Anthropic Is Becoming a Drug Company. It Also Decides Who Else Gets to Be One.
It bought a biotech, signed Lilly and BMS, and diverts most of biology away from its best model.
By Steven Muskal, Ph.D. | July 30, 2026 | stevenmuskal.com
The Sequence
April 3, 2026. Anthropic acquires Coefficient Bio, a stealth biotech founded eight months earlier, for roughly $400 million in stock. The team is fewer than ten people, nearly all former computational drug discovery researchers from Genentech’s Prescient Design, and their platform drafts drug R&D plans, manages clinical regulatory strategy, and proposes new drug candidates. It folds into Anthropic’s healthcare and life sciences division.
April 16, 2026. Anthropic announces a collaboration with Eli Lilly, presented by Dario Amodei alongside Lilly’s chief information and digital officer, covering clinical research and drug development. It follows an earlier partnership with AbbVie.
May 20, 2026. Bristol Myers Squibb announces a strategic agreement with Anthropic, an enterprise deployment spanning research, clinical development, manufacturing, commercial and corporate functions, reported as reaching a workforce of more than 30,000 employees.
June 9, 2026. Fable 5 ships, and with it a routing policy that diverts, in the company’s own words, the “majority of biology, chemistry, and life sciences queries, such as lab methods or molecular mechanisms” away from the most capable model. Not bioweapons queries. The majority of the field.
June 30, 2026. Anthropic announces Claude Science, a research workbench for target identification and lead optimization, and alongside it its own preclinical drug-discovery programs, run in house, reportedly aimed at neglected diseases.
Read that sequence in order and one thing jumps out. The therapeutics commitment came first. Anthropic did not drift into drug discovery after the fact; it spent $400 million in stock on a drug discovery team in April, signed Lilly sixteen days later and Bristol Myers Squibb in May, and only then shipped the model whose safeguards divert most of biology, chemistry and life sciences away from everybody else.
I want to be explicit that this is not a causal claim. I am not asserting that Anthropic broadened its biology filter in order to protect a position, and I have no evidence for that. But the ordering does retire one defense, which is that the drug business is a late afterthought bolted onto a safety posture that was already fixed. It was not an afterthought. It was bought, staffed and announced first.
Narrow, Then the Majority
It is worth being precise about when the breadth arrived, because the chronology is the strongest fact in this story and it is easy to overstate.
Anthropic’s classifier-based CBRN protections date to its ASL-3 activation in May 2025. But the company described those safeguards at the time as narrowly targeted, saying they “should not lead Claude to refuse queries except on a very narrow set of topics.” The policy of broadly diverting the majority of biology, chemistry and life sciences requests appears with Fable 5. So in roughly fourteen months, the company’s own description of what its safeguards touch moved from a very narrow set of topics to the majority of a scientific discipline. That is not an inference. It is Anthropic’s published language in both periods.
And it is not hiding the tradeoff. It drew it.
Anthropic’s own illustration. The band it widened is labeled, in its own key, benign but blocked.
There is a band of requests Anthropic classifies as benign and blocks anyway, to buy confidence about the harmful band further right, and for Fable 5 it made that band deliberately wider: “more benign requests would be blocked, but fewer genuinely harmful requests would be missed.” A tradeoff is a fair thing to make. But a tradeoff has two sides, and only one of them is in the room when the line gets drawn. The cost of a blocked benign request is not paid by Anthropic. It is paid by the chemist, the clinician and the graduate student, who appear in that diagram as a shaded rectangle.
Nobody needs a conspiracy to explain a company being careful about bioweapons, and the ASL-3 lineage argues against one. The weaker claim is the one that survives, and it requires no intent at all. Few organizations have ever combined frontier general-purpose scientific reasoning, unilateral control over its availability, an acquired drug discovery team, a portfolio of incumbent pharmaceutical customers and internal therapeutic programs under one roof. Anthropic now holds all five. There is no published firewall between the group that sets the biology threshold and the group running the drug programs, no outside auditor, and no disclosure of where the internal work sits relative to the line that stops everyone else.
