Google DeepMind's SynthID Bio Watermarks AI-Designed Proteins
Google DeepMind's SynthID Bio embeds detectable signatures into AI-designed proteins that survive physical synthesis and lab testing without harming biological function.
Updated
Why it matters
- SynthID Bio watermarked protein binders matched unwatermarked versions in hit rate, binding affinity, and sequence diversity across three targets (VEGF-A, SARS-CoV-2 spike RBD, PD-L1).
- DeepMind fine-tuned part of AlphaFold 3's diffusion network so its predicted 3D coordinates carry a watermark with near-perfect detectability, regardless of who runs the model.
- In work with Stanford's Hie lab and Arc Institute, SynthID Bio was integrated into the Evo 2 genomic model to watermark a bacteriophage genome; early lab tests in bacteria cultures confirmed functionality.
- DeepMind is open-sourcing the code, in vitro data, and model weights, and invites partnership proposals at [email protected].
Google DeepMind has introduced SynthID Bio, a watermarking system that embeds a detectable signature directly into AI-generated proteins — a signature that survives synthesis into physical molecules and remains verifiable in laboratory testing without compromising biological function.
The announcement, published alongside a methods paper, extends the company's SynthID watermarking technology from digital media into synthetic biology. The stakes are concrete: generative AI tools such as AlphaFold, AlphaProteo, and ProteinMPNN now let scientists predict protein structures, design novel proteins from scratch, and even engineer bacteriophages — viruses that infect bacteria. Those same capabilities strain the biosecurity infrastructure built to screen dangerous biological sequences before they are ever synthesized.
The core problem sits at DNA synthesis screening, the frontline of biosecurity. Converting a digital protein design into a physical molecule requires placing an order with a DNA synthesis provider, which screens requests against databases of known threats. Historically, screeners could safely assume an unfamiliar sequence came from an undiscovered natural organism. AI breaks that assumption. Models can now generate entirely new sequences that bear little resemblance to known hazards, forcing screeners into exhaustive manual reviews that can stall legitimate research.
How the watermark works
SynthID Bio is a family of watermarking methods that adapt to the type of biological data. For protein sequences, it subtly guides the choice of amino acids. For predicted 3D structures, it adjusts atomic coordinates. The result is a reliable detection signal embedded in the biological design itself.
DeepMind validated the approach on protein binders — molecules engineered to latch selectively onto other proteins — using its AlphaProteo binder design method alongside a SynthID Bio-enabled version of ProteinMPNN, a widely used protein sequence generation tool. In wet-lab testing across three target proteins (VEGF-A, the SARS-CoV-2 spike protein RBD, and PD-L1), the watermarked designs matched the hit rate, binding affinity, and natural sequence diversity of unwatermarked versions. DeepMind describes these as the first-ever watermarked and biologically functional protein binders.
For protein folding, the team took a different route: it fine-tuned a small part of AlphaFold 3's diffusion network so the watermarking capability lives directly in the model's weights. Every predicted 3D coordinate set inherently carries a detectable signature, regardless of who runs the model. According to DeepMind, this preserves AlphaFold 3's prediction accuracy while delivering near-perfect detectability, maintaining key structural feature distributions, and holding up against digital noise or minor coordinate changes.
A layer in a layered defense
DeepMind frames the technology as one layer in what biosecurity experts call the "Swiss cheese" defense model — multiple independent safeguards working together to cover each other's blind spots. Model-level mitigations and customer vetting each represent layers with gaps. SynthID Bio adds a verification layer embedded in the biological design itself, part of what DeepMind calls its broader vision for "bioresilience."
"SynthID Bio is an important piece of the puzzle for tracking the provenance of biological designs," said Sarah Carter, a biosecurity policy expert and Principal at Science Policy Consulting who reviewed the work. "By linking designs to the model developer, these watermarks empower developers to lead on safety and allow synthesis providers to streamline screening for customers who have used those models."
The potential commercial appeal is visible in early industry feedback. "AI is expanding what scientists can design, and DNA synthesis companies have an important role in helping that innovation scale responsibly," said James Diggans, Vice President, Policy and Biosecurity at Twist Bioscience, who provided early feedback on the paper. "For Twist, watermarking offers a promising new addition to the biosecurity toolbox that could strengthen screening, focus resources on sequences that warrant closer review and make biosecurity more efficient as AI-designed biology continues to advance."
Database integrity
Beyond synthesis screening, DeepMind points to scientific databases as a second use case. Public repositories such as the Protein Data Bank, UniProt, and GenBank accept open submissions and underpin large parts of biological research. Mislabeled synthetic 3D structures risk polluting these databases and misleading downstream research — a challenge DeepMind expects to grow as AI-generated biological data accumulates. SynthID Bio could flag synthetic entries during submission, ensuring they are properly labeled or routed for review.
Extending to genomes
DeepMind is already pushing the technique beyond proteins. In ongoing work with the Hie lab at Stanford University and Arc Institute, the team integrated SynthID Bio into Evo 2, an advanced genomic model, to watermark the genome of a bacteriophage designed by Evo 2. Early laboratory testing in bacteria cultures confirmed the watermarked bacteriophages are functional. DeepMind says this work could address biosecurity risks associated with genome design and will share details in a technical manuscript soon.
The company acknowledges open challenges. The watermark needs to become more robust against deliberate tampering. DeepMind also sees potential in pairing SynthID Bio with provenance metadata approaches — analogous to C2PA for digital media — or with central repositories of AI-generated biological data.
The project was initiated by Pushmeet Kohli, with research and technical development led by Alexander I. Cowen-Rivers and David Stutz. Adaptyv Bio assisted with in vitro validation, and Demis Hassabis supported the project.
DeepMind is publishing its methods paper, open-sourcing the code and in vitro data, and releasing model weights to the research community. The company invites potential partners in biosecurity, gene synthesis, and policy to submit high-level proposals via [email protected]. No single biosecurity intervention is a silver bullet, DeepMind notes — but as AI-designed biology scales, an automated, model-embedded verification signal gives screeners and database curators a tool that manual review alone cannot provide.
Original: science.org
More from Rebecca Stone
Show full bio
Correspondent covering consumer brands and retail at AI In Context.
165 articles
Related articles
- Google Figures Out How to Watermark AI-Designed Proteins
- AI Developers Weigh Biology's Double Edge: Promise and Biosecurity Risk
- Google Watermarked 100 Billion Files, Now Lets Rivals Use SynthID
- Google Publishes Co-Scientist in Nature, Opens AI Hypothesis Tool to Researchers
- AI Watermarking Alters Model Safety Behavior, Research Finds