AI Models & Platforms

DeepMind Embeds Verifiable Watermarks in AI-Designed Proteins

mm
Add Unite.AI to your preferred sources on Google

Google DeepMind unveiled SynthID Bio on September 30, 2026, a family of watermarking methods that embeds an imperceptible, verifiable signature into AI-generated protein sequences and predicted 3D structures. The company says the proof of concept preserved biological function in wet-lab testing across three target proteins.

The announcement situates the tool in a field where AI systems already predict protein structures, as DeepMind’s AlphaFold does, and design entirely new proteins, as AlphaProteo and the commonly used ProteinMPNN sequence generation method do. More recently, researchers have used AI to develop bacteriophages, viruses that infect bacteria. DeepMind says these capabilities also create new problems: novel AI designs can bypass traditional DNA synthesis screening, and mislabeled synthetic 3D structures can contaminate public databases and mislead downstream research.

Wet-Lab Validation on Three Protein Targets

SynthID Bio adapts its approach to the type of data. For sequences, it subtly guides the choice of amino acids; for predicted 3D structures, it adjusts atomic coordinates. In both cases the goal is a detectable signal, and DeepMind reports that in its experiments these adjustments did not compromise the proteins’ biological function. Because the signature sits in the biological code itself, the watermark can be verified on the synthesized, physical protein rather than only on a digital model.

The team verified its approach on protein binders, molecules engineered to latch selectively onto other proteins, using DeepMind’s AlphaProteo binder design method alongside a SynthID Bio-enabled version of ProteinMPNN. The company said that in wet-lab testing on three target proteins, VEGF-A, the SARS-CoV-2 spike protein RBD, and PD-L1, the watermarked designs matched unwatermarked versions on hit rate, binding affinity, and natural sequence diversity. DeepMind describes the outcome as the first-ever watermarked and biologically functional protein binders. Binding affinity was measured as KD, with lower values indicating stronger binders, and the project credits Adaptyv Bio with helping on in vitro validation.

Watermarking Built Into AlphaFold 3

For protein folding, the method works inside the model itself. The team fine-tuned a small part of the diffusion network in AlphaFold 3, embedding the watermarking capability in the model’s weights, so any predicted 3D coordinates carry a detectable signature no matter who runs the model. According to DeepMind, the fine-tuned model keeps AlphaFold 3’s prediction accuracy, delivers near-perfect detectability and maintains key structural feature distributions, and the watermark holds up against digital noise or minor coordinate changes. A visualization in the post compares, for the protein 7PPA, the AlphaFold 3 predicted structure, the ground truth structure, and the watermarked structure.

Biosecurity Screening and Database Integrity

DeepMind describes biosecurity as a matter of layered defenses, invoking the Swiss cheese model in which each independent safeguard covers the blind spots of the others, and places SynthID Bio within its broader vision for bioresilience as a verification layer embedded in the biological design itself.

That layer applies most directly to DNA synthesis screening. A digital protein design becomes a physical molecule only after an order is placed with a DNA synthesis provider, and those providers screen incoming requests against databases of known threats. In the past, screeners could reasonably treat an unfamiliar sequence as an undiscovered natural organism. DeepMind says AI erases that assumption because it can generate entirely new sequences bearing little resemblance to known hazards, and checking whether such an order is an engineered threat requires exhaustive manual review that can stall vital research. SynthID Bio is intended to supply an automated verification signal showing that an order originated from a trusted model with built-in safeguards.

James Diggans, Vice President of Policy and Biosecurity at Twist Bioscience, who provided early feedback on the paper, said watermarking offers “a promising new addition to the biosecurity toolbox” that could strengthen screening, focus resources on sequences that warrant closer review, and make biosecurity more efficient as AI-designed biology advances.

DeepMind also says the method could help preserve the integrity of public databases such as the Protein Data Bank, UniProt, and GenBank, many of which are open to public submission. As part of the submission process, the watermark could ensure synthetic entries are properly labeled or flagged for further review.

Sarah Carter, a biosecurity policy expert and Principal at Science Policy Consulting who reviewed the work, called SynthID Bio “an important piece of the puzzle for tracking the provenance of biological designs,” adding that linking designs to the model developer allows synthesis providers to streamline screening for customers who have used those models.

Bacteriophage Extension and Open Release

Among the remaining challenges, DeepMind lists making the watermark more robust against deliberate tampering. The company says SynthID Bio can also be paired with provenance metadata approaches, similar to C2PA for digital media, or with central repositories of AI-generated biological data, to better identify and track AI-generated proteins.

The team has also integrated SynthID Bio into Evo 2, a genomic model, in ongoing collaboration with the Hie lab at Stanford University and Arc Institute, watermarking the genome of an Evo 2-designed bacteriophage. Early laboratory testing in bacteria cultures confirmed the watermarked bacteriophages are functional, the company said, adding that it will share more details in a technical manuscript soon.

SynthID Bio extends SynthID, Google DeepMind’s existing tool that embeds digital watermarks into AI-generated images, audio, text, and video across the company’s generative AI consumer products. Those marks are imperceptible to people but detectable by SynthID’s technology, and the company also operates the SynthID Detector, a verification portal where users upload an image, video, or audio file to check whether content was watermarked.

Alongside the announcement, DeepMind is publishing a methods paper, open-sourcing the code and in vitro data, and releasing the weights to the research community. Pushmeet Kohli initiated the project, and Alexander I. Cowen-Rivers and David Stutz led the research and technical development, advised by Kohli.

Aria Bloom is an AI-generated journalist exploring how artificial intelligence is transforming biotechnology and genomic research. Her writing blends precision with a deep curiosity about the future of life sciences.

From synthetic biology to personalized medicine, Aria analyzes how machine learning is accelerating human health innovation.

Articles authored by Aria Bloom are AI-generated and reviewed by Unite.AI’s editorial team for accuracy and compliance.