Google DeepMind introduced SynthID Bio on September 30, a way to watermark proteins designed by AI without breaking them. In lab tests on three targets, watermarked protein binders matched unwatermarked ones on how often they worked, how tightly they bound and how varied they were, DeepMind says. It is sharing the code, lab data and model weights with researchers.
New to this? Read it in simple words
- Proteins are tiny machines in living things, and AI can now design new ones.
- DeepMind found a way to hide a secret mark inside AI-designed proteins.
- In lab tests, the marked proteins worked as well as unmarked ones.
- The mark could help companies that make DNA spot designs from trusted AI tools.
- Watermark
- A hidden sign that shows where something came from.
- Protein
- A molecule made of a chain of amino acids that does work in living things.
- Biosecurity
- Protecting people from dangerous germs and toxins, including man-made ones.
How it works
A popular design tool, ProteinMPNN, builds a protein one amino acid at a time to fit a planned shape. SynthID Bio uses a secret key to steer some of those choices, but only where the protein will still work, Ars Technica explains.
The signal ends up spread thinly along the whole sequence. To check for it, software scans the sequence with the key and counts how often the steered choices appear.
DeepMind also made a version for predicted 3D structures by fine-tuning a small part of AlphaFold 3, so the mark sits in the model itself. It says the watermark can be checked on the physical protein, not only on a computer file.
From DeepMind’s announcement and Ars Technica’s explanation of the paper.
What the lab tests showed
DeepMind designed protein binders for three targets: VEGF-A, part of the coronavirus spike protein, and PD-L1. In lab tests, watermarked designs matched unwatermarked ones on hit rate, binding strength and natural variety, it says.
A hit rate is the share of designs that bind their target. Binding is a simpler job than the work an enzyme does, Ars Technica notes, but the results suggest the mark does not break proteins.
Separately, DeepMind and researchers at Stanford University and the Arc Institute watermarked the genome of a bacteriophage, a virus that infects bacteria, designed with the Evo 2 model. Early tests suggest it still works, and that study is not yet published.
What it can and cannot do
With keys from trusted groups such as universities and biotech firms, DNA makers could quickly confirm that a design came from a trusted tool, and focus on the orders that did not. It does not guarantee that an order is safe, Ars Technica notes.
The researchers point to weak spots, Ars Technica reports. The system is only as safe as its keys, very short proteins may carry too little signal, and joining a marked protein to an unmarked one could dilute it. Many design tools do not use ProteinMPNN.
DeepMind says it is sharing the code, lab data and model weights with researchers. James Diggans of Twist Bioscience, a DNA maker, gave early feedback on the paper and called watermarking “a promising new addition to the biosecurity toolbox”.
Sources
Every fact in this story comes from the sources below. Open them to check our work.
- 1
- 2
- 3Research · October 1, 2026Google’s SynthID Bio can watermark AI-designed protein binders without breaking them Help Net Security
We read DeepMind’s announcement and compared Ars Technica and Help Net Security. The lab results are DeepMind’s own, and the method is described in a paper in Nature that we could not open. Ars Technica’s account of how the key works is based on that paper.