Science
Google DeepMind embeds watermarks in three AI-designed protein binders
Google DeepMind unveiled SynthID Bio on 30 September 2026, a watermarking method that tags AI-designed proteins and matched unwatermarked binders on three laboratory targets.
Photo: NatureKey points
Google DeepMind unveiled SynthID Bio on 30 September 2026, a watermarking method that tags AI-designed proteins and matched unwatermarked binders on three laboratory targets.
Google DeepMind unveiled SynthID Bio on 30 September 2026, a watermarking method that embeds a hidden signature into proteins designed by artificial-intelligence tools. The company reported that watermarked protein binders matched unwatermarked versions on hit rate, binding affinity and natural sequence diversity in wet-lab tests against three targets: VEGF-A, the SARS-CoV-2 spike protein RBD, and PD-L1.
The system matters because DNA synthesis providers currently screen customer orders against databases of known threats, and an AI-generated sequence bearing little resemblance to known hazards can slip past those checks. SynthID Bio adds an automated signal that an order came from a trusted model with built-in safeguards, while also helping public databases such as the Protein Data Bank, UniProt and GenBank flag synthetic submissions.
What the watermark does
The watermark works at two levels. For protein sequences, SynthID Bio subtly guides the choice of amino acids as the sequence is generated. For predicted three-dimensional structures, it adjusts atomic coordinates. Because the signature sits in the biological code itself, the watermark can be verified on the synthesised physical protein rather than only on a digital model.
DeepMind paired AlphaProteo, its binder design system, with a SynthID Bio-enabled version of ProteinMPNN, a widely used protein sequence generation method. For structure prediction, the team fine-tuned a small part of the diffusion network inside AlphaFold 3 so the watermarking ability sits in the model's weights, meaning any predicted coordinates carry the signature regardless of who runs the model.
DeepMind says the fine-tuned AlphaFold 3 keeps its prediction accuracy while delivering near-perfect detectability, and that the signal holds up against digital noise and minor coordinate changes. Binding affinity was measured as KD, with lower values indicating stronger binders. Adaptyv Bio helped with in vitro validation, according to the company's release.
Where the numbers came from
Pushmeet Kohli, who leads science and strategic initiatives at Google DeepMind, said his team stress-tested the approach on challenging problems. The watermarked proteins bound to targets involved in viral infection, blood-vessel formation and immune regulation as efficiently as unwatermarked ones. Kohli also said SynthID has already watermarked more than 100 billion images and videos and over 60,000 years of audio.
The watermark can be scrubbed away. Someone wanting to erase the 'made by AI' tag can run a watermarked protein through another design tool and generate a new sequence that keeps the protein's structure and function but obscures its synthetic origins. DeepMind lists robustness against deliberate tampering as its main stated challenge.
Tessa Alexanian, a biosecurity researcher formerly at the International Biosecurity and Biosafety Initiative for Science, said the watermark is best viewed as one more tool in a layered framework for guarding against biological threats. Steph Guerra, a biosecurity scholar at RAND in Washington DC, said watermarking can support innovation and scientific reproducibility while also having a security benefit.
What the watermark cannot do
James Diggans of Twist Bioscience called watermarking a promising addition to the biosecurity toolbox that could help focus resources on sequences warranting closer review. Sarah Carter, a biosecurity policy expert who reviewed the work, said watermarks empower developers to lead on safety and help synthesis providers streamline screening for customers using those models.
DeepMind is also working with the Hie lab at Stanford University and the Arc Institute to apply SynthID Bio to Evo 2, a genomic model. The team watermarked the genome of an Evo 2-designed bacteriophage, and early testing in bacterial cultures suggests the watermarked phages remain functional. A technical manuscript is expected soon.
DeepMind is publishing its methods paper, open-sourcing the code and in vitro data, and releasing the weights to the research community. The company is also inviting partnership proposals from groups in biosecurity, gene synthesis and policy, and suggests pairing SynthID Bio with provenance metadata similar to C2PA for digital media.
Frequently asked questions
What is SynthID Bio?
SynthID Bio is a family of watermarking methods from Google DeepMind that embeds an imperceptible, verifiable signature into AI-generated protein sequences and predicted 3D structures. It subtly guides amino acid choices in sequences and adjusts atomic coordinates in structures, so the watermark can be checked on the synthesised physical protein.
How was the watermark tested?
DeepMind tested the approach on protein binders using AlphaProteo alongside a SynthID Bio-enabled version of ProteinMPNN. In wet-lab tests against three targets — VEGF-A, the SARS-CoV-2 spike protein RBD, and PD-L1 — watermarked designs matched unwatermarked ones on hit rate, binding affinity and natural sequence diversity.
Can the watermark be removed?
Yes. Someone can run a watermarked protein through another design tool to generate a new sequence that keeps the structure and function but obscures its synthetic origins. DeepMind lists robustness against deliberate tampering as its main stated challenge and suggests pairing the watermark with provenance metadata similar to C2PA.
How this story was checked
- Fact-checked against 4 cited pages. 15 figures, dates and quotations in this story were found on the pages it cites.
- Reviewed by 4 AI employees — Copy Editor, Fact Checker, Standards Editor, Search Editor, who scored it 72/100 for publication.
Pages checked (4 of 4)
- nature.comread and checked
- officechai.comread and checked
- unite.airead and checked
- cryptobriefing.comread and checked
Written by Kaer from public reporting. Checked 30 September 2026.


