Google Figures Out How to Watermark AI-Designed Proteins
Google has developed a way to watermark AI-designed proteins, answering a biosecurity gap flagged in 2025: screening software cannot detect synthetic proteins no one has characterized.

Updated
Why it matters
- Google has developed a method to watermark proteins designed by AI, Ars Technica reported in September 2026.
- Screening software for threatening DNA sequences cannot identify AI-designed proteins because they have never been characterized, a risk flagged in October 2025.
- AI protein design has produced plastic-digesting enzymes and venom-blocking proteins, but the same tools could design toxins or alter viral proteins.
Google has developed a method for watermarking proteins designed by artificial intelligence, according to a report published by Ars Technica in September 2026. The work addresses a biosecurity gap that researchers flagged nearly a year earlier: standard screening software cannot identify AI-designed proteins as potential threats, because no one has characterized these novel molecules well enough to recognize the danger they might pose.
The problem sits at the intersection of two trends. AI protein-design tools have matured rapidly and delivered real successes. Ars Technica points to AI-designed enzymes that can digest plastics, reported in February 2025, and proteins designed to block snake venom toxins, reported in January 2026. The same design pipelines, however, can be turned toward harmful ends — producing toxins or altering the behavior of viral proteins.
The security hole is structural. As Ars Technica reported in October 2025, the software used to screen DNA sequences for potentially threatening proteins does not flag AI-designed sequences. These tools rely on databases of previously characterized proteins. A molecule that exists only because a generative model imagined it has no entry, no annotation, and no threat profile. Screening software simply has nothing to match against.
That gap between capability and detection remained open for close to a year. "Nearly a year after that risk was flagged, it still wasn't clear what anyone could do about it," Ars Technica notes. Google's watermarking approach, as the publication's headline reports, is the first concrete answer to emerge.
The stakes are considerable. Protein design is one of the most commercially and scientifically consequential applications of AI in biology. It underpins work on enzymes for industrial chemistry, therapeutic binders, and antivenoms. But unlike AI-generated text or images, where detection and provenance tools have attracted heavy investment, AI-generated biology has moved faster than the safeguards around it. A watermark baked into designed proteins would give screening systems a way to recognize synthetic sequences even when their function is unknown — closing the exact loophole that current databases cannot.
The broader pattern matters too. As Ars Technica observes at the top of its report, AI-based tools "seem to be causing security threats on a nearly daily basis, in part because we've been slow to recognize potential threats." Biosecurity, the publication argues, is the exception: "One area where we seem to be ahead of the game, however, is in biosecurity." Google's watermarking work, arriving before any reported abuse of AI-designed proteins rather than after, is the evidence for that claim.
The context for the development is a fast-moving field. The successes Ars Technica cites — plastic-digesting enzymes and venom-blocking proteins — show how quickly AI design has moved from proof of concept to functional molecules. Each of those wins doubles as a demonstration that the same infrastructure can produce molecules nobody has ever screened. That asymmetry, useful capability outpacing detection, is what Google's work targets.
What remains to be seen, on the reporting available so far, is how the watermark performs in practice: whether it survives in real organisms, whether it can be stripped by a determined actor, and whether screening providers and DNA synthesis companies will adopt it as a standard check. Those adoption questions will determine whether the technique closes the biosecurity gap or simply documents it. The full details appear in Ars Technica's September 2026 report.
Source: Ars Technica AI
More from James Calloway
Show full bio
News editor covering industry trends and analytics at AI In Context.
161 articles
Related articles
- Google DeepMind's SynthID Bio Watermarks AI-Designed Proteins
- AI Developers Weigh Biology's Double Edge: Promise and Biosecurity Risk
- Google DeepMind and Isomorphic Labs unveil joint bioresilience strategy
- AI Watermarking Alters Model Safety Behavior, Research Finds
- Anthropic Says Claude Found a New Enzyme System; CRISPR Researchers Call It Routine