Security1 publisher2 min readPublished
DeepMind's SynthID Bio watermark passes wet-lab tests without harming protein binders
Google DeepMind's SynthID Bio watermark matched unwatermarked binders on hit rate, affinity and sequence diversity across three wet-lab targets. The company aims it at DNA synthesis screeners, who could use the signal to auto-clear orders from safeguarded AI models.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- SynthID Bio hides its signature in two places, the amino acid sequence and the predicted 3D atomic coordinates, and DeepMind says both can be read off the physical protein after synthesis.
- The binder tests paired DeepMind's AlphaProteo designer with a watermarked ProteinMPNN, running against VEGF-A, the SARS-CoV-2 spike receptor-binding domain and PD-L1.
- For 3D structure prediction, DeepMind wrote the watermark into AlphaFold 3's weights by fine-tuning part of its diffusion network, so every set of coordinates the model emits carries it.
- In separate work with Stanford's Hie lab and the Arc Institute, DeepMind watermarked an Evo 2-designed bacteriophage genome, and early bacterial-culture tests found the phages still functional.
- DeepMind is publishing the methods paper, open-sourcing the code and in vitro data, and releasing the model weights to the research community.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint Automation built on this signal can only whitelist: it confirms trusted origin, not biological risk, so a hazardous design routed around the watermarking model stays invisible to the check.
- exposure DeepMind lists resistance to deliberate tampering as unmet, so an actor who strips the signature slips the check it is meant to anchor.
- precedent Pointed at the Protein Data Bank, UniProt and GenBank, the same mark could flag synthetic entries for review as researchers submit them.
Screening runs on comparison. A synthesis provider takes a digital design and checks the sequence against databases of known hazards before making the molecule. [4] DeepMind's starting point is that the comparison is becoming unreliable: AI can now generate sequences that resemble nothing in those databases, so an unfamiliar order can no longer be waved off as some undiscovered natural organism. [5] Checking one by hand can hold up a legitimate project. [6]
The watermark adds provenance. Its signal marks an order as coming from a model that carries SynthID Bio and its safeguards. [7] A design from a model that never applied the mark arrives looking exactly as it did before, and a determined actor would place that order. DeepMind frames the watermark as one layer next to model-level mitigations and customer vetting, each with its own gaps. [17] To harden it, the company suggests pairing the mark with provenance metadata or central repositories of AI-generated biological data. [18]
On detectability, DeepMind calls the signal near-perfect but does not cite a rate in its blog post. [14] It reports that AlphaFold 3 kept its prediction accuracy with the watermark in place and that the signature survived digital noise and minor coordinate changes in testing. [13]
James Diggans, VP of policy and biosecurity at Twist Bioscience, gave early feedback on the paper. He called watermarking "a promising new addition to the biosecurity toolbox that could strengthen screening." [19]
What to watch
- The technical manuscript DeepMind says will follow on the Evo 2 watermarked bacteriophage work.
- Whether any synthesis provider wires the signal into live screening, and how it treats orders without a mark.
- Progress on tamper resistance, which DeepMind lists as the unmet challenge.