AI/News
DeepMind puts a watermark inside AI-designed proteins; the marked binders matched the originals on all three targets
SynthID Bio nudges the choice of amino acids so a synthesised protein carries a detectable signature. DeepMind calls it a proof of concept and says resisting deliberate tampering is still open.
By Daily Aletheia · Checked against the primary source · 30 September 2026 · 2 min read

Google DeepMind introduced SynthID Bio on 30 September, extending its SynthID watermarking to synthetic biology. It calls the work a proof of concept for watermarking AI-generated proteins while preserving their biological function.
How it works
The watermark sits in the biological code itself. For sequences it subtly guides the choice of amino acids; for predicted 3D structures it adjusts atomic coordinates. DeepMind says the signature is verifiable not only on a digital model but on the synthesised, physical protein.
For protein binders, DeepMind used its AlphaProteo design method with a SynthID Bio-enabled version of ProteinMPNN. In wet-lab testing across three target proteins - VEGF-A, the SARS-CoV-2 spike protein RBD and PD-L1 - the watermarked designs matched the hit rate, binding affinity and natural sequence diversity of unwatermarked versions. DeepMind calls them the first watermarked and biologically functional protein binders.
For protein folding, SynthID Bio fine-tunes a small part of AlphaFold 3's diffusion network so the watermark lives in the model's weights. DeepMind says prediction accuracy is preserved with "near-perfect detectability".
Why
DeepMind's case is DNA synthesis screening. Synthesis providers screen orders against databases of known threats. An unfamiliar sequence could once be assumed to be an undiscovered natural organism; AI can now create sequences with little resemblance to known hazards. A watermark would show an order came from a trusted model with built-in safeguards.
James Diggans of Twist Bioscience, who gave early feedback on the paper, called it "a promising new addition to the biosecurity toolbox".
What it is not
DeepMind says no single biosecurity intervention is a silver bullet, and names making the watermark robust against deliberate tampering as a key remaining challenge.
Work with the Hie lab at Stanford and Arc Institute has watermarked the genome of an Evo 2-designed bacteriophage; early testing in bacteria cultures found it functional, with a technical manuscript to follow. The methods paper, code, in-vitro data and model weights are being released to the research community.