Skip to content
AnthropicAgentsVendor RiskLife SciencesData Governance

Anthropic quietly built a wet lab. When your model vendor starts running physical experiments, write the data and permission boundary before you hand it a protocol.

Reuters reported exclusively on Friday, September 18, that Anthropic has set up a wet lab in the San Francisco Bay Area for physical biology work, moving beyond computer-only evaluation. Anthropic's head of life sciences confirmed the lab in a Reuters interview on Tuesday, describing a mix of in-house facilities and external partners. One source says the company wants Claude to direct robotic units through experiments with limited human intervention; Anthropic says human oversight remains essential, that the lab is not for drug discovery specifically, and that it is not running clinical trials. For a small team, the lesson is not about biology. It is about what changes when a software vendor becomes a physical-process vendor, and why the data and agent-permission boundary needs to be written before any proprietary protocol, assay design, or instrument access pattern lands in that vendor's tools.

Steve Defendre
September 18, 2026
10 min read
Anthropic quietly built a wet lab. When your model vendor starts running physical experiments, write the data and permission boundary before you hand it a protocol.

The AI story for Friday, September 18, 2026 is a room. Reuters reported this morning, in an exclusive by Jeffrey Dastin and Michael Erman, that Anthropic has quietly set up a wet lab in the San Francisco Bay Area, a place for physical biology experiments rather than simulations. Two people familiar with the matter described the lab. Anthropic's head of life sciences, Eric Kauderer-Abrams, confirmed it in a Reuters interview on Tuesday.

I want to lay out what Reuters actually reported, separate the confirmed parts from the sourced parts, and then make one argument that has nothing to do with whether Anthropic ever ships a drug. When a frontier-model vendor moves from software into physical process control, meaning wet labs, robotic execution, procurement, and partner contract research organizations, the surface you trust that vendor with changes shape. The right response for a small team is to write the boundary down before the first proprietary protocol gets pasted into a chat window.

What Reuters reported, with dates attached

The Reuters piece went up Friday, September 18, around 10:02 AM UTC. The interview it quotes happened on Tuesday, September 16. The photo at the top is a Dreamforce logo shot dated September 17, which is the photo's date and not the lab's. Keep those three dates apart.

Here is the confirmed part, in Kauderer-Abrams' words to Reuters: "We believe that to do biology, the final test is still and will be for a while in real lab work. We absolutely are doing that today, and I would describe our approach as being typical of what you would see in most biotech companies, where there's some amount of that that we're doing in our own facilities and some amount of that that we're working with external partners on." He also said Anthropic is "bulking up" in-house lab work for speed and firsthand experience, outsourcing when that is more efficient, and that "there's some things that we can do much faster in our own hands," with the goal "to operate at the largest possible scale." Life sciences, he said, is already one of Anthropic's biggest investment areas by headcount and resources.

Here is the sourced part, attributed by Reuters to two people who spoke anonymously. The lab is in the Bay Area. Anthropic is embracing physical automation the way other biotech companies do. One of the two said the company wants to push how Claude can direct robotic units to carry out experiments with limited human intervention. On that point, Anthropic's spokesperson told Reuters that human oversight and involvement are essential for safety, and Kauderer-Abrams described the company as being "in the very early innings of using AI to automate the execution of lab work."

Here is the part that narrows the story. After the interview, a spokesperson clarified to Reuters that the lab is not for drug discovery specifically, and declined to elaborate. And Kauderer-Abrams said Anthropic has set a boundary: it is not running clinical trials for now, partly because of competition concerns with the pharmaceutical customers it sells tools to. "We're not competing with pharma and biotech companies that make their business in bringing drugs to market," he said. Reuters names Genentech, Bristol Myers Squibb, and Novo Nordisk among the companies Anthropic provides AI services and tools to, and notes that the two sources described a trust problem: customers may worry that Anthropic will learn from their competing drug programs, even as the startup walls their data off from view.

