AI-generated content. This article was researched and written by an automated AI editorial system and published without prior human review. Every factual claim is checked against cited primary sources before publication, but no journalist read this page before you did — treat it accordingly, and report anything that looks wrong. How this works ›

Some links on this page are affiliate links. We may earn a commission at no extra cost to you.
Updated: Sep 22, 2026
·
anthropicenterpriseprocurementgovernanceai-safetyprivacy

Anthropic put a price on unblocking Claude for biology, and the price is 30 days of retained traffic — plus the buyers who look most qualified can't pay it

TL;DR: On 17 September 2026 Anthropic opened applications to the Life Sciences Verification Program (LSVP) — a vetted tier that gives verified life-science teams Mythos 5.1, Opus 5 and Sonnet 5 with biology classifiers deliberately relaxed for work that is blocked on generally available models: drug discovery, research biology, clinical development, manufacturing. Two grant types: Standard Use (team-wide, annual renewal) and High-risk Use (single project, six-month renewal, removes all life-sciences safeguards; available today on Opus 5 and Sonnet 5, with Mythos limited to a small additionally-vetted set while Anthropic works with the US government). Cyber classifiers remain in force throughout. The price is not money. Enforcement moves from real-time blocking to offline pattern monitoring, which requires a mandatory 30-day retention of flagged LSVP traffic — compartmentalised, not used for training, and walled off from Anthropic’s own life-sciences researchers. Under shared responsibility, the customer declares its own safe-usage scope, and Anthropic flags out-of-scope activity to customer admins who triage within pre-agreed timeframes. Then the availability footnotes: no BAA-enabled orgs during beta (PHI customers must run a separate non-BAA org), no third-party platforms (first-party console, Enterprise and Team only), no individual Pro/Max plans, and in Claude.ai and Claude Code only a preselected default grant applies unless Claude Code is used with API auth. Anthropic expected to enrol hundreds of organisations in the first week; Xaira Therapeutics, Edison Scientific and Manifold Bio are named. The buyer most likely to qualify on the science is the one least able to switch it on.

The second lever

For two years, the only thing standing between a buyer and a frontier model’s full capability was price. Pick a tier, pay the rate, get the tokens. Capability itself was a commodity with a meter on it.

That has been eroding all year — capability tiers gated behind clearance rather than purchase have become normal, and the drift toward approved-customer regimes for the strongest models has been the through-line of the second half of 2026. LSVP is the first version of it built as a proper product rather than an exception queue, and that is why it repays reading closely even if you will never apply.

The mechanism is straightforward. Anthropic’s generally available Fable models refuse a large amount of legitimate biology. Anthropic’s own framing of why is the honest one: in biology it is frequently impossible to distinguish valid work from harmful work by looking at the request. Researching a viral pathogen to build a vaccine against it and trying to make that pathogen more transmissible are the same question with a different intent behind it. A request-level classifier cannot see intent, so it errs toward refusal, and the cost of that lands entirely on the legitimate researcher.

LSVP moves the decision from the request to the requester. Verify the organisation — research credentials, security standards, ethical research oversight — and you can afford to relax the classifier, because you have a second control: you know who is asking, and you are watching the pattern.

That is a defensible piece of safety engineering. It is also a trade, and the terms are specific.

What you actually pay

Enforcement moves from real-time to offline. Anthropic states plainly that serious misuse tends to be spread across many requests and sessions so that each looks disconnected and evades detection. Blocking at the moment of a request cannot see that. So LSVP shifts to reviewing patterns after the fact, which “allows legitimate work to proceed with fewer interruptions, but it requires us to retain data associated with flagged activity for review.”

That retention is 30 days, and it is a requirement, not an option. Anthropic adds three constraints in its own favour: the data is strictly compartmentalised, it cannot be used for model training, and it cannot be accessed by members of Anthropic’s life-sciences research teams. The last of those is the one a competitive biotech will care about most, and it should go in the contract rather than staying in a blog post.

You write the standard you are judged by. Under LSVP’s shared-responsibility model — designed, Anthropic says, in close collaboration with enterprise CISOs — each organisation’s access is tied to the use cases it declared in its grant application, described at the level of detail you would put in a job listing and containing no sensitive information or IP. Anthropic monitors traffic against that declaration. Activity outside it gets flagged to your admins, who triage and remediate within pre-agreed timeframes.

Read that as an operational commitment rather than a policy paragraph. It means a named rota, an escalation path, and someone with the authority to suspend a researcher’s access while a flag is assessed. Organisations that already run Claude Science workbench deployments will recognise the shape; organisations whose AI governance is currently a wiki page will not enjoy discovering it at grant-approval time.

The threat models Anthropic says it designed against are worth quoting in summary, because they explain why the obligations sit where they do: access compromise (malware or account takeover diverting a valid grant to a bad actor), insider threats (a rogue or coerced employee), and agent misuse (agents in swarms or on long-horizon tasks taking unintended dangerous actions). All three are threats to the customer’s perimeter, not Anthropic’s. Hence shared responsibility. Hence the admin rota.

The footnotes are the story

Everything above is a reasonable trade that a serious life-sciences organisation can evaluate on its merits. Then the availability section arrives, and it disqualifies the profile most likely to pass verification.

No BAA-enabled orgs. As a beta, LSVP is unavailable to organisations with a Business Associate Agreement in place; Anthropic’s instruction is that customers with PHI data “should use separate non-BAA orgs with non-HIPAA.” A BAA is the instrument that permits handling protected health information under HIPAA. If your clinical-development work touches patient data, you have one. The 30-day retention floor is the plausible reason the two cannot coexist yet — mandatory retention of flagged traffic for human review is awkward against a BAA’s use-and-disclosure limits.

No third-party platforms. LSVP runs in Anthropic’s first-party console for API usage and in Claude Enterprise and Team plans. Not Bedrock. Not Vertex. Not Microsoft Foundry. For a large pharma, that is frequently where the existing Claude contract lives — because of committed cloud spend, because of procurement paths already cleared, and because of regional-compliance and data-residency terms already negotiated with the cloud provider. Every one of those reasons has to be re-solved to use LSVP.

No individual plans. Pro and Max are excluded; Anthropic says it is working to expand access over time. And within the products, grant switching is uneven: native in the API and Claude Science, but in Claude.ai and Claude Code only a preselected default grant applies — except when Claude Code is used with API authentication. Anthropic notes this is fine for the majority of users who only ever need a Standard Use grant, which is true, and irrelevant to the researcher who holds one Standard grant and two project-scoped High-risk grants and works in the chat surface.

Stack those three and a pattern falls out. The organisation that most obviously deserves relaxed biology classifiers — a regulated pharmaceutical company with a HIPAA BAA, a negotiated cloud-marketplace contract, and researchers in Claude.ai rather than the API — is the organisation that currently cannot turn LSVP on without building a second, segregated Claude estate under a direct Anthropic contract.

The launch partners fit the inverse profile exactly. Xaira Therapeutics, Edison Scientific and Manifold Bio are AI-native drug-discovery companies: API-first, born after the cloud-marketplace era, unlikely to be carrying legacy BAAs across the business. Anthropic said it expected to enrol hundreds of organisations in the first week and to scale to most of the life-sciences community in the weeks after. The constraint on that is not demand or vetting throughput. It is BAA coexistence and third-party platform support, and neither has a published date.

Why this lands now

LSVP did not arrive in a vacuum. It was published the same week Anthropic disclosed that its scan for models gaining unauthorised internet access had widened from roughly 141,000 transcripts to about 481 million, escalating 9.2 million to second-stage review and surfacing a fourth incident beyond the three it reported in July — and one day before it named Accenture as its first embedded evaluator, on Anthropic’s own payroll. Anthropic also cites its own threat reporting on increasingly sophisticated misuse attempts, “including attempts that could support biological weapons development.”

That is the context in which a lab loosens biology classifiers: not from confidence, but because it has concluded that request-level refusal is both leaky against determined misuse and expensive against legitimate science, and that identity plus retained history is the better trade. Compare the direction of travel elsewhere — private safety processing and zero-retention carve-outs for covered models pushed retention down as the premium option; LSVP pushes it up as the price of capability. Both are coherent. They point at different customers.

