AI & Automation

Claude Loosens Biology Guardrails—but Researchers Must Pass Verification

|Author: QUASA Editorial Team|5 min read| 5
Claude Loosens Biology Guardrails—but Researchers Must Pass Verification

On September 17, 2026, Anthropic opened applications for the Life Sciences Verification Program, a beta that gives verified teams access to Mythos, Opus and Sonnet with biology safeguards more permissive than those on generally available Fable models. Anthropic’s September 17 launch post limits the initial rollout to teams and institutions whose research credentials, security standards and ethical oversight pass review.

This is a controlled route around biology-related refusals, not a general suspension of Claude’s safety systems. AI Watch’s September 18 coverage independently records that Standard Use applies to Mythos 5.1, Opus 5 and Sonnet 5 and renews annually, while High-risk Use renews every six months.

Which blocked biology tasks become available

The program targets legitimate professional work that Claude may otherwise refuse because the same technical knowledge could support harmful activity. The permitted fields include drug discovery, research biology, clinical development, manufacturing, basic science, quality assurance, regulatory affairs, supply-chain work, and scientific or investment diligence.

Approval is tied to declared use cases rather than an exhaustive public list of allowable prompts. Applicants provide high-level descriptions comparable to a job listing and are instructed not to include sensitive intellectual property. A grant therefore authorizes work within an approved scope; it does not create unrestricted biology access for every member of an organization.

Some work remains blocked under Standard Use and requires a project-specific High-risk grant. The published example involves characterizing how a particular family of viral vectors is recognized by human immune pathways. Even at that level, safeguards outside the life-sciences layer, including cyber classifiers, remain active.

Standard and High-risk grants have different boundaries

Standard Use is the broader organizational authorization. It can extend across an approved team and cover varied daily workloads, including most biology research and development activity supported by the program.

High-risk Use is an add-on for one research project whose work would still encounter life-science request blocks under Standard Use. It requires additional vetting and removes those biology-specific blocks only within the approved project scope. A researcher may consequently have general access through a team’s Standard grant while participating in separately authorized High-risk projects.

High-risk access is not uniform across models. Opus and Sonnet are included, while High-risk Mythos access remains limited to a small set of additionally vetted entities as work continues with the US government on broader availability. Standard access to Mythos is not subject to that project-level restriction.

The safeguard model also changes after approval. Instead of relying only on real-time refusals, the program uses offline monitoring across requests and sessions to identify activity outside the use cases declared by the organization. Suspected unauthorized activity can be flagged to administrators, and associated traffic is subject to a mandatory retention window; retained material is compartmentalized, excluded from model training and unavailable to life-sciences research teams.

Eligibility and access matrix

The main qualification and product restrictions can be consolidated as follows:

  • Applicant type: teams and institutions, including academic laboratories, startups and pharmaceutical companies. Individual Pro and Max accounts are excluded from the initial beta.
  • Verification evidence: research credentials, organizational security standards and ethical research oversight. No public scoring threshold, approval rate or guaranteed review timetable has been published.
  • Permitted work: professional life-science activity within the use cases declared in the approved application. Work blocked at the Standard level needs a separately reviewed High-risk grant.
  • Authorization scope: Standard Use may cover a team and varied workloads; High-risk Use is confined to a single research project.
  • Product surfaces: grants can operate through Claude Science, Claude.ai, Claude Code and the API. At launch, organizational availability is limited to Anthropic’s first-party API console and Claude Enterprise and Team plans; third-party platforms are not supported.
  • Grant selection: the API and Claude Science allow native switching between grants. Claude.ai and Claude Code initially apply a preselected default grant, except when Claude Code uses API authentication.
  • Renewal: Standard approval is renewed annually, while each High-risk project is renewed every six months.
  • PHI constraint: the beta is unavailable inside BAA-enabled organizations, and the separate LSVP environment is not presented as HIPAA-ready access for protected health information.

These boundaries mean approval does not make every Claude surface interchangeable. A team holding both grant types can select the relevant authorization in the API or Claude Science, but the same choice is not initially available in a normally authenticated Claude.ai or Claude Code session.

Why individuals and BAA-enabled organizations remain outside the beta

Individual access does not fit the initial operating model, which relies on organizational verification, accountable administrators and agreed procedures for investigating suspected activity outside an approved scope. Expansion to Pro and Max plans is planned, but no date or final verification process for individuals has been published.

BAA-enabled organizations face a different data-governance boundary. The beta requires customers handling PHI to keep eligible non-PHI research in a separate non-BAA organization. That distinction aligns with Anthropic’s current BAA guidance, under which coverage attaches only to the organization that accepts the agreement and remains subject to service and configuration limits.

An LSVP grant therefore should not be treated as extending HIPAA coverage to the separate research organization or as permission to place PHI there. Organizations unable to separate non-PHI research from BAA-covered workloads remain outside the beta’s supported configuration.

Applications are open, but the program remains a vetted organizational beta on Anthropic’s first-party surfaces. The unresolved points are when individual plans, BAA-enabled organizations and third-party platforms may qualify, and when High-risk Mythos access and grant switching will become more broadly available.

Also read:

Share:

Subscribe to our newsletter

Get the latest Web3, AI, and crypto news delivered straight to your inbox.

0