Google DeepMind can now watermark AI-designed proteins, and the mark survives in the physical molecule
The mark lives in the protein's own amino acids, so a DNA synthesis company could check where an unfamiliar order came from.
On September 30, 2026, Google DeepMind introduced SynthID Bio, a set of watermarking methods for proteins designed by AI. The paper came out in Nature the same day, and Demis Hassabis posted about it on X that afternoon.
SynthID has marked AI images, text and video since 2023. This one goes into the protein itself, so you can check it on the physical molecule a lab makes. What surprised me is that the watermarked proteins still worked just as well in DeepMind's lab tests, though.
- Who
- Google DeepMind
- What
- SynthID Bio, watermarking methods for synthetic biology
- Tested on
- three target proteins (VEGF-A, the SARS-CoV-2 spike protein RBD, and PD-L1)
- Released
- the code, in vitro data and weights
How does a protein carry a watermark?

Two ways, one for each kind of data. For a protein sequence, SynthID Bio nudges which amino acids the design model picks, a little at a time, so the choices add up to a pattern only a detector can see. For a predicted 3D structure it shifts the atomic coordinates instead. Tiny shifts.
For structures, DeepMind fine-tuned a small part of AlphaFold 3's diffusion network. So the mark lives in the weights, and it shows up whoever runs the model. Prediction accuracy held, the team says.
Then the real test. DeepMind made protein binders with AlphaProteo and a watermarking version of ProteinMPNN, then tested them in a wet lab against three targets.
our watermarked designs matched the hit rate, binding affinity, and natural sequence diversity of unwatermarked versions
Who would check it?
Mostly the companies that turn a design into DNA. They screen every order against databases of known threats, and an AI-made sequence can look like nothing in them, which today means someone reviews it by hand. Slowly. A watermark would tell the screener the order came from a model with safeguards built in.
Twist Bioscience (it's one of those companies) gave early feedback on the paper. Its biosecurity policy lead, James Diggans, called watermarking "a promising new addition to the biosecurity toolbox". DeepMind also sees a use in keeping public databases like the Protein Data Bank and GenBank honest about which entries are synthetic.
Hassabis put it to his followers as a safety step first, and pointed at the open-source release.
Biosecurity is one of the most urgent challenges for the AI era. Bringing SynthID to biology so AI-generated proteins can be watermarked is a critical step - and we’re open sourcing SynthID Bio tools so the research community can build on this work. Published in @Nature today, congrats to the team! https://t.co/Y4sv8bnGQY
What it can't do yet
Survive a determined attacker, for one. DeepMind's own post says the watermark has to hold up better against deliberate tampering, and that's the gap I'd worry about, because the people a biosecurity check most wants to catch are the ones likeliest to try.
The team has also put the watermark into the genome of a bacteriophage designed with Evo 2, working with the Hie lab at Stanford and Arc Institute. Early tests in bacteria cultures show the marked phages still work (DeepMind says a technical manuscript on it is coming soon).
More on Google
- Current Google DeepMind and OpenAI researchers say on camera that AI could end humanitySeptember 30, 2026
- Gemini Call for Me phones businesses from your own number and opens by saying it's AISeptember 29, 2026
- Google says stolen AI accounts sell at up to 99% off, but prices more than doubledSeptember 28, 2026
- Google sends its AI chips to orbit next week, ahead of its two-satellite test in 2027September 24, 2026