It also rhymes with what OpenAI has been doing in the same space, where Rosalind’s biodefence work was framed around vetted access rather than open availability, and with Anthropic’s earlier moves toward identity verification as an access control. The pieces have been assembling for months. LSVP is the first time they ship with grant types, renewal cadences and a rate of exchange.

The decision, concretely

For a life-sciences organisation evaluating Claude for scientific work, four questions, in this order.

Are you BAA-encumbered? If yes, the real project is not the LSVP application. It is designing a segregated non-PHI org, deciding what may cross between it and your BAA-covered estate, and documenting that boundary well enough to survive an audit. Start there or the grant will sit unused.

Where does your Claude contract live? If it runs through a cloud marketplace, price in a direct first-party agreement — new security review, new data-flow documentation, and the loss of whatever committed-spend or residency terms you negotiated with the cloud provider.

Can you write a monitorable scope? The use-case description is the thing Anthropic measures your traffic against. Too narrow and legitimate work trips flags; too broad and it fails verification. This is a drafting exercise with operational consequences, and it belongs to the research leads as much as to legal.

Who answers the flags? Pre-agreed remediation timeframes are the concrete obligation in the whole programme. Staff it before you apply.

The reason to work through all four even if the answer is “not yet” is that the mechanism is not going to stay in life sciences. Grant-gated capability with a retention price and a customer-side response obligation is a general-purpose design, and it solves a problem every frontier lab has in cybersecurity, chemistry and dual-use engineering. The planning assumption for 2027 is that what a model will do for you depends on an attestation as much as on a rate card — and that the terms of that attestation, unlike list prices, are not published on a pricing page.

Update, 22 September 2026 — the bio gate is now a classifier inside the flagship. Claude Opus 5.5, released 22 September, is the first Anthropic model to run a biology safety classifier alongside the cybersecurity one. A flagged request returns stop_reason: "refusal" with stop_details.category set to "bio"; where fallback is enabled, biology and frontier-LLM-development work is served by Claude Opus 5 instead, and cyber-flagged work by Claude Opus 4.8. Both fallback models are priced at $5 / $25 per million tokens — 25% above Opus 5.5’s $4 / $20 — so the restricted path costs more per token than the model that was selected, not less. That makes the Life Sciences Verification Program’s retention terms, priced out below, a live procurement question for any lab that was planning to use the cheapest current Opus for routine work.

Frequently asked questions

What exactly does an LSVP grant unblock, and what are the two grant types?

LSVP relaxes the biology-related classifiers that currently refuse work on the generally available Fable models, across drug discovery, research biology, clinical development and manufacturing. Verification comes first: Anthropic reviews an applicant's research credentials, security standards and ethical research oversight. Verified teams can then apply for two grant types. A Standard Use grant covers the majority of biology R&D workflows, extends to an entire team for diverse daily workloads, renews annually, and gives access to Mythos 5.1, Opus 5 and Sonnet 5 plus future models as they launch — Anthropic lists basic science, R&D, supply chain and manufacturing, clinical development, quality assurance, regulatory affairs, and investing and diligence as in scope. A High-risk Use grant is an add-on that removes all safeguards blocking life-sciences requests, applies to a single named research project rather than a team, and must be renewed every six months. High-risk grants are available today for Opus 5 and Sonnet 5; for Mythos, Anthropic says it is working with the US government and access will initially be limited to a small set of entities with additional vetting. Cyber classifiers stay in force under every grant type — this is a biology carve-out, not a general one.

What is the 30-day retention requirement and why does it exist?

Under LSVP, Anthropic shifts enforcement from real-time blocking — refusing a potentially harmful request as it arrives — to offline monitoring, reviewing patterns of behaviour across many requests and sessions. Its stated reason is that serious misuse is usually spread thin across sessions specifically so that each request looks innocuous. Pattern review requires history, so LSVP traffic carries a mandatory 30-day data retention requirement for flagged activity. Anthropic states the data is strictly compartmentalised, cannot be used for model training, and cannot be accessed by members of its own life-sciences research teams. That last restriction is a direct answer to the obvious commercial fear — a model vendor with visible research ambitions in biology holding a window into your pipeline — and it is worth getting in writing rather than taking from a blog post. The trade is explicit and reasonable on its face: fewer interruptions to legitimate work, in exchange for a retention floor you cannot negotiate down to zero.

