The Watermark Lives in the Molecule Itself: DeepMind's SynthID Bio Aims to Expose AI-Designed Proteins
Google DeepMind launched a watermarking system for AI-designed proteins on 30 September 2026, covered in Nature. The system, called SynthID Bio, embeds a faint statistical signature into both the amino-acid sequence and the three-dimensional shape of proteins designed on a computer — without noticeably compromising function. The technique is borrowed from watermarking of images, video, audio and text, but here the provenance signal sits in the molecule itself, not in file metadata. At the same time, both the company and Nature are clear about a significant limitation: in many cases, the mark can be washed away by anyone who wants to remove it.
Why This Is Coming Now
The background is that AI protein-design tools are increasingly able to produce sequences that bear little resemblance to anything in existing screening databases. That makes it difficult for DNA synthesis companies and biosecurity authorities to distinguish AI-generated designs from natural proteins. SynthID Bio is DeepMind's answer: an embedded provenance signature intended to reveal that a design came from an AI model — provided the mark survives, and provided the detection key is in the hands of those doing the checking.
How the Watermarking Works
The watermark is to be added automatically in AI tools such as AlphaFold and RFdiffusion, according to Nature's reporting. Detection requires a secret key shared only with trusted partners, such as DNA synthesis companies. Ordinary users will therefore not be able to see or search for the mark — it is an arrangement between DeepMind and the screening actors.
For structure prediction, Google has fine-tuned a smaller part of the diffusion network in AlphaFold 3, so that the watermark sits in the network weights themselves. No matter who uses the model, the output thus carries the mark. Google claims "nearly perfect detectability," but the announcement contains no numbers supporting that claim — for now it stands as a company statement without published documentation.
Unlike adding metadata to a file, the provenance signal here is built into the biological design itself, and is thus intended to survive the design being moved between software systems. That is the point that distinguishes SynthID Bio from a file note: the molecule carries its own history with it.
The Lab Tests: Function Survives
The published documentation concerns binders — proteins designed to bind to other proteins. The researchers combined AlphaProteo with a SynthID Bio-equipped version of ProteinMPNN and designed binders for three targets: VEGF-A, which is involved in the formation of blood vessels; the receptor-binding domain (RBD) of the SARS-CoV-2 spike protein; and PD-L1, which is involved in immune regulation.
The results from wet-lab testing show that the watermarked designs perform roughly on par with unwatermarked designs on three points: hit rate, binding affinity and sequence diversity. The figures are company-reported. Pushmeet Kohli, a computer scientist at DeepMind, told Nature that the team "stress-tested the approach on a number of challenging problems," and that the watermarked proteins bound the targets just as effectively as the unwatermarked ones.
Worth noting: according to the analyst Shugo Nozaki, who has reviewed the official announcement, the watermarking of the amino-acid sequence and the watermarking of the 3D coordinates are two separate experimental results, which should not be conflated. Complete functional preservation has also not been shown for all types of proteins and targets — only for the binders tested.
The Catch: The Mark Can Be Removed
Nature describes the limitation plainly: the molecular stamp can be washed out. Anyone wanting to shed the "made by AI" label can, in many cases, run a watermarked protein through a different design tool and get a new sequence that preserves the protein's structure and function but hides its synthetic origin.
Google itself acknowledges that making the signal tamper-resistant remains an unsolved problem, and that watermarking is not a complete biosecurity solution. A central open question is how resistant such watermarks are to deliberate alteration or removal attempts. In other words: the system works against those who do not actively try to conceal origin — and biosecurity scenarios typically concern precisely the actors who do.
Provenance Is Not Safety
Nozaki points to a distinction that easily gets lost in coverage: knowing the origin of something is not the same as knowing it is safe. It cannot be said that a design without a watermark is dangerous, or that a design with a watermark is harmless. A watermarked protein is not thereby harmless, and an unwatermarked one is not thereby dangerous.
That means SynthID Bio should be read as a screening tool for synthesis companies — a signal that can trigger closer examination — not as a safety guarantee or a tamper-proof stamp. The company itself frames it as one layer in a broader defense, not as the solution.
What Comes Next
Two things lie ahead. First, Google is to release code, lab data and model weights to researchers, making it possible to independently test both detectability and robustness — figures for which published documentation is still lacking. Second, Google, in collaboration with Brian Hie's lab at Stanford University and the Arc Institute, has applied the watermarks to the genome of a bacteriophage — a virus that infects bacteria — using the Evo 2 genome framework. This extension to genomes is preliminary: the testing is described as successful, but a technical paper has not yet been published, and the level of verification should not be equated with the protein-binder experiments.
The open question, then, is not whether watermarking biological design is technically possible — according to Nature's reporting on the work, the results show that it is — but whether the signal can withstand resistance. Until independent researchers can test the code, data and weights Google has promised to release, SynthID Bio is a promising screening tool with a known and acknowledged weakness: those who know how can wash the mark out of the protein.
Sources:

