AI Affairs, home

Friday 2 October 2026

Technology

Google DeepMind introduces SynthID Bio to watermark AI-designed proteins

In laboratory tests, watermarked protein binders performed comparably to unwatermarked designs; the company is also applying the method to predicted structures and bacteriophage genomes.

Pushmeet Kohli speaks into a microphone against a colourful backdrop at SXSW London 2026
Photo: Photographer.JuliaMustard, CC BY-SA 4.0, via Wikimedia Commons (cropped)

Google DeepMind introduced SynthID Bio on 30 September 2026, describing it as a proof of concept for marking AI-designed proteins so their origin can be checked after they are made. The company says its sequence watermark remained detectable in synthesised proteins while tested designs retained their biological function. SynthID Bio brings Google DeepMind’s existing SynthID watermarking tool to synthetic biology.

Key points

  • Google DeepMind tested watermarked protein binders against VEGF-A, the SARS-CoV-2 spike protein RBD and PD-L1.
  • The company says the designs matched unwatermarked versions on hit rate, binding affinity and natural sequence diversity in laboratory testing.
  • A separate method puts a detectable signature into AlphaFold 3’s predicted protein structures.
  • Google DeepMind is releasing methods, code, laboratory data and model weights for further research.

AlphaProteo binders face three protein targets

For protein sequences, SynthID Bio steers the choice of amino acids, the components arranged in a particular order to make a protein. A binder needs that arrangement to latch onto its target, so changing it to carry a signature could also change whether the binder works. Google DeepMind says its method makes small choices during design rather than adding a visible label afterwards, allowing a detector to find the signature in the resulting protein.

The company generated binders using AlphaProteo together with a SynthID Bio-enabled version of ProteinMPNN, which generates protein sequences. It then tested designs in the laboratory against VEGF-A, the SARS-CoV-2 spike protein RBD and PD-L1. Google DeepMind reports that its watermarked designs matched unwatermarked versions on hit rate, binding affinity and natural sequence diversity across those targets. Binding affinity measures how strongly a binder attaches to its target; the company assessed it using KD, for which a lower value denotes stronger binding.

Those measurements address a practical constraint on any protein watermark: a detectable design would be of little use if the changes stopped the molecule doing its intended job. Google DeepMind calls the tested binders biologically functional. The laboratory comparison it describes concerns binders for the three named targets, rather than every kind of protein a design model might produce.

AlphaFold 3 marks predicted coordinates

SynthID Bio takes a different route for predicted three-dimensional structures. Google DeepMind says it fine-tunes a small part of AlphaFold 3’s diffusion network, placing the marking behaviour in the model’s weights. That lets the model produce atomic coordinates carrying a detectable pattern. Coordinates describe where atoms sit in a prediction, much as points on a map describe locations; a change to those points is distinct from a change to the amino-acid sequence used to make a protein.

Google DeepMind says the marked predictions retain AlphaFold 3’s accuracy and key structural feature distributions, with near-perfect detectability. It also says the signature withstands digital noise and minor changes to the coordinates. These are the company’s results for predicted structures. The physical-protein verification described in its announcement concerns the sequence watermark, whose amino-acid choices persist when the designed molecule is synthesised.

DNA synthesis screening gains another signal

The proposed use reaches beyond identifying a design in a laboratory. DNA synthesis providers screen orders against databases of known threats, Google DeepMind says, while AI can produce unfamiliar sequences with little resemblance to known hazards. Checking such orders can require extensive manual review. A detectable watermark could give a provider an automated indication that a sequence came from a model with built-in safeguards, though the company presents it as one layer alongside other screening measures.

Ordering a DNA sequence could therefore involve a provenance check as well as a comparison with known threats. If an unfamiliar design carried a detectable signature, that check could help direct closer review without treating the signature alone as proof that the order was safe.

Sarah Carter, a biosecurity policy expert and Principal at Science Policy Consulting who reviewed the work, said linking designs to a model developer could help developers take responsibility for safety and help synthesis providers screen customers using those models. James Diggans, Vice President, Policy and Biosecurity at Twist Bioscience, provided early feedback on the paper and described watermarking as a possible addition to screening. Their comments concern how the method could be used, rather than the laboratory measurements of binder performance.

Google DeepMind also proposes checking submissions to the Protein Data Bank, UniProt and GenBank so AI-generated material can be labelled or flagged for review. The company says incorrectly labelled synthetic structures could mislead research that relies on public databases. It identifies resistance to deliberate tampering as a remaining challenge for SynthID Bio.

Evo 2 extends the work to bacteriophages

Google DeepMind says it has worked with the Hie lab at Stanford University and Arc Institute to put SynthID Bio into Evo 2, a genomic model, and watermark the genome of an Evo 2-designed bacteriophage. Its early tests in bacterial cultures found that the watermarked bacteriophages remained functional. This moves the experiment from individual protein designs towards a more complex biological object, under the early laboratory conditions the company describes.

Google DeepMind says it is publishing a methods paper, open-sourcing the code and in vitro data, and releasing model weights to the research community.

Topics: Foundation models, Healthcare, Safety