Lifestyle

Google DeepMind Launches SynthID Bio: Hidden Watermarks for AI