Science4 publishers2 min readPublished Updated
DeepMind's SynthIDBio embeds a detectable watermark in AI-designed proteins without loss of function
Google DeepMind's SynthIDBio hides a watermark in AI-designed proteins that a detector reads near-perfectly without weakening how they bind. The authors call it a proof of concept, and a determined user can still scrub the mark by rerunning a design through another tool.
The Scientist · Science desk

What happened
- The sequence method builds the watermark into ProteinMPNN, the model many labs already use to write an amino-acid sequence onto a chosen protein backbone.
- A second method, SynthIDBio-structure, is a fine-tuned version of AlphaFold3 that hides an imperceptible mark in a molecule's 3D structure.
- The mark can be read only with a secret detection key, which DeepMind would share with trusted partners such as DNA synthesis companies.
- DeepMind is releasing the methods, the code, its in vitro data and the model weights to the research community.
Compiled by The ScientistSomething wrong?How this is made
Why it matters
- capability Synthesis providers screening DNA orders could get an automated signal that a design came from a trusted model, and reserve slow manual review for orders that carry none.
- constraint The mark catches designs that pass through untouched but not a determined adversary who regenerates the sequence, so it works only as a layer inside broader biosecurity defenses.
- decision Open repositories like the Protein Data Bank, UniProt and GenBank could label or flag AI-generated submissions at intake, before mislabeled entries distort later biosecurity calls.
The engineering claim is narrow. DeepMind wove a watermark into both a protein's amino-acid sequence and its 3D shape [1]. That is harder than marking text or an image, because a designed protein has to keep working after you hide a signal in it. A binder has to bind. Earlier methods for watermarking predicted structures cost a noticeable amount of accuracy [9].
So the test that counts is whether a marked protein still does its job. Pushmeet Kohli and his team at DeepMind "stress-tested the approach on a number of challenging problems," he said [11]. The watermarked binders bound to targets tied to viral infection, blood-vessel formation and immune regulation about as well as unmarked designs [12]. The paper, in Nature, reports comparable binding affinity and near-perfect detection but does not attach a figure to either [6][7][8].
The way around the mark is described by the researchers, not skated over. Run a watermarked protein through a different design tool and you can generate a new sequence that keeps the shape and function while dropping the signal [13]. Tessa Alexanian, a biosecurity researcher formerly at the International Biosecurity and Biosafety Initiative for Science in Geneva, calls it one tool in a layered framework [14]. "We're in a wild new world," she said [15].
Even so, it helps where screening is weakest. Synthesis providers check DNA orders against databases of known toxins and pathogen proteins, and an AI design can resemble nothing in those references even when the finished protein behaves like a known hazard [17][18]. James Diggans, vice-president of policy and biosecurity at the synthesis firm Twist Bioscience, said watermarking "could strengthen screening, focus resources on sequences that warrant closer review and make biosecurity more efficient" [20].
The signal is deliberately thin. It reveals only that a protein came from an AI tool, nothing about what the protein does [16]. Function screening still has to happen; the mark tells a reviewer which orders to weigh, not what they encode.
DeepMind calls the work a proof of concept for function-preserving biological watermarking [10]. The function-preservation part is the strong result and was the harder engineering problem; durability is the weaker part, and the team lists making the mark resist deliberate tampering as the next step [23].
What to watch
- Whether DNA synthesis firms and database maintainers actually adopt the detection keys, which only work if trusted partners hold them.
- The technical manuscript DeepMind has promised on watermarking the genome of an Evo 2-designed bacteriophage that stayed functional in culture.
- Whether independent labs reproduce the near-perfect detection and comparable binding using the released weights, code and in vitro data.