Skip to main content
BiosecurityGoogle DeepMind· 5 min read· in Artificial Intelligence

Google DeepMind Unveils SynthID Bio to Watermark AI-Designed Proteins for Biosecurity Screening

DeepMind has adapted its digital watermarking technology to embed verifiable signatures directly into the amino acid sequences of AI-generated proteins. The open-source tool aims to help DNA synthesis providers screen for biological threats without degrading the proteins' intended functions.

By Viktoria Sokolova

DNA synthesis providers who manufacture custom biological molecules can now screen incoming orders for AI-generated designs using an automated digital signature. Google DeepMind has released SynthID Bio, an open-source tool that embeds a verifiable watermark directly into the amino acid sequences of artificially designed proteins.[1][3]

The system addresses a growing bottleneck in synthetic biology. Generative AI models like AlphaProteo and ProteinMPNN can now invent entirely novel proteins that do not exist in nature, accelerating drug discovery but complicating biosecurity for the laboratories that physically manufacture them.[1]

Because these synthetic molecules bear little resemblance to known pathogens, traditional screening protocols struggle to verify them. "AI is expanding what scientists can design, and DNA synthesis companies have an important role in helping that innovation scale responsibly,” said James Diggans at Twist Bioscience.

SynthID Bio works by subtly guiding the selection of amino acids during the generation process. It uses a cryptographic-style key to favor certain building blocks over others, creating a statistical pattern without altering the molecule's intended purpose. The tool integrates directly into ProteinMPNN, a popular protein design system.

The watermarking tool subtly guides the selection of amino acids during generation to create a statistical pattern.

For three-dimensional structures, the tool slightly adjusts the predicted coordinates of individual atoms. DeepMind fine-tuned a small portion of the AlphaFold 3 diffusion network, ensuring that the predicted coordinates inherently carry a detectable signature regardless of who runs the model locally.[1][2]

This hidden signature persists even after the digital design is manufactured into a physical protein in a laboratory. Software can scan the synthesized sequence with the original key, measuring how often the suggested amino acids appear to confirm its artificial origin.[3]

Preserving biological function

In wet-lab tests published in the journal Nature, researchers applied the watermark to protein binders designed to target three specific molecules. These included VEGF-A, the receptor-binding domain of the SARS-CoV-2 spike protein, and the immune checkpoint protein PD-L1.[2][3]

The watermarked proteins matched the binding affinity and success rates of unwatermarked versions. DeepMind reported that the embedded signature did not compromise the molecule's biological function or its natural sequence diversity, successfully creating the first watermarked and functional protein binders.[1][3]

Laboratory tests confirmed that watermarked proteins matched the binding affinity and success rates of unwatermarked versions.

Adaptyv Bio assisted with the laboratory testing, confirming that the watermarked designs performed identically to their unwatermarked counterparts. The structural adjustments maintained the model's prediction accuracy while offering near-perfect detectability against digital noise or minor coordinate changes.[1]

Despite these successes, the current iteration of SynthID Bio has distinct limitations that restrict its use as a comprehensive security tool. The watermark provides a basic signal that a design was AI-generated, but it cannot yet identify the specific creator or the exact model used.[4]

The tampering challenge

The embedded signature can also be scrubbed if a sequence is run through another design tool. If a user takes a marked protein and generates a functionally similar sequence using a different system, the tag effectively disappears, leaving the sequence untraceable.

DeepMind acknowledges that resistance to deliberate tampering remains a significant challenge for future updates. The company suggests pairing the watermark with provenance metadata standards—similar to the C2PA standard used for digital media—or central repositories of AI-generated biological data.[1][4]

The technology is already expanding beyond basic protein binders. In early collaborative trials with Stanford University and the Arc Institute, researchers successfully integrated the watermarking method into Evo 2, an advanced genomic model designed for more complex biological systems.[1]

This collaboration allowed the team to embed signatures into the genomes of AI-designed bacteriophages—viruses that infect bacteria. Early tests in bacterial cultures demonstrate that the watermarked phages remain fully functional, pointing toward broader applications in genomic design and synthetic life.[1]

Illustration: The technology aims to help DNA synthesis providers screen incoming orders for AI-generated designs.

