Google DeepMind's SynthID Bio watermarks AI-designed proteins
Wet-lab tests on three protein targets found watermarked designs matched the binding affinity of unwatermarked versions, and DeepMind is open-sourcing the method.
- Safety & alignment
- Security & misuse
- Minor
Google DeepMind introduced SynthID Bio, a method for embedding an imperceptible watermark into AI-designed protein sequences and their predicted three-dimensional structures, extending a watermarking approach the company has applied since 2023 to images, text, audio and video into synthetic biology. The system nudges which amino acids a sequence-design model selects, or which atomic coordinates a structure-prediction model outputs, aiming to leave a detectable signal without changing how the protein folds or behaves.
DeepMind said it tested the approach on AI-designed protein binders targeting three disease-relevant proteins — VEGF-A, the SARS-CoV-2 spike protein’s receptor-binding domain, and PD-L1 — and found that watermarked designs matched the binding affinity, hit rate and sequence diversity of unwatermarked versions from the same design process. That result, verified in wet-lab synthesis rather than only in simulation, was the paper’s central claim: the watermark survives actual protein-making without measurably weakening the protein it marks. Collaborators on the work included Stanford’s Hie lab, the Arc Institute and Adaptyv Bio, which ran the in vitro validation.
The stated aim is biosecurity rather than attribution for its own sake. Companies that synthesise DNA to order already screen requests against databases of known pathogen sequences; a watermark would let them also flag a sequence as having come from an AI design tool, independent of what it resembles, and could help repositories such as GenBank, UniProt and the Protein Data Bank label AI-generated entries rather than let them accumulate unmarked alongside naturally occurring ones. DeepMind said it is publishing the method, open-sourcing code and in vitro data, and releasing model weights to outside researchers rather than keeping the technique proprietary.
As with any watermarking scheme, the limitation is adoption: SynthID Bio only identifies output from design tools that choose to add the mark, offers nothing for sequences produced by tools that don’t, and depends on synthesis providers and database curators actually checking for it. The release extends the pattern set by DeepMind’s earlier SynthID watermark for images and its public verification tool launched in 2025 into biology.