Google DeepMind introduces SynthID Bio to watermark AI-designed protein sequences and structures.

For sequence watermarking, SynthID Bio subtly steers amino-acid choices inside ProteinMPNN: a cryptographic-style key guides suggestions, and the model rejects choices that would not produce a working protein. Detection scans the sequence using the key. The structural method instead adjusts atomic coordinates.
The binder tests involved three targets—VEGF-A, the SARS-CoV-2 spike protein’s receptor-binding domain and PD-L1—and Adaptyv Bio assisted with laboratory testing.
DeepMind says its verification test can detect the signature in the physical protein as well as in the digital design, extending detection beyond analysis of a protein sequence file.
Google DeepMind Chief AI Scientist Demis Hassabis described biosecurity as “one of the most urgent challenges for the AI era” and said the company was open-sourcing SynthID Bio tools for the research community.
Google DeepMind introduced SynthID Bio, a watermarking system that embeds hidden signatures into AI-designed proteins without breaking their function. Phys.org reported that the method adds invisible marks to protein sequences and 3D structures, allowing scientists to identify which designs came from AI systems. The technology is designed to address biosecurity concerns, since AI-generated proteins can be harder for existing screening methods to catch.
In laboratory tests, watermarked proteins retained comparable function and binding strength to unwatermarked designs, TechRepublic reported. Google DeepMind Chief AI Scientist Demis Hassabis described biosecurity as "one of the most urgent challenges for the AI era" and said the company would open-source the SynthID Bio tools for researchers.
SynthID Bio uses two approaches to hide signatures. WebProNews explained that for sequence watermarking, the system subtly steers amino-acid choices inside ProteinMPNN, a protein design model. A cryptographic key guides suggestions while rejecting any choices that would break protein function. Detection scans the sequence using the same key to verify the watermark.
The structural method takes a different approach: it adjusts atomic coordinates in the protein's 3D shape rather than tweaking the sequence. TechRepublic noted that DeepMind's verification test can detect the signature in both the physical protein and the digital design file, extending detection far beyond simple sequence analysis.
Researchers tested watermarked proteins against three targets: VEGF-A, the SARS-CoV-2 spike protein's receptor-binding domain, and PD-L1. The Next Web reported that watermarked binders retained comparable binding affinity and sequence diversity to unwatermarked designs. The structural watermark largely preserved prediction accuracy in 3D shape models.
Adaptyv Bio assisted with the laboratory testing, validating that the hidden signatures did not interfere with real-world protein behavior. Phys.org confirmed that the watermarks remained undetectable while maintaining full biological function. This proof-of-concept demonstrates the method's practical viability for biological traceability.
DeepMind is releasing SynthID Bio tools to the research community, aiming to make watermarking a standard practice. Times of India reported that Hassabis framed the initiative as part of addressing urgent biosecurity challenges in the AI era. The company believes watermarks will help DNA synthesis companies and screening systems identify AI-generated designs more easily.
However, WebProNews noted this is an early step—the watermarking system does not by itself guarantee that DNA synthesis companies can verify all AI-designed proteins or prevent misuse. SynthID Bio is one piece of a larger biosecurity puzzle, not a complete solution to preventing dangerous biological designs from being synthesized.
Publishers
20
Articles
10
Reach
30