They have never claimed that simply doing bio research is inherently dangerous. Rather, the risk is from bad actors doing research for nefarious purposes. Which is exactly why they let other organizations use the models without guardrails on a case-by-case basis. Them using it internally has nothing to do with existential risk (at this point anyway).
I mean. When a bunch of people are abusing their API to do terrible things with their models, they can certainly decide they can trust themselves with models more than others.