Skip to main content
Back to timeline
AnthropicSource publication:

Life Sciences Verification Program (LSVP): Tiered Access and Offline Monitoring for Life Science Professionals

Synopsis

On September 17, 2026, Anthropic introduced the Life Sciences Verification Program (LSVP), which verifies research credentials, security standards, and ethical research oversight to grant life science teams two types of access—Standard Use and High-risk Use—enabling work such as drug discovery, research biology, clinical development, and manufacturing that is currently blocked in generally-available models, while shifting safeguards from real-time blocking to offline monitoring with a 30-day data retention requirement for LSVP traffic.

AI-generated editorial illustration: Introducing the Life Sciences Verification Program

Interpretation

LSVP establishes a two-tier grant system: Standard Use covers entire teams across basic science, R&D, supply chain and manufacturing, clinical development, quality assurance, regulatory affairs, investing and diligence, and more, renewed annually; High-risk Use is an add-on grant for a single research project that removes all safeguards blocking life sciences requests, renewed every six months. Relative to the prior blocking of life-science-related tasks in generally-available Fable models, the program offers more permissive classifiers after verification and narrows high-risk access from team-level to project-level. The tiers and renewal rules are stated explicitly in the announcement, which notes that high-risk grants are available for Claude Opus 5 and Claude Sonnet 5, while Claude Mythos high-risk grants remain limited to a small set of entities with additional vetting due to work with the US government.

LSVP shifts safeguards from real-time blocking to offline monitoring to identify serious misuse spread across many requests and sessions that appears disconnected to evade detection, and requires 30-day data retention for LSVP traffic to support this monitoring. The announcement states that serious misuse is often spread across many requests and sessions to evade detection, so offline pattern identification allows legitimate work to proceed with fewer interruptions. The announcement specifies a 30-day retention period and states that the data is strictly compartmentalized, cannot be used for model training, and cannot be accessed by members of Anthropic's life sciences research teams.

LSVP is designed around shared responsibility: each entity's access is tied to the use cases specified in its grant applications, LSVP traffic is continuously monitored to identify usage or patterns outside the stated safe scope, and unauthorized activity can be flagged to organization admins to act within pre-agreed timeframes for triaging and remediating incidents. The announcement says the design was developed in close collaboration with enterprise CISOs and, because organizations are vetted for life sciences credibility and oversight, empowers them to specify what constitutes safe usage for their teams or projects. The announcement lists three threat models the safeguards target—access compromise (malware or account takeover), insider threats (rogue or coerced employees), and agent misuse (especially swarms or long-horizon tasks)—and states that other safeguards such as cyber classifiers remain in place.

LSVP launches in beta initially for teams and institutions, with dozens of organizations already onboarded through early access and an expectation to enroll hundreds within the first week; it is available in the first-party console for API usage and in Claude for Enterprise and Team plans, but not yet for individual plans or third-party platforms, and is not available for BAA-enabled orgs. The announcement specifies availability boundaries, including native grant switching in API and Claude Science, while Claude.ai and Claude Code initially apply only a preselected default grant. Availability, plan types, and restrictions are itemized in the announcement, which also includes public statements from Xaira, Edison, and Manifold Bio as industry feedback.

Perspective

The program targets vetted life science teams and institutions, launching in beta in the first-party console for API usage and in Claude for Enterprise and Team plans; it is not available for BAA-enabled orgs, individual plans, or third-party platforms. High-risk grants are available for Claude Opus 5 and Claude Sonnet 5, while Claude Mythos high-risk grants remain limited to a small set of entities with additional vetting due to work with the US government. The announcement states plans to expand to individual Pro and Max plans over time and to improve grant switching and portability.

The announcement does not disclose the specific criteria of the verification process, details of the offline monitoring detection methods, the practical effectiveness of organizational responses after flagging, or the privacy and compliance implications of 30-day data retention in practice; it also mentions collaboration with enterprise CISOs and exploring integration with Enterprise Frontier Safeguards but does not describe the integration approach or timeline.

Sources