
Google DeepMind unveils SynthID Bio, a watermark for AI-designed proteins
Google DeepMind has published SynthID Bio, a family of watermarking methods that mark AI-designed protein sequences and predicted 3D structures while preserving their biological function.
Google DeepMind has introduced SynthID Bio, a family of watermarking methods built for synthetic biology. The system embeds a subtle signature into biological designs, so AI-generated proteins can still be identified after they are synthesized in the lab. The announcement came with a paper in Nature.
How the watermark works
SynthID Bio adapts Google's SynthID technology to biological data. For protein sequences it works with ProteinMPNN: as it places amino acids one at a time along a protein backbone, SynthID Bio uses a key and the amino acids already chosen to suggest the next one. ProteinMPNN accepts the suggestion only when it still fits the backbone shape and constraints, so the bias spreads across the whole sequence.

Detection is statistical, not a simple yes or no. A verifier holding the key scans the full sequence and measures how often the suggested amino acids appear. For predicted 3D structures, the team fine-tuned part of AlphaFold 3's diffusion network so the watermark lives in the model's weights; DeepMind says accuracy is preserved and the mark survives digital noise.
Wet-lab results and biosecurity
With the binder design system AlphaProteo, the researchers tested watermarked proteins against three targets: VEGF-A, the SARS-CoV-2 spike RBD, and PD-L1. The watermarked versions matched unwatermarked controls on hit rate, binding affinity and sequence diversity, which DeepMind calls the first watermarked, functional protein binders.
The goal is screening. DNA synthesis providers check orders against databases of known threats, but an unfamiliar AI-designed sequence resembles nothing on record. DeepMind argues that if providers hold keys from trusted organisations, they can quickly confirm that an unknown protein came from a vetted model and focus review capacity on the rest. The watermark could also help keep databases such as the Protein Data Bank, UniProt and GenBank accurate.
Limits the team flags
The scheme is only as secure as the system distributing the keys. Very short proteins may carry too few watermark amino acids to identify. A watermarked design can be padded with unmarked sequence, which may dilute the signal, and deliberate tampering can scrub the watermark. Many AI design tools do not use ProteinMPNN, so not every designer can add a watermark. Detection thresholds also trade false positives against false negatives. Ars Technica notes that the practical value in this form is not yet clear. DeepMind is open-sourcing the code and in vitro data, and is testing the approach on a bacteriophage genome designed with the Evo 2 model.
Sources: Ars Technica · Google DeepMind
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.