Anthropic Opens Previously Blocked Biology Work to Verified Organizations through LSVP
The Life Sciences Verification Program gives vetted research teams broader Claude access through risk-based grants, offline monitoring, and 30-day traffic retention.

Anthropic is changing how it handles sensitive biology requests: instead of broadly blocking them, it will grant wider access to verified organizations with declared use cases. The Life Sciences Verification Program divides access into team-level Standard Use and project-specific High-risk Use. Applicants must pass credential, security, and ethical-oversight checks while accepting 30-day retention of relevant traffic for offline monitoring.
Best for: Universities, laboratories, biotechnology startups, pharmaceutical companies, and security or compliance teams evaluating AI for scientific work that general classifiers may block.What matters in this announcement
- 01
Standard Use covers most life-sciences work at team level and renews annually; High-risk Use is tied to a specific project and renews every six months.
- 02
LSVP shifts some enforcement from real-time blocking to offline monitoring, requiring 30-day retention of relevant traffic even though Anthropic says it is not used for training.
- 03
The Beta supports the first-party API console, Claude Enterprise, and Team—but not individual plans, third-party platforms, or BAA-enabled organizations.
What was announced — and what still needs checking
Why Anthropic is moving from blocking to verification
Some biology requests are inherently dual use: the same work can support vaccine development or enable harm. Broad keyword-level blocking interrupts legitimate research, while unrestricted access creates obvious risk.
LSVP addresses that tension by verifying an organization first and binding access to declared use cases. Anthropic lists basic science, R&D, supply chain, manufacturing, clinical development, quality assurance, regulatory affairs, investing, and diligence among the covered activities.
Standard Use versus High-risk Use
Standard Use is designed for most daily life-sciences work, can cover an entire team, and renews annually. It currently applies to Mythos 5.1, Opus 5, and Sonnet 5 with classifiers that are more permissive for legitimate scientific work.
High-risk Use is an add-on for work still blocked under Standard Use. It is limited to one research project and renews every six months. Opus 5 and Sonnet 5 are available at this level; Mythos remains restricted to a small set of additionally vetted entities, while safeguards such as cyber classifiers remain in place.
Shared responsibility is not unrestricted access
Applicants must demonstrate research credentials, security standards, and ethical oversight. Anthropic ties access to the submitted scope and monitors for patterns outside it, with a process to alert organization administrators for triage and remediation.
The stated threat model includes account compromise, insider misuse, and unintended dangerous behaviour by agents. Organizations therefore need MFA, least privilege, project separation, audit logs, and an access-suspension playbook rather than relying on model safeguards alone.
The 30-day retention condition
LSVP moves some enforcement from real-time blocking to offline monitoring so that suspicious patterns can be detected across requests and sessions. That design requires Anthropic to retain data associated with LSVP traffic for 30 days.
Anthropic says the data is compartmentalized, cannot be used for model training, and is not accessible to its life-sciences research teams. It is still not Zero Data Retention, so data classification, consent, contract terms, and internal-review permissions must be resolved before real research data is introduced.
Beta availability and material exclusions
Organizations can apply to use LSVP through the first-party API console, Claude Enterprise, and Claude Team. Individual plans and third-party platforms are not yet supported. Grant switching is available in the API and Claude Science, while Claude.ai and Claude Code initially use a preselected default grant.
The Beta is not available to BAA-enabled organizations. Anthropic directs customers with PHI toward a separate non-BAA, non-HIPAA organization; this should not be interpreted as permission to process PHI. Thai organizations should keep patient and identifiable health data outside the Beta unless appropriate legal and contractual conditions become available.
What a Thai research organization should prepare
Before applying, designate project ownership, ethical oversight, account and device standards, allowed data classes, incident response, and a clear separation between Standard Use and High-risk projects.
Use-case descriptions should remain high level and exclude sequences, compounds, protocols, IP, or unpublished study details. Program approval does not replace IRB, IEC, biosafety, or institutional review obligations.
Announcement and source status
Anthropic announced and opened the LSVP Beta on 17 September 2026, initially for teams and institutions. The announcement page does not show a separate modification date.
Before getting started
- Separate Standard Use from project-specific High-risk Use
- Prepare research credentials, security standards, and ethical oversight
- Describe use cases without confidential information or IP
- Assess 30-day retention and internal review permissions
- Do not submit PHI to the non-BAA beta environment
- Define account security, incident triage, and access suspension
Frequently asked questions
Can a Claude Team organization use LSVP?
Team is a supported product surface, but access still requires application and verification.
Does LSVP provide zero data retention?
No. Relevant traffic is retained for 30 days for offline monitoring.
Can it be used with PHI?
The beta does not support BAA-enabled organizations and the announced separate organization is non-HIPAA, so PHI should not be introduced.
Sources used for verification
Vendor facts are separated from TechTouch guidance. Features, pricing, and commercial terms may change, so confirm the latest information at the time of purchase.