Thursday, October 1, 2026 Newsletter Advertise
Breaking
AI

Google DeepMind extends SynthID watermarks to AI-made proteins

The company says its SynthID Bio watermarks survive into physical proteins and could help DNA synthesis providers verify that orders came from trusted AI models.

Google DeepMind extends SynthID watermarks to AI-made proteins. Source: Google DeepMind

Google DeepMind on September 30, 2026 introduced SynthID Bio, which it describes as a proof of concept for watermarking AI-generated proteins while preserving their biological function. The company said the watermark can be verified on the synthesized, physical protein, not only on a digital model.

What the method does

Google DeepMind said SynthID Bio is a family of watermarking methods developed specifically for synthetic biology to strengthen biosecurity and scientific integrity.

According to the company, the approach adapts to the type of data, subtly guiding the choice of amino acids for sequences and adjusting atomic coordinates for predicted 3D structures to create a signal that detectors can pick up. DeepMind said that in experiments these adjustments did not compromise the protein's biological function.

For protein folding, the company said SynthID Bio fine-tunes a small part of AlphaFold 3's diffusion network so that the watermarking ability is built into the model's weights, meaning predicted 3D coordinates carry a detectable signature regardless of who runs the model. DeepMind said the method preserves AlphaFold 3 prediction accuracy while offering near-perfect detectability and holding up against digital noise or minor coordinate changes.

Lab testing on protein binders

DeepMind said it verified the approach for protein binders using its binder design method AlphaProteo alongside a SynthID Bio-enabled version of ProteinMPNN, which it described as a commonly used protein sequence generation method.

In wet-lab testing across three target proteins — VEGF-A, the SARS-CoV-2 spike protein RBD, and PD-L1 — the company said its watermarked designs matched the hit rate, binding affinity and natural sequence diversity of unwatermarked versions, which it called the first-ever watermarked and biologically functional protein binders. DeepMind thanked Adaptyv Bio for help with in vitro validation.

Why DeepMind frames it as a biosecurity layer

The company compared biosecurity to a "Swiss cheese" defense model in which multiple independent safety measures cover each other's blind spots, and positioned watermarking as a verification layer embedded in the biological design itself.

DeepMind said DNA synthesis screening is a particular pressure point: because AI can create entirely new sequences with little resemblance to known hazards, screeners can no longer assume an unfamiliar sequence is an undiscovered natural organism, and verification can require exhaustive manual reviews that stall research. SynthID Bio, it said, could provide an automated signal proving an order originated from a trusted model with built-in safeguards.

Sarah Carter, a biosecurity policy expert and Principal at Science Policy Consulting who reviewed the work, said: "SynthID Bio is an important piece of the puzzle for tracking the provenance of biological designs." James Diggans, Vice President, Policy and Biosecurity at Twist Bioscience, who provided early feedback on the paper, said watermarking "offers a promising new addition to the biosecurity toolbox."

DeepMind added that the technique could help keep databases such as the Protein Data Bank, UniProt and GenBank free of mislabeled synthetic entries.

Open release and next steps

The company said it is publishing its methods paper, open-sourcing the code and in vitro data, and releasing the weights to the research community.

DeepMind said key remaining challenges include making the watermark more robust against deliberate tampering, and that SynthID Bio could be paired with provenance metadata approaches similar to C2PA for digital media.

In ongoing work with the Hie lab at Stanford University and Arc Institute, the company said it integrated SynthID Bio into the genomic model Evo 2 to watermark the genome of an Evo 2-designed bacteriophage, and that early laboratory testing in bacteria cultures confirmed the watermarked bacteriophages are functional. A technical manuscript is to follow.

What to do

  • Researchers can obtain the published methods paper, open-sourced code, in vitro data and model weights that Google DeepMind says it is releasing to the research community.
  • Organizations interested in collaborating can email synthidbio@google.com with a high-level proposal; DeepMind asks that no confidential or proprietary information be disclosed.
Key facts and where they come from
  • SynthID Bio is presented as a proof of concept for watermarking AI-generated proteins without losing biological function.
    Proof of concept for watermarking AI-generated proteins while preserving biological function.
  • The watermark is intended to be verifiable on the physical synthesized protein, not just the digital model.
    ensuring the watermark is verifiable not just on a digital model but on the synthesized, physical protein itself
  • Wet-lab tests covered VEGF-A, the SARS-CoV-2 spike protein RBD and PD-L1.
    In wet-lab testing across three target proteins (VEGF-A, the SARS-CoV-2 spike protein RBD, and PD-L1), our watermarked designs matched the hit rate, binding affinity, and natural sequence diversity
  • For structures, watermarking is built into AlphaFold 3 model weights via fine-tuning of its diffusion network.
    SynthID Bio fine-tunes a small part of AlphaFold 3’s diffusion network, building the ability to watermark directly into the model’s weights.
  • DeepMind says accuracy is preserved with near-perfect detectability.
    SynthID Bio preserves AlphaFold 3 prediction accuracy while offering near-perfect detectability
  • Code, in vitro data and weights are being released.
    we are publishing our methods paper and open-sourcing the code and in vitro data, and releasing the weights to the research community
  • Work with the Hie lab and Arc Institute watermarked an Evo 2-designed bacteriophage genome.
    we integrated SynthID Bio into Evo 2, an advanced genomic model, to watermark the genome of an Evo 2 designed bacteriophage
  • Remaining work includes tamper robustness.
    key challenges include making the watermark more robust against deliberate tampering

Read the original from Google DeepMind →

The TechUpscale Brief

The day's cyber, AI and tech news in one short email, every weekday morning. Free. Unsubscribe anytime.

I'm most interested in

More AI