is flagged.
PHI is outside the beta boundary
The program is unavailable to organizations operating under a Business Associate Agreement. Customers handling protected health information are directed to use a separate organization that is neither BAA-enabled nor HIPAA-configured for eligible program work.
That requirement makes data separation an eligibility condition, not an optional setting after approval. A life-science institution that cannot reliably prevent PHI from entering the program environment has no supported route into the beta under the published terms. Creating another workspace inside the same BAA-enabled organization does not satisfy the stated separation.
The exclusion also clarifies what verification does not provide. It governs access to more permissive biology capabilities; it does not certify a workflow for healthcare privacy, regulated records or scientific decision-making.
Applications are open, but access remains conditional
The program remains a vetted beta for teams and institutions. Submitting an application does not guarantee acceptance, and the public launch material does not give an approval rate or a review timetable.
Individual access, better grant portability, broader High-risk Mythos availability and support for BAA-enabled organizations remain outside the current launch. Until those terms change, the decisive questions are whether the work fits Standard or project-specific High-risk Use, whether the selected model and product surface support that grant, and whether the organization can accept monitoring, incident-response duties and flagged-data retention without bringing PHI into the environment.
Also read:
Subscribe to our newsletter
Get the latest Web3, AI, and crypto news delivered straight to your inbox.