Safeguarding public databases

Beyond commercial synthesis, the framework aims to protect public biological repositories. As AI-generated data floods open platforms, researchers risk building theories on unverified synthetic structures, potentially spending months working on a foundation that an AI simply dreamt up.

SynthID Bio offers a mechanism to flag or certify synthetic entries automatically. This prevents biological AI slop from polluting the databases that scientists rely on to test theories, ensuring that experimentally validated structures remain distinct from artificial predictions.

DeepMind has open-sourced the SynthID Bio methodology, alongside in vitro validation data and model weights, to foster collaborative development. The company hopes to start an industry-wide conversation about the pros and cons of watermarks and how to best implement them.[1]

Biosecurity experts view the release as a critical first step toward bioresilience. “SynthID Bio is an important piece of the puzzle for tracking the provenance of biological designs,” said Sarah Carter, a biosecurity policy expert at Science Policy Consulting who reviewed the work.[1]

The development of SynthID Bio by a major frontier AI laboratory signals a growing recognition that responsible development and cutting-edge progress must occur simultaneously. Industry advocates argue that strengthening critical control points like DNA synthesis actually supports faster, more effective research.[5]

As artificial intelligence continues to expand what scientists can design, the burden of verifying these novel molecules will only increase. Open-source tools that embed verifiable provenance directly into the biological code represent a foundational layer for the next generation of synthetic biology safeguards.[5]

Key points

  1. Google DeepMind's SynthID Bio embeds a detectable statistical signature into the amino acid sequences and 3D structures of AI-designed proteins.
  2. The open-source tool allows DNA synthesis companies to quickly identify AI-generated molecules during biosecurity screening without manual review.
  3. Laboratory tests confirmed that the watermarking process preserves the binding affinity and core biological function of the proteins.
  4. The embedded signature can currently be removed if the sequence is rewritten by another design tool, limiting its resistance to deliberate tampering.

What we don’t know

  • Whether the watermarking process will preserve the biological function of highly complex proteins beyond the specific binders tested in the laboratory.
  • How quickly commercial DNA synthesis providers will adopt the open-source tool into their standard screening protocols.
  • Whether future updates can make the watermark resistant to deliberate scrubbing or tampering by malicious actors.

How we got here

  1. May 2024

    DeepMind releases AlphaFold 3, advancing the prediction of complex molecular structures.

  2. August 2026

    Anthropic announces that its Claude model successfully designed working protein binders.

  3. September 30, 2026

    DeepMind publishes the SynthID Bio proof-of-concept in Nature, demonstrating functional watermarked proteins.

Biosecurity Advocates 40%AI Developers 35%Protein Scientists 25%
Biosecurity Advocates
Focus on the necessity of automated screening tools to prevent malicious actors from synthesizing dangerous AI-designed pathogens.
AI Developers
Emphasize open-source collaboration and the technical achievement of embedding signatures without degrading biological function.
Protein Scientists
Express cautious optimism but worry about the added complexity and potential structural compromises when applying watermarks to highly sensitive therapeutic research.

Perspectives this story doesn't cover

  • Commercial DNA Synthesis Providers
  • Open-Source AI Model Creators

Sources

Source coverage

5 outlets

3 viewpoints surfaced

Biosecurity Advocates 40%AI Developers 35%Protein Scientists 25%
  1. [1]Google DeepMindAI Developers

    Introducing SynthID Bio

    Read on Google DeepMind →
  2. [2]NatureProtein Scientists

    Function-preserving watermarking of AI-generated proteins

    Read on Nature →
  3. [3]Help Net SecurityBiosecurity Advocates

    Google's SynthID Bio can watermark AI-designed protein binders without breaking them

    Read on Help Net Security →
  4. [4]BioScienceBiosecurity Advocates

    Google DeepMind Is Now Watermarking AI-Designed Proteins to Prevent Biological Risks

    Read on BioScience →
  5. [5]NTIBiosecurity Advocates

    Google DeepMind's SynthID Bio

    Read on NTI →

Comments

Stay informed

Every angle. Every day.

Get Artificial Intelligence stories with full source coverage and perspective breakdowns, free every day.