Logo
FrontierNews.ai

Anthropic Opens Claude Mythos to Drug Researchers, But Keeps the Tightest Controls for Bioweapon Defense

Anthropic has officially opened its most powerful Claude models to drug researchers and biotech companies through a new Life Sciences Verification Program (LSVP), marking the first time the company has allowed public access to capabilities previously locked behind safety guardrails. The program, which entered beta on September 17, 2026, creates a two-tier system where vetted institutions can unlock drug discovery, clinical development, and manufacturing functions on Claude Mythos 5.1, Opus 5, and Sonnet 5 models. However, the company is taking an unusual approach to safety: instead of blocking capabilities outright, Anthropic is monitoring how researchers actually use the models after granting access.

Why Is Anthropic Restricting Access to Its Most Powerful Models?

The decision to create LSVP came directly from a threat intelligence report Anthropic released simultaneously with the program announcement. Between December 2025 and August 2026, Anthropic recorded approximately 35 independent research activities from hostile state-affiliated institutions attempting to misuse AI for biological purposes. The company detailed five representative cases of biological misuse in the report, establishing the security rationale for the tiered access structure.

This represents a fundamental shift in how Anthropic thinks about AI safety. Rather than using real-time classifiers to block requests on a per-query basis, the company is moving toward offline behavioral pattern analysis. The new system examines usage patterns across multiple sessions to identify scenarios like insider misuse, account compromise, and coordinated AI agent activity operating outside authorized tasks. Flagged activity data is retained for 30 days and explicitly kept separate from Anthropic's model training pipeline and internal research teams.

How Does the Two-Tier Authorization System Work?

Anthropic designed LSVP with two distinct permission levels that operate independently, allowing institutions to hold multiple authorizations simultaneously without them interfering with each other.

  • Standard Use Authorization: Available to entire research teams and covers basic research, research and development, supply chain and manufacturing, clinical development, quality assurance, regulatory affairs, and investment due diligence. This tier uses calibrated classifiers more permissive than public-facing models, renews annually, and automatically applies to future new versions of the three approved models.
  • High-Risk Use Authorization: Specific to a single declared research project, valid for six months, and removes all safety guardrails blocking life sciences requests while keeping cybersecurity classifiers active. High-risk access to Opus 5 and Sonnet 5 opened immediately, but high-risk Mythos access remains limited to a small number of institutions that have completed additional government review.
  • Scope Locking Mechanism: Even if a researcher obtains high-risk Mythos access, that authorization applies only within the declared project scope and cannot be laterally extended to other work, preventing mission creep or unauthorized capability expansion.

This design addresses a real problem researchers faced before LSVP. Previously, even legitimate drug discovery work could trigger real-time interception at critical points, such as queries about pathogen mechanisms. Anthropic's automated classifiers would silently route biology, chemistry, or cybersecurity-related requests to less capable Claude Opus models, and users might not even notice the downgrade. LSVP provides a formal channel to bypass this workflow interference while maintaining oversight.

Who Can Access These Models, and What Are the Practical Barriers?

Dozens of institutions had already onboarded during early access, and Anthropic expects to bring in hundreds of organizations within the first week after applications officially opened. Three companies have publicly announced participation: Xaira Therapeutics, Edison Scientific, and Manifold Bio. However, access is not equally available to all researchers.

LSVP is available across API, Claude Science, Claude.ai, Claude Code, and Enterprise or Team plans, but individual Pro and Max plans are not yet included. This means developers who want to embed life sciences capabilities into their products must apply through institutional channels; individual developers are currently excluded. For large pharmaceutical companies and academic institutions with existing compliance infrastructure, LSVP provides certainty through clear authorization boundaries, predictable renewal cycles, and a legal basis for using frontier models in regulatory-sensitive areas.

For biotechnology startups, the annual review system and team coverage of standard use authorization are relatively accessible, but the project-scope locking of high-risk use creates friction. If research direction shifts, a new application is required, and the six-month authorization cycle may create scheduling challenges. Most critically, high-risk Mythos access is currently open only to a very small number of institutions that have completed additional joint government review, a threshold that is nearly unattainable for most startups.

What Role Does the U.S. Government Play in This Architecture?

The U.S. government forms part of the approval chain for high-risk Mythos access, distributing compliance responsibility from a single private company to government agencies and giving the program a stronger legal basis at the regulatory level. This structure naturally favors large research institutions that already have cooperative relationships with federal agencies, further widening the gap between institutions eligible for the high-risk tier and everyone else.

Anthropic's decision to release the threat intelligence report on the same day as LSVP serves a strategic purpose. The narrative structure of "threats first, opening second" tells regulators and the public that Anthropic understands the true scale of biological misuse risk, and that LSVP's tiered design is an evidence-based judgment made on the basis of that understanding. This is the opposite of the usual logic for releasing AI capabilities, which typically emphasizes benefits first and addresses safety concerns secondarily.

What Happens Next for This Program?

The real stress test for LSVP will come after high-risk Mythos access is expanded beyond its current restricted state. At present, very few participants have access to this tier. Once the coordination mechanism with the U.S. government matures and high-risk Mythos is opened to more institutions, whether the offline behavioral monitoring system can truly detect cross-session abuse patterns will become the core metric for judging whether the entire architecture is viable.

If the monitoring system produces false negatives, meaning misuse passes through the 30-day detection window undetected, Anthropic will face not only reputational damage but also a legitimacy challenge to the entire tiered access model itself. The success of LSVP ultimately depends on whether Anthropic's shift from real-time interception to retrospective behavioral analysis can actually prevent the biological misuse scenarios that motivated the program in the first place.