Anthropic has introduced a Life Sciences Verification Program that gives approved research organisations access to Claude models with safeguards adapted for legitimate biology work. The beta is designed for teams whose drug discovery, research, clinical development or manufacturing tasks can be blocked by the more conservative biology controls used in generally available models.

The program, announced on 17 September and later clarified on 30 September, is initially aimed at institutions and teams. Anthropic says dozens of organisations took part in early access and that it expects to enrol hundreds more. Individual Pro and Max customers are not yet supported, although the company says broader access is planned.

Verification replaces blanket access

Applicants are assessed on their research credentials, security standards and ethical oversight. Once verified, an organisation can seek one of two grants: Standard Use or High-risk Use. The standard category covers most research and development activity, while the higher-risk category is intended for work that needs more permissive access and correspondingly stronger review.

This tiered structure matters because advanced biology support creates a similar problem to cyber capability. Overly broad restrictions can prevent scientists from using AI for valuable work, yet removing safeguards for everyone would increase the chance of misuse. Anthropic’s answer is to qualify users and environments first, then apply controls that are proportionate to the work they have been approved to conduct.

Where researchers can use the grants

Approved teams can use the program through Claude Science, Claude.ai, Claude Code and Anthropic’s API. The initial commercial availability covers API use through Anthropic’s first-party console and Claude Enterprise and Team plans. Third-party cloud platforms are not supported at launch, and organisations handling protected health information should note that the beta is not available in BAA-enabled environments.

Grant switching is built into the API and Claude Science experience. Claude.ai and Claude Code initially apply a preselected default grant, except when Claude Code is authenticated through the API. Anthropic expects most participants to use Standard Use for their routine work and says it will improve portability and switching over time.

Models and data boundaries

The program covers Anthropic’s Mythos, Opus and Sonnet model families with refined classifiers for science tasks. That can enable workflows spanning literature analysis, experimental planning, computational biology, process development and other technical work that might otherwise trigger refusals. Access is still bounded by the grant and the organisation’s approved purpose.

Anthropic says program data is compartmentalised and cannot be used for model training or accessed by members of its life-sciences research teams. It is also exploring how the program could connect with Enterprise Frontier Safeguards, its broader system for giving qualified organisations strong model access alongside privacy and governance controls.

Early users frame the opportunity

The announcement includes support from organisations working in computational biology and medicine, including Xaira Therapeutics, Edison Scientific and Manifold Bio. Their stated interest ranges from analysing biological data and building foundation models to accelerating drug discovery. These examples show why a specialised access path could be valuable: life-sciences teams often combine sensitive data, complex tools and long research cycles that do not fit a generic consumer assistant.

However, verification does not remove the need for scientific validation. Model outputs can still contain errors, omit context or propose impractical experiments. Organisations will need human review, documented approvals, secure data handling and clear boundaries between exploratory work and decisions affecting patients or regulated manufacturing.

A test for capability-based governance

The Life Sciences Verification Program is an important test of whether AI providers can offer differentiated access without creating opaque exceptions. Researchers will want predictable rules and timely approvals; safety teams will need evidence that the controls limit misuse; and customers will need confidence that sensitive intellectual property remains protected.

If Anthropic can meet those requirements, the program could provide a practical middle ground between broad refusal policies and unrestricted frontier-model access. Its value will ultimately be measured by useful research completed, not by enrolment alone, and by whether the company can expand participation while preserving credible oversight.

Prospective participants should begin with a tightly defined research portfolio, name accountable reviewers and record how outputs are checked before they influence laboratory work. They should also separate confidential data by project and test the product’s access controls with ordinary users, administrators and external collaborators. Those operational details will determine whether the new access translates into reliable science.

The beta’s exclusions also matter. Teams working with protected health information cannot assume their existing BAA-enabled environment will cover this program, and individual subscribers cannot join yet. Organisations should avoid moving sensitive work into an unsuitable account merely to obtain access. Waiting for an approved configuration is safer than creating an informal workaround that breaks established privacy or compliance boundaries.

Clear documentation of those limits will be essential as the program grows across more plans and organisations.