The Canary Is Not the Story
I should say where my own evidence comes from, and then set it aside.
I run a drug discovery informatics company and have for 25 years. These notices appear in my terminal several times a week. The consolation used to be that a block on the top model dropped you a tier and you carried on working. That consolation is now gone: the same “intentionally broad safeguards” language has arrived on the fallback tier, which advises trying a different model. Inside the workflow I selected and pay for, there is no equivalent fallback model left.
That is a canary, not an argument. One flagged practitioner is an anecdote, and any company can point at an anecdote and promise to look into it. What makes it worth publishing is what it indicates about the air in the shaft. If ordinary target biology and molecular mechanism work trips the filter for someone with a Berkeley Ph.D. in biophysical chemistry, four decades in computational biology and a paid enterprise relationship, it is tripping for the graduate student, the twenty-person informatics shop and the biotech that has not raised its B round. Those organizations do not write essays about it. They quietly get less capable answers.
And here the asymmetry matters more than the inconvenience. A broad filter may genuinely reduce some misuse risk, and I am not going to pretend otherwise. But its practical burden is not distributed evenly, and the honest thing to say is that from the outside we cannot see how it is distributed at all.
Anthropic has not published whether a large enterprise agreement carries the same safeguard configuration as the subscription on my laptop. It has separately announced a trusted-access program that removes biology and chemistry safeguards for a small cohort of researchers it has not named. So I do not know whether Eli Lilly or Bristol Myers Squibb work under the same constraints I do. Neither does any other customer, competitor, or regulator. I am not going to assert that they are exempt, because I have no evidence of that, and I am not going to assert that they are not, because I have no evidence of that either. Nobody outside the company can tell. That opacity is not a side issue in this story. It is the story.
What is observable is the difference in what each party can do about it. Alphabet’s Isomorphic Labs, which develops proprietary drug-design models and infrastructure and raised $2.1 billion in May, is building on its own stack rather than renting someone else’s. A pharmaceutical company with tens of thousands of employees has procurement leverage, legal resources, internal infrastructure and a direct line to the vendor, so it is in a position to pursue accommodations, alternative models, or a place in that unnamed cohort. A graduate laboratory or a twenty-person biotech has none of those. Even a rule applied with perfect uniformity lands very differently depending on who you are, and at present no one outside Anthropic can confirm that it is applied uniformly.
Disease Is Not a Two-Company Problem
Here is my real objection, and it is not about my own access. It is about the bet.
There are more than 200 recognized types of cancer, with many molecularly distinct subtypes beneath them. What is clinically labeled Alzheimer’s disease encompasses substantial biological heterogeneity and frequently includes multiple coexisting pathologies. There are more than 10,000 recognized rare diseases, and the great majority have no FDA-approved treatment. Nothing on that list is solved by a few large pharmaceutical companies and one AI lab’s internal programs. It gets solved, if it gets solved, by an army: thousands of groups attacking thousands of targets in parallel, most of them failing, a few of them not, with the failures published so the next group does not repeat them.
Anthropic knows this. Its own life sciences lead framed the in-house programs around diseases traditional biopharma will not touch, which is a tacit admission that the field vastly exceeds any one organization’s bandwidth. That admission is correct. It also sits in tension with the architecture the company has built, because concentrating the most capable scientific reasoning behind a handful of incumbent pharmaceutical relationships and an in-house discovery effort is a bet that the binding constraint in medicine is capability rather than parallelism.
I think that bet is wrong, and wrong in a way that costs lives rather than money. Modern biology depends on a vast pre-competitive commons. Every molecule any of us has worked on rests on structures somebody deposited in the Protein Data Bank, sequences somebody released to GenBank, assays and dead ends somebody published anyway. The industry calls that layer pre-competitive for a reason: you compete on the molecule, not on the fact that the protein has a pocket. A layer of intelligence that draws freely on that commons and then rations what comes back out is not a neutral instrument sitting above the field. It narrows how many shots on goal the field gets to take.
Notice also who the incumbents are. AbbVie, Eli Lilly, Bristol Myers Squibb, and a client list reported to include Sanofi, Novo Nordisk and Genmab. These are not the organizations most at risk of being short of capability. The smaller companies and academic groups on the other side of the filter are a large part of where new biology has historically come from.
Call It What It Is
I have no criticism of Anthropic for wanting to win. It spent enormous capital and talent building these models, it is entitled to a return, and buying a drug discovery team and entering therapeutics is a legitimate commercial decision any board would consider.
My objection is to the label.
When a routing policy touches the majority of an entire scientific discipline, and the company operating it has an acquired drug discovery team, several of the largest pharmaceutical companies as customers, and therapeutic programs of its own, “safety” stops being a complete description of what the mechanism does. It may still be sincere. It is no longer sufficient. A safeguard and a competitive moat can be the same mechanism, and the party operating it has no commercial incentive to hurry the disentangling.
So say it out loud. Publish where the line sits, publish who it applies to, and publish whether the internal programs run against the same threshold external customers do. If the answer is that they do, that is a strong answer and it costs nothing to state. What is hard to defend is describing a boundary with commercial consequences in the vocabulary of biosecurity, and leaving the market to guess which one it is looking at.
The Question Every Other Lab Is About to Ask
Now set the ethics aside entirely and treat this as a vendor decision, which is where I have spent 25 years on the selling side of the table.
Big pharma does not buy software the way a startup does. It qualifies vendors: supplier assessment, risk classification, validation plan, change control, business continuity review, all of it because these systems eventually touch a regulatory filing. Four questions get asked. Can you guarantee availability. Will behavior change without notice. What is our fallback. And who else are you.
Anthropic’s own account of the June suspension and its restoration.
On the first three, the record of the last two months is mixed, and worth stating carefully rather than dramatically. Anthropic’s two newest frontier models went offline worldwide for roughly eighteen days in June under a US government directive concerning foreign-national access; the company has said the global disablement was the practical consequence of complying, since it could not verify nationality in real time, and its other models remained available throughout. On pricing, a model initially bundled into subscriptions was announced at launch as moving behind usage credits less than three weeks later, so this was disclosed rather than concealed, though the window was brief and commercially awkward for anyone building on it.
June 9. The launch announcement that set both the capability and its expiry date in the subscription.
A classifier boundary that moves without publication, underneath a system somebody validated last quarter, is an uncontrolled change. That is not a philosophical complaint. It is a finding, and the remediation is revalidation.
But it is the fourth question that has changed, and it is the one I would put to any life sciences organization currently in procurement. Your prospective platform vendor bought a drug discovery company in April, signed two of your largest competitors in April and May, and announced its own therapeutic programs in June. Nothing improper need be happening with anyone’s data, and I have no reason to think it is. But somebody in your legal department is going to write a memo containing the words our shared intelligence platform is operated by a party that has entered our industry, and that memo does not have to reach a bad conclusion to be expensive. It adds clauses. It adds review cycles. At renewal, it adds a second source.
So, honestly: knowing what you now know, do you route your target biology through that platform? Or do you build an abstraction layer, keep two providers behind it, hold an open-weight model in reserve for anything the filter is likely to touch, and never let one vendor sit alone in the critical path? I built exactly that in July. I doubt I am the only one, and I am not going to tear it out.
That is the part I think gets missed inside a company that is winning. Dependency is only a moat if it is reliable. Make it unreliable, or make it conflicted, and you do not get a captive customer. You get an architecture decision.
Three Things to Publish
None of these removes a guardrail. All of them convert a private judgment into a legible one, and every one is in Anthropic’s own commercial interest.
One: turn the announced biology trusted-access program into a real front door. To the company’s credit, it has said it will enroll a small number of life sciences researchers and remove the biology and chemistry safeguards for them. That is the right instinct, and it is not yet a process. Make it comparable to the Cyber Verification Program, which is public, free, scoped to an organization and answered in about two business days: published criteria, organizational verification, a defined review period, and an answer either way.
Two: let verified identity reach the classifier. There is no anonymous user of a paid API. Every request carries an organization-scoped key, which is how the invoice gets addressed. A system that bills a customer by name and judges them as a stranger is not a safety architecture. It is an unfinished one.
Three: disclose the firewall, and publish a pre-competitive floor. State whether the internal therapeutic programs and the acquired discovery team run against the same threshold as customers, and name the class of work that will not be gated: target biology, mechanism, structure, the ordinary literate content of the field. The commons these models were trained on should not be harder to reach through the model than through PubMed.
The Stakes
The frontier is consolidating into a handful of firms that own the capability, the criteria that ration it, and now the downstream products built from it. Some of that rationing is genuinely safety. But its burden falls hardest on the part of the field least able to absorb it, and hardly at all on the organizations best positioned to compete.
Nobody is going to cure Alzheimer’s inside one company. Not Anthropic, not Isomorphic, not Lilly or Bristol Myers Squibb. It will take an army, drawing on a commons, most of it failing in public so the rest can move. The question is whether the most powerful scientific instrument ever built gets pointed at that whole army, or at a few flagship accounts and an in-house research effort while everybody else is told, in the calm register of a safety notice, to try a different model.
“Try a different model” is not an answer when the model being withheld is the capability the customer selected and paid to use.
REFERENCES
TechCrunch, “Anthropic buys biotech startup Coefficient Bio in $400M deal,” Apr. 3, 2026
Fierce Biotech, “Anthropic acquires stealth AI startup Coefficient Bio in $400M deal,”April 2026
“Claude partners with Eli Lilly on AI-driven drug development and clinical research,” Apr. 16, 2026
Fierce Pharma, “BMS taps Anthropic’s Claude for enterprise-wide AI adoption to speed drug R&D, global workflows,” May 20, 2026
Drug Discovery News, “Weekly rundown: Anthropic and Lilly’s deals prove AI is becoming biopharma’s biggest infrastructure bet,” 2026
Ashley Capoot, “Anthropic launches AI drug discovery program, Claude Science,” CNBC, June 30, 2026
Anthropic Support, “Why Claude switched models in your conversation with Fable 5,”accessed July 2026
Anthropic, “Claude Fable 5 and Claude Mythos 5,” June 9, 2026
Anthropic, “Activating AI Safety Level 3 protections,” May 22, 2025
Anthropic, “Statement on the US government directive to suspend access to Fable 5 and Mythos 5,” June 12, 2026
Anthropic, “Usage Policy,” accessed July 2026
Kyle Orland, “Anthropic says these topics are too dangerous to let its Fable 5 model talk about,” Ars Technica, June 9, 2026
“Alphabet-backed Isomorphic Labs raises $2.1B to accelerate AI-designed drug discovery as clinical trials near,” Tech Startups, May 12, 2026
Michael A. Heller and Rebecca S. Eisenberg, “Can Patents Deter Innovation? The Anticommons in Biomedical Research,” Science 280:698, May 1, 1998
Structural Genomics Consortium, “Open Science,” accessed July 2026
Steven Muskal, “Universities Built the Bomb. Now Build This,” Renaissance Circle, Jun. 26, 2026
Steven Muskal, “AI for Everyone,” Renaissance Circle, Jul. 23, 2026
Steven Muskal, Ph.D. is the CEO of Eidogen-Sertanty, Inc. - a drug discovery informatics company. He has spent four decades working at the intersection of computational biology, AI, and drug discovery. He writes about AI, health, and the intersection of biology and technology at stevenmuskal.com









