Google DeepMind hid a watermark inside AI-designed proteins, and in lab tests they still worked
SynthID Bio marks AI-made protein designs so DNA synthesis companies can check where an order came from. In wet-lab tests, marked designs matched unmarked ones.
Google DeepMind has introduced SynthID Bio, which it calls a "proof of concept for watermarking AI-generated proteins while preserving biological function." The idea is to place an invisible signature inside the biological code itself, so it can be checked not only in a digital file but on the physical protein made in a lab.
Why it matters: to turn a protein design into a real molecule, someone orders DNA from a synthesis company, and those companies screen orders against databases of known threats. An unfamiliar sequence used to be safely treated as an undiscovered natural organism. Because AI can now create entirely new sequences, DeepMind says "screeners can no longer make that assumption." A watermark could give them an automated signal that an order came from a trusted model with built-in safeguards, instead of slow manual reviews.
How it works depends on the data. For sequences, the method subtly guides the choice of amino acids. For predicted 3D structures, it adjusts atomic coordinates, and DeepMind fine-tuned a small part of AlphaFold 3 so the signature is built into the model's weights.
The key test: in wet-lab experiments on three target proteins, watermarked designs matched unwatermarked ones on hit rate, binding affinity and sequence diversity. Twist Bioscience, which gave early feedback on the paper, called watermarking "a promising new addition to the biosecurity toolbox".
DeepMind says it is publishing the methods paper, open-sourcing the code and lab data, and releasing the weights to researchers.
Open it and check the claim yourself. That is the point.