Google DeepMind · 2026-09-30 · major
SynthID Bio — DeepMind watermarks AI-designed proteins without breaking them
SynthID Bio is Google DeepMind's method for hiding a detectable watermark inside AI-designed proteins and structures. Lab tests on three targets showed watermarked binders work as well as unmarked ones. Code, data and weights are out for researchers.
A hidden, checkable signature inside AI-designed proteins that does not change what the protein does.
Quick facts
| Maker | Google DeepMind |
|---|---|
| Paper | Nature, "Function-preserving watermarking of AI-generated proteins" |
| Works on | Protein sequences, 3D structures, genome design |
| Lab-tested targets | VEGF-A, SARS-CoV-2 spike RBD, PD-L1 |
| Code license | Apache-2.0 (data CC-BY 4.0) |
| Status | Proof of concept, released to researchers |
What is it?
SynthID Bio brings Google DeepMind's SynthID watermarking to synthetic biology. It hides an invisible signature in the biological code of an AI-designed protein, so the mark can still be checked on the physical protein after it is made. DeepMind calls the result the first watermarked protein binders that still work in the lab.
How does it work?
For sequences, the method gently steers which amino acid the design model picks at each step, using a modified ProteinMPNN with SynthID Text-style logic; a detector then computes g-values to find the signal. For 3D structures, it nudges atomic coordinates by fine-tuning a small part of AlphaFold 3's diffusion network, so the watermark lives in the model weights. The team also watermarked bacteriophage genomes with the Hie lab at Stanford and Arc Institute.
Why does it matter?
DNA synthesis companies screen orders for dangerous sequences, and a watermark gives them an automatic signal that a design came from a trusted model with safeguards. Twist Bioscience said it could help focus review on the sequences that need it. DeepMind says the main open problem is making the mark hold up against deliberate tampering.
Who is it for?
protein designers, biosecurity teams, DNA synthesis providers
Frequently asked questions
- Does the SynthID Bio watermark change how the protein works?
- No, according to Google DeepMind's lab tests. Watermarked SynthID Bio binders for VEGF-A, the SARS-CoV-2 spike protein RBD and PD-L1 matched unwatermarked designs on hit rate, binding affinity and sequence diversity. Adaptyv Bio helped with the in vitro checks, and watermarked bacteriophages were confirmed working in bacterial culture.
- Is SynthID Bio open source?
- Partly. Google DeepMind open-sourced the SynthID Bio sequence code and in vitro data in the google-deepmind/synthidbio GitHub repo under Apache-2.0, with data under CC-BY 4.0. The fine-tuned AlphaFold 3 weights for structures are released to researchers through the AlphaFold 3 repository under its model-parameter terms.
- Can someone remove a SynthID Bio watermark?
- Google DeepMind presents SynthID Bio as a proof of concept and names robustness as its main open challenge. The announcement says future work must make the watermark hold up better against deliberate tampering, so today it is a screening signal for trusted models, not a tamper-proof guarantee.
- Who would use SynthID Bio?
- SynthID Bio is aimed at DNA synthesis screening and at keeping public databases such as the Protein Data Bank, UniProt and GenBank trustworthy. Twist Bioscience gave feedback, and Google DeepMind invites partners to contact synthidbio@google.com about using the method.
Try it
https://github.com/google-deepmind/synthidbio