Google DeepMind has introduced SynthID Bio, a new family of watermarking methods that embed a detectable, imperceptible signature directly into AI-designed proteins. Announced on September 30, the system extends the company's SynthID watermarking technology — already used to label AI-generated text, images, audio, and video — into synthetic biology, where the stakes include biosecurity and the integrity of public scientific databases.
Unlike digital watermarking, a biological watermark has to survive a much harsher test: it must remain detectable not just in a software model's output, but in the synthesized, physical protein itself. According to DeepMind, SynthID Bio clears that bar. In laboratory experiments, watermarked protein designs retained their biological function while staying verifiable, producing what the company describes as the first-ever watermarked and biologically functional protein binders. The work is detailed in a Nature paper titled "Function-preserving watermarking of AI-generated proteins." For more context on this story, see our ongoing more AI stories.
Why watermark biology?
Generative AI has become a genuine tool of biological research. DeepMind points to its own portfolio: AlphaFold for predicting protein structures, AlphaProteo and ProteinMPNN for designing entirely new proteins, and more recently, AI systems used to develop new bacteriophages — viruses that infect bacteria. The same tools, however, create new risks.
According to the announcement, novel AI-designed sequences can bypass traditional DNA synthesis screening, because screeners can no longer assume that an unfamiliar sequence belongs to some undiscovered natural organism. Separately, mislabeled synthetic 3D structures risk polluting public databases and misleading downstream research. Both problems share a root cause: nobody can currently prove where a given biological design came from.
Two watermarking approaches, one goal
SynthID Bio adapts its technique to the type of data. For protein sequences, it subtly guides the choice of amino acids as the sequence is generated, embedding a statistical signal that detection tools can pick up. For predicted 3D structures, it makes small adjustments to atomic coordinates that carry a detectable signature.
The strongest evidence comes from wet-lab validation. Working with a SynthID Bio-enabled version of ProteinMPNN alongside DeepMind's AlphaProteo binder-design method, researchers watermarked designs targeting three proteins: VEGF-A, the SARS-CoV-2 spike protein receptor-binding domain, and PD-L1. The watermarked designs matched their unwatermarked counterparts on hit rate, binding affinity measured as KD, and natural sequence diversity. In other words, the watermark did not degrade the molecules' ability to do their job.
For protein folding, DeepMind took a different route: the team fine-tuned part of AlphaFold 3's diffusion network so the watermarking ability is built directly into the model's weights. That means every predicted structure carries a detectable signature regardless of who runs the model, while the company reports the approach preserves AlphaFold 3's prediction accuracy, offers near-perfect detectability, and holds up against digital noise or minor coordinate changes.
A new layer in biosecurity's 'Swiss cheese' defense
DeepMind frames SynthID Bio as one layer in a layered biosecurity model — the "Swiss cheese" approach, where multiple independent safeguards each cover the others' blind spots. DNA synthesis screening sits on the front lines: turning a digital protein design into a physical molecule requires ordering DNA from synthesis providers, who screen requests against databases of known threats. Verifying an unfamiliar order today can require exhaustive manual review that stalls legitimate research. An embedded watermark gives providers an automated signal that an order originated from a trusted model with built-in safeguards.
Independent experts quoted by DeepMind echoed that framing. "SynthID Bio is an important piece of the puzzle for tracking the provenance of biological designs," said Sarah Carter, a biosecurity policy expert and Principal at Science Policy Consulting, adding that the watermarks let developers lead on safety and let synthesis providers streamline screening. James Diggans, Vice President of Policy and Biosecurity at Twist Bioscience, which provided early feedback on the paper, called watermarking "a promising new addition to the biosecurity toolbox" that could focus scrutiny on sequences that warrant closer review.
The same provenance signal could protect open scientific repositories such as the Protein Data Bank, UniProt, and GenBank, which accept public submissions. As AI-generated biology accumulates, SynthID Bio could flag or verify synthetic entries before they contaminate the record that other researchers — and biosecurity decisions — rely on.
Limits, and what comes next
DeepMind is candid that the system is not tamper-proof. Making the watermark robust against deliberate adversarial removal is listed as a key open challenge, and the company suggests pairing SynthID Bio with provenance metadata standards similar to C2PA, the content-credential scheme used for digital media, or with central repositories of AI-generated biological data.
The scope is also expanding beyond proteins. In ongoing work with the Hie lab at Stanford University and the Arc Institute, DeepMind integrated SynthID Bio into Evo 2, an advanced genomic model, and used it to watermark the genome of an Evo 2-designed bacteriophage. Early laboratory testing in bacterial cultures confirmed the watermarked phages remain functional, and the company says a technical manuscript is forthcoming.
For a field where AI is starting to write biological code that has never existed in nature, being able to answer "who made this, and with which model?" is quietly becoming infrastructure. SynthID Bio is an early, deliberately cautious step in that direction — one that its creators insist is a complement to, not a substitute for, the rest of the biosecurity stack. For more on how AI research is evolving, follow the latest AI developments as labs keep pushing generative models deeper into the natural sciences.
Stay Ahead of AI
Follow the full story and more on our homepage: Read more AI news →
