AI Codex
Administrationupdate

The Life Sciences Verification Program: how verified biology teams get Claude to stop refusing their work

In brief

On September 17, 2026 Anthropic opened a verification program for life sciences teams on Team and Enterprise plans. Verified teams get Mythos 5.1, Opus 5, and Sonnet 5 with biology safeguards relaxed, or removed entirely for a single approved project. The trade is 30-day data retention and monitoring of usage patterns. Here is who should apply, which grant to ask for, and what to settle internally first.

8 min read·AI Safety

Contents

Sign in to save

If your organization does drug discovery, research biology, clinical development, or biomanufacturing, you have probably watched Claude decline a request that was routine for your scientists. That is deliberate. Anthropic's generally available models carry safeguards that block some biology requests, because the same knowledge that speeds up a vaccine program can help someone build a pathogen. The model cannot tell a pharma chemist from anyone else, so it blocks the category.

On September 17, 2026 Anthropic launched the Life Sciences Verification Program, in beta. It moves the decision from the individual request to the organization: Anthropic verifies your team once, and your team gets models with those safeguards relaxed or removed.

What you get

There are two grants.

Standard Use grant High-Risk Use grant
Scope Your team One research project
Renewal Annual Every six months
Covers Most life sciences work: basic science, R&D, supply chain, clinical development, quality assurance, regulatory affairs, investment diligence Work that needs everything unblocked
Biology safeguards Relaxed All life sciences blocks removed
Models Mythos 5.1, Opus 5, Sonnet 5 Opus 5 and Sonnet 5 now; Mythos limited to a small set of additionally vetted entities

Two things stay the same under both grants. Other safeguards, such as the cyber classifiers, remain in place: this program is about biology only. And the Fable models are not part of it. Your scientists will need to pick Mythos, Opus, or Sonnet explicitly to get the relaxed behavior.

The models are available through claude.ai, Claude Science, Claude Code, and the API.

Who can apply

Academic labs, startups, and pharma companies are all in scope. Verification reviews three things: research credentials, security standards, and ethical research oversight. For a university lab that likely means your institution's biosafety committee and IRB paperwork. For a company, it means documenting who approves research directions and how access to sensitive work is controlled. Anthropic has not published how long verification takes.

Current limits:

  • Team and Enterprise plans only. Individual plans are listed as coming later.
  • Direct from Anthropic only. Not yet available through Bedrock, Google Cloud, or other third-party platforms. If your organization buys Claude through a cloud marketplace, you would need a direct account for this work.
  • Not for BAA-enabled organizations. A BAA (business associate agreement) is what lets a US healthcare organization put patient health information into Claude. If yours has one, you would need a separate, non-BAA Claude organization for verified work, and that organization cannot hold patient data.

Apply through Anthropic's application form.

The trade: retention and monitoring

The program replaces request-by-request blocking with monitoring after the fact. Anthropic looks for misuse across patterns of behavior instead of refusing individual prompts. That requires keeping data for 30 days.

Anthropic says the retained data is compartmentalized: it cannot be used for model training, and Anthropic's own life sciences research teams cannot access it. When monitoring flags something, Anthropic tells your organization's admins, who are expected to act within timeframes you agree in advance.

That last point is the one to plan for. Joining the program makes someone at your organization responsible for triaging incidents on a clock. Decide who that is before you apply.

If your organization already runs zero data retention as policy, 30-day retention for this workload is an exception your security and legal teams have to approve. Put that on the agenda early. It is the step most likely to stall an application.

Which grant to ask for

Start with Standard. It covers the day-to-day work most teams actually get refused on: literature synthesis that touches pathogen biology, assay design, regulatory writing about a biologic, manufacturing process questions. It covers the whole team and renews yearly.

Apply for High-Risk only for a named project where Standard still blocks work you need, such as specific gain-of-function-adjacent research approved by your biosafety committee. It is scoped to that project, renews every six months, and on Mythos it is limited for now.

Before you apply: a short internal checklist

  1. Collect the refusals. Ask two or three scientists to log every blocked request for two weeks, with the task they were trying to do. This tells you whether Standard is enough and gives you evidence for the application.
  2. Name an incident owner who will receive flags from Anthropic and respond within the agreed window.
  3. Get the 30-day retention exception approved by security and legal if you run zero retention elsewhere.
  4. Check how you buy Claude. Direct Team or Enterprise account, no BAA on that organization.
  5. Decide who gets access. A Standard grant covers the team; that team should be defined by your research oversight process, not by whoever asks.
  6. Update your model guidance. Tell verified users to select Mythos, Opus, or Sonnet for this work. A scientist who stays on the default Fable model will keep hitting the old blocks and conclude the program does not work.

Why this matters beyond biology

This is the second domain where Anthropic has moved to verified access. The same pattern appeared for cybersecurity with Mythos: capabilities that are withheld by default, released to vetted organizations with monitoring attached. Expect more of it. For administrators, the practical lesson is that "the model refused" increasingly has two possible answers — rephrase the request, or verify the organization — and the second requires paperwork, an owner, and a retention decision. Knowing which one applies saves your users weeks of frustration.

For how refusals show up on the flagship model and why, see Claude Fable 5.

Weekly brief

For people actually using Claude at work.

Each week: one thing Claude can do in your work that most people haven't figured out yet — plus the failure modes to avoid. No tutorials. No hype.

No spam. Unsubscribe anytime.

What to read next

Picked for where you are now

All articles →