The background Reuters provides, which is context and not the news: Anthropic said at a San Francisco event in June that it would run preclinical programs in areas traditional companies do not find financially attractive. It launched Claude Science, added Novartis CEO Vas Narasimhan to its board, and acquired Coefficient Bio for roughly $400 million in stock according to media reports, a deal Anthropic confirmed without commenting on price. It launched the Model Hardware Standard in August to help AI operate equipment. It has posted jobs for a leader to ramp up procurement and operations, for an expert in protein and nucleic acid characterization, and for a role whose listing says the goal is to speed up progress in the life sciences by an order of magnitude. Dario Amodei has written that a disease killed his father a few years before a cure arrived. Kauderer-Abrams told Reuters that the life sciences are "by far" the biggest opportunity for the company's mission, and that "that is motivating everything that we're doing."

One adjacent item, and only one line on it: Anthropic's Life Sciences Verification Program, announced yesterday, September 17, is a separate access-and-safeguards program for outside researchers. It is not the wet lab, and I am not writing about it today beyond one detail I will come back to in the checklist.

Five small glass vials of violet liquid standing on dark wet stone beneath a floating cyan wireframe cube, with a thin beam of light descending from the cube toward the vials and stopped partway by a small brass latch glowing amber

Why a room changes the vendor relationship

Most of what a small team worries about with a model vendor is data: what did we paste in, who can see it, is it used for training, how long is it kept. Those questions do not go away when the vendor buys pipettes. They get joined by a second set.

A wet lab means the vendor now has its own protocols, its own assay designs, its own instrument fleet, its own procurement pipeline, and its own external partners. Some of those partners will be the same contract research organizations you use. Some of the people it is hiring will have worked at companies whose data sits in the same product you use. Reuters' two sources named the trust problem directly, and Kauderer-Abrams' clinical-trials boundary is Anthropic's answer to it. That answer is real, and it is also a business decision that can change. The interview said "for now."

The second thing a lab changes is that the vendor's tools start to have opinions about physical steps. If Claude Science or an agent built on the Model Hardware Standard can propose a plate layout, schedule an instrument, or draft a reagent order, then the boundary you need is no longer only "what data leaves my building." It is also "which physical actions may a model propose, which may it operate, and who signs off before the next wet step." Software mistakes get reverted. A contaminated cell line, a wasted week of reagents, or a mislabeled sample does not.

You may not run a lab. You probably run something with the same shape. An agent that can send a purchase order, open a support ticket with a supplier, push a firmware update to a field device, print a shipping label, or schedule time on a shared machine is an agent operating a physical process. The wet-lab story is the clearest version of a question every agent operator has: when does "propose" become "operate," and who is standing there when it does.

Distinct from the last few notes

Yesterday was OpenAI's misalignment disclosure framework and six training-time reports, a story about a vendor telling you how its models misbehaved. Today is a vendor telling you, through Reuters, that it is doing physical work with the same models. Those rhyme, and I will borrow one lesson from yesterday below, but they are different files.

September 16 was Mozilla and Mistral in Firefox, a consumer distribution story. September 15 was Google's internal vendor quota. September 14 was standards-body talks with no entity formed. September 13 was Amodei on pacing and evaluators. Reuters mentions the slowdown call and the extinction warnings as backdrop for the lab story. I covered them then and am not rehashing them now.

The small-team file: write the boundary before you paste the protocol

You do not need a biosafety officer to do this. You need one document, dated, that answers five questions before proprietary material enters a vendor tool that now sits next to that vendor's own bench.

  1. Classify what a protocol actually contains. A protocol, an assay design, or a runbook is not one thing. It is sequences and reagent identities, concentrations and timings, instrument settings and access patterns, and the reasoning about why. Sort each into three buckets: stays local and never leaves, may be shared in abstracted form (the shape of the step without the specific values), and may be shared as is. Write the buckets down. If you cannot sort it, it stays local until you can.

  2. Separate propose from operate, and default to propose. Write, in one paragraph, which physical steps an agent may propose as a plan for a human to execute, which it may operate directly, and which it may not touch. For most small teams the honest first version is: propose everything, operate nothing, and expand one step at a time with a written reason. Anthropic's own spokesperson said human oversight is essential. Take them at their word and make it your policy too.

  3. Name the sign-off. Every wet action, every purchase order, every firmware push, every instrument run that an agent had a hand in gets one named human who signs off on the next step. Not a role, a name, per run. Log the name next to the action. If the person is not available, the run waits. This is the same rule you would want from a contractor with keys to your building.

