ThinkFacility Sign in
  1. Home
  2. News
  3. Google

Google DeepMind can now watermark AI-designed proteins, and the mark survives in the physical molecule

The mark lives in the protein's own amino acids, so a DNA synthesis company could check where an unfamiliar order came from.

On September 30, 2026, Google DeepMind introduced SynthID Bio, a set of watermarking methods for proteins designed by AI. The paper came out in Nature the same day, and Demis Hassabis posted about it on X that afternoon.

SynthID has marked AI images, text and video since 2023. This one goes into the protein itself, so you can check it on the physical molecule a lab makes. What surprised me is that the watermarked proteins still worked just as well in DeepMind's lab tests, though.

Who
Google DeepMind
What
SynthID Bio, watermarking methods for synthetic biology
Tested on
three target proteins (VEGF-A, the SARS-CoV-2 spike protein RBD, and PD-L1)
Released
the code, in vitro data and weights

How does a protein carry a watermark?

Demis Hassabis, in glasses, speaks at a wooden press table behind his name card, with John Jumper in a red tie beside him
Demis Hassabis and John Jumper at the 2024 Nobel Prize press conference at the Royal Swedish Academy of Sciences. Photo: Jennifer 8. Lee, CC BY-SA 4.0, via Wikimedia Commons

Two ways, one for each kind of data. For a protein sequence, SynthID Bio nudges which amino acids the design model picks, a little at a time, so the choices add up to a pattern only a detector can see. For a predicted 3D structure it shifts the atomic coordinates instead. Tiny shifts.

For structures, DeepMind fine-tuned a small part of AlphaFold 3's diffusion network. So the mark lives in the weights, and it shows up whoever runs the model. Prediction accuracy held, the team says.

Then the real test. DeepMind made protein binders with AlphaProteo and a watermarking version of ProteinMPNN, then tested them in a wet lab against three targets.

our watermarked designs matched the hit rate, binding affinity, and natural sequence diversity of unwatermarked versions

From SynthID Bio: Watermarking methods for synthetic biology — Google DeepMind

Who would check it?

Mostly the companies that turn a design into DNA. They screen every order against databases of known threats, and an AI-made sequence can look like nothing in them, which today means someone reviews it by hand. Slowly. A watermark would tell the screener the order came from a model with safeguards built in.

Twist Bioscience (it's one of those companies) gave early feedback on the paper. Its biosecurity policy lead, James Diggans, called watermarking "a promising new addition to the biosecurity toolbox". DeepMind also sees a use in keeping public databases like the Protein Data Bank and GenBank honest about which entries are synthetic.

Hassabis put it to his followers as a safety step first, and pointed at the open-source release.

Demis Hassabis@demishassabis · Google

Biosecurity is one of the most urgent challenges for the AI era. Bringing SynthID to biology so AI-generated proteins can be watermarked is a critical step - and we’re open sourcing SynthID Bio tools so the research community can build on this work. Published in @Nature today, congrats to the team! https://t.co/Y4sv8bnGQY

View the post on X

What it can't do yet

Survive a determined attacker, for one. DeepMind's own post says the watermark has to hold up better against deliberate tampering, and that's the gap I'd worry about, because the people a biosecurity check most wants to catch are the ones likeliest to try.

The team has also put the watermark into the genome of a bacteriophage designed with Evo 2, working with the Hie lab at Stanford and Arc Institute. Early tests in bacteria cultures show the marked phages still work (DeepMind says a technical manuscript on it is coming soon).

More on Google

All Google stories