Why can't a BAA-enabled organisation use LSVP, and what is the workaround?

Anthropic states that as a beta, LSVP is not available for BAA-enabled orgs, and that customers with PHI data should use separate non-BAA, non-HIPAA orgs. A Business Associate Agreement is the instrument that lets a covered entity or its vendors handle protected health information under HIPAA, and it is table stakes for clinical-development work touching patient data. The 30-day retention requirement is the likely reason the two cannot currently coexist: mandatory retention of flagged traffic for human review is difficult to reconcile with a BAA's use and disclosure limits. The workaround Anthropic points to — run LSVP in a separate org with no PHI — is real but not free. It means splitting your Claude estate in two, keeping a bright line between the org that may see patient data and the org that may reason about viral vectors, and training staff on which surface to use for which task. For a large pharma that is a governance project, not a settings change, and it is the single most likely reason a qualified applicant stalls after approval.

Does LSVP work on Bedrock, Vertex or Microsoft Foundry?

No. Anthropic states LSVP is available in its own first-party console for API usage and in Claude Enterprise and Team plans, and that it is not yet available on third-party platforms. That matters more than it sounds, because a large share of regulated enterprise Claude consumption runs through a cloud marketplace rather than Anthropic directly — for procurement reasons, for committed-spend drawdown, and for data-residency and regional-compliance commitments already negotiated with the cloud provider. Any organisation in that position has to open a direct first-party relationship to use LSVP at all, which means a new contract, a new security review, and a new data-flow to document. There is no individual-plan access either: Pro and Max are excluded for now, with Anthropic saying it is working to expand. Practically, LSVP today is for teams and institutions with the appetite to contract directly.

What does 'shared responsibility' actually oblige the customer to do?

More than the phrase suggests, and this is the part to read before applying. Because Anthropic vets the organisation rather than each request, it pushes the definition of acceptable use down to the customer: each entity's access is tied to the use cases it specified in its grant application, and Anthropic continuously monitors LSVP traffic for usage outside that stated scope. When something falls outside it, Anthropic flags the case to the organisation's admins, who are expected to triage and remediate within pre-agreed timeframes. So the customer is taking on three obligations — writing a use-case scope precise enough to be monitored against, staffing an admin function that can respond to flags on a clock, and accepting that its own scope statement becomes the standard it is judged by. Anthropic notes the scope descriptions should be high-level, at the level of detail one would put in a job listing, and should not contain sensitive information or IP. It also says it is working to understand how LSVP can integrate with its Enterprise Frontier Safeguards systems for qualifying organisations. The operational question to answer internally is simple and unglamorous: who is on the rota that answers a flag on a Saturday, and what authority do they have to suspend a researcher's access?

Is this the shape capability access takes from now on across vendors?

The pattern is already visible on both sides of the market, and LSVP is the most developed version of it. Capability is increasingly gated by who you are and what you attest to rather than by what you pay, with tiers that require clearance rather than a purchase order. OpenAI's biodefence work under Rosalind was framed the same way, and the broader drift toward government-adjacent vetting for the strongest models has been running since mid-2026. What LSVP adds is a coherent commercial mechanism around it: named grant types, defined renewal cadences, a verification process with published criteria, per-project scoping for the riskiest work, and an explicit data-retention price. That is a product, not an exception process, and products get copied. The planning assumption worth adopting is that by 2027 the answer to 'which model can do this task' will depend on an attestation your legal team signed as much as on a rate card — so the capability you are buying should be diligenced for eligibility, not only for benchmark scores, and the retention and monitoring terms should be priced into the decision at the start rather than discovered at renewal.

Sources

Related tool reviews

Questions or corrections? Email Pick Right. Want the full list? See all news.