  4. Treat instrument and procurement access like production credentials. Yesterday's lesson from OpenAI's Artifactory report was that read-only tokens turned out to write. If your agents can reach an instrument API, a lab scheduler, a supplier portal, or a spend account, test what those credentials can actually do before the agent does. Keep instrument write access, ordering, and scheduling on separate tokens with separate limits, and put a dollar and a quantity cap on anything that buys.

  5. Ask the vendor five questions and write down the answers, including silence. Is my data used to train or evaluate your models? Who inside your company can see it, and does that include your own life sciences or lab teams? How long is it retained, and for what? Do you run any program adjacent to mine, and what does "walled off" mean in writing? What is your process if that changes? Here is the one LSVP detail that matters: Anthropic's own program page says flagged LSVP traffic is retained for 30 days for offline monitoring, is compartmentalized from model training and from Anthropic's life sciences research teams, and asks that stated use cases not include sensitive information or IP. That is a vendor telling you, in its own document, what not to paste. Read every vendor's equivalent and hold them to it.

  6. Write the stop condition. Physical runs need a kill switch that a human can hit without asking the agent. Decide in advance what stops a run: an unexpected reading, a reagent substitution the plan did not include, a step the agent proposes that is not in the approved list. Then decide who hits it and how you find out it was hit.

  7. Revisit when the vendor's boundary moves. Anthropic's clinical-trials line is "for now." The spokesperson's "not for drug discovery specifically" came with no elaboration. Put a calendar entry to re-read this file when the vendor announces a new lab, a new acquisition, a new partner, or a new hardware standard. The document is only as good as the day it was last checked against the vendor's own statements.

A dark wet stone plain split by a single bright cyan line, with three glass petri dishes glowing faint violet resting on the left side, one dish sitting directly on the line, and the right side dissolving into a drift of blue light particles toward distant dark glass towers

What not to do

Do not write "Anthropic is discovering drugs in its new lab." The spokesperson told Reuters the lab is not for drug discovery specifically, and did not say what it is for. Do not write that Kauderer-Abrams spoke to Reuters today; the interview was Tuesday, September 16, and the report is today. Do not write that Anthropic is running clinical trials; it said the opposite. Do not describe Claude directing robots as a shipped product; one anonymous source described it as something the company wants to push, and the company itself said it is in the very early innings. Do not fold the September 17 verification program into this story; it is a different announcement about outside researchers' access. Do not put the June preclinical remarks in September; that event was three months ago. And do not decide any of this is a reason to drop a vendor. A vendor with a bench is a vendor that understands what a bad wet step costs. The right response is a boundary document, not an exit.

Bottom line

On Friday, September 18, 2026, Reuters reported that Anthropic has set up a Bay Area wet lab for physical biology work, confirmed on Tuesday by its head of life sciences as a mix of in-house facilities and external partners. One source says the company wants Claude to direct robotic experiments with limited human intervention; Anthropic says human oversight is essential, the lab is not for drug discovery specifically, and it is not running clinical trials, partly to stay out of competition with the pharmaceutical customers whose data it walls off. For a small team, the lesson is that a software vendor became a physical-process vendor this week, and the surface you trust it with grew. Before any proprietary protocol, assay design, instrument access pattern, or supplier list goes into that vendor's tools, write down what stays local, which physical steps an agent may propose versus operate, and who signs off on the next wet action. If you want help writing that boundary for your own team, that is the kind of work we do.

Sources checked September 18, 2026: Reuters, Exclusive: Anthropic quietly sets up biology lab as it ramps AI drug program (September 18, 2026, approximately 10:02 AM UTC; Kauderer-Abrams interview conducted Tuesday, September 16, 2026; all quotes, sourcing, the spokesperson clarification, the clinical-trials boundary, the June event, the Coefficient Bio acquisition, the August Model Hardware Standard, the job listings, and the named pharmaceutical customers are drawn from this report); Anthropic, Introducing the Life Sciences Verification Program (September 17, 2026; cited only for the 30-day retention, compartmentalization, and no-sensitive-IP-in-use-cases details). The Dreamforce photograph in the Reuters piece is dated September 17, 2026, which is the photograph's date and not the date of the lab report.

Was this article helpful?

Share this post

Copy the link or send it across your usual channels.

Newsletter

Get the weekly field notes

One concise email each week with the latest insights on defense tech, AI, and software engineering.

Get the latest field notes once a week.

Discussion

Comments

Leave a comment

Loading comments…