← All posts / Research

Watermarks That Survive the Wet Lab: DeepMind's SynthID Bio Signs AI-Designed Proteins

Google DeepMind extends SynthID watermarking to synthetic biology: SynthID Bio embeds a verifiable signature into AI-generated protein sequences and predicted 3D structures — and proves it survives synthesis and wet-lab testing without hurting function.

Watermarks That Survive the Wet Lab: DeepMind's SynthID Bio Signs AI-Designed Proteins

On September 30, 2026, Google DeepMind took a technology it knows intimately — invisible watermarking — and pointed it at a target nobody had cracked before: living molecules. SynthID Bio, announced today with a methods paper, open-source code, in vitro data, and released model weights, embeds an imperceptible, verifiable signature directly into AI-generated protein sequences and predicted 3D structures. Crucially, the watermark is not just a digital artifact: it survives DNA synthesis and registers on the physical, synthesized protein itself, while — according to DeepMind’s wet-lab results — leaving the molecule’s biological function intact.

If that sounds like a niche technical achievement, consider what it is actually answering. Generative AI can now predict protein structures (AlphaFold), design novel binders (AlphaProteo, ProteinMPNN), and even write functional bacteriophage genomes (Evo 2). Each of those capabilities doubles as a biosecurity question: when a DNA synthesis company receives an unfamiliar sequence, the old assumption that “unusual probably means natural” no longer holds. AI can produce sequences with little resemblance to anything in the threat databases that screening systems check against.

How the watermark works

SynthID Bio is not one technique but a family of them, adapted to the type of biological data being generated:

  • Protein sequences. For sequence generation, the method subtly guides the choice of amino acids at certain positions — a statistical bias in the sampling that encodes a detectable signal without pushing the protein away from its functional design.
  • Predicted 3D structures. For structure prediction, the approach is more radical: the team fine-tuned a small part of AlphaFold 3’s diffusion network, baking watermarking capability directly into the model’s weights. Any coordinates the model predicts inherently carry the signature, no matter who runs it or where. DeepMind says the fine-tuned model preserves AlphaFold 3’s prediction accuracy, achieves near-perfect detectability, maintains key structural feature distributions, and holds up against digital noise or minor coordinate perturbations.

That in-the-weights design choice is the philosophically important one. A post-hoc watermark can be stripped by re-running a design through another tool; a watermark that lives in the generator itself means provenance travels with every output by default.

The wet-lab proof

The empirical core of the announcement is the binder validation. Working with AlphaProteo and a SynthID Bio-enabled version of ProteinMPNN, the team designed protein binders against three targets — VEGF-A (a vascular growth factor relevant to cancer and ophthalmology), the SARS-CoV-2 spike protein RBD, and PD-L1 (the checkpoint protein behind several immunotherapies). Across all three, watermarked designs matched unwatermarked controls on hit rate, binding affinity (measured as K_D), and natural sequence diversity. DeepMind credits Adaptyv Bio with support on the in vitro validation, and describes the result as the first-ever watermarked and biologically functional protein binders.

In other words: the signature costs nothing measurable. That is the finding that makes the rest of the announcement plausible.

Why synthesis screening is the real audience

DeepMind frames biosecurity through the “Swiss cheese” model — layered defenses whose holes don’t align. Model-level mitigations, customer vetting, and synthesis screening each catch different risks. SynthID Bio is positioned as a new verification layer embedded in the design itself, and its most direct application is DNA synthesis screening, the choke point where digital designs become physical molecules.

Today, when a synthesis provider screens an order against databases of known hazardous sequences, an AI-designed protein that resembles nothing in those databases triggers either a rejection or an expensive manual review — or, worst case, slips through on the assumption that unfamiliar means natural. A watermark flips that calculus: it is an automated attestation that the order originated from a trusted model with built-in safeguards.

The industry noticed. James Diggans, VP of Policy and Biosecurity at Twist Bioscience, who reviewed the work early, called watermarking “a promising new addition to the biosecurity toolbox” that could focus screening resources on sequences that genuinely warrant closer review. Sarah Carter, a biosecurity policy expert at Science Policy Consulting, framed it as “an important piece of the puzzle for tracking the provenance of biological designs” — one that lets providers streamline screening for customers of watermarked models.

The same logic extends to the scientific record. Public databases — the Protein Data Bank, UniProt, GenBank — increasingly accept submissions that may include AI-generated content, and mislabeled entries can propagate errors into both research and biosecurity decision-making. A watermark embedded at generation time could flag synthetic entries at submission, keeping the provenance of structural data trustworthy as AI fills it faster than humans can audit it.

From proteins to genomes

The most forward-looking part of the announcement is the bacteriophage work. In an ongoing collaboration with the Hie lab at Stanford and the Arc Institute, DeepMind integrated SynthID Bio into Evo 2, the genomic foundation model that earlier this year produced the first AI-designed viable phage genomes. The team watermarked the genome of an Evo 2-designed bacteriophage, and early laboratory testing in bacteria cultures confirmed the watermarked phages remain functional. A technical manuscript is promised soon.

That matters because genome-level design is where biosecurity stakes are highest — and where detection is hardest. If watermarking generalizes from proteins to DNA, it becomes a candidate provenance layer for the entire synthetic biology stack. DeepMind says it is already exploring watermarking for other AI-designed biomolecules like DNA, with what Pushmeet Kohli (who initiated the project) describes as “very promising results.”

Limits, honestly stated

DeepMind is careful not to oversell. The announcement explicitly says no single biosecurity intervention is a silver bullet, and lists robustness against deliberate tampering as an unsolved challenge — an attacker with the right tools might try to launder a design through unwatermarked models or mutate the signature away. The company also suggests pairing watermarks with provenance metadata (a C2PA-for-biology analogue) and central repositories of AI-generated biological data, both of which would require community buy-in that doesn’t yet exist.

There are fair structural critiques, too. A watermark proves a design came from a participating model; it says nothing about designs from non-participating models, open-weight alternatives, or adversarial actors. Adoption by synthesis providers is voluntary. And the detection infrastructure — who can verify a watermark, and under what access controls — will determine whether this becomes genuine public infrastructure or a Google-ecosystem feature.

But as a first, verifiable, openly published step — code, data, and weights released to the research community, with a contact address for partners across biosecurity, gene synthesis, and policy — SynthID Bio answers a question the field has been asking since AlphaFold: if AI can now write biology, can we at least sign our names to it? As of today, the answer is yes, and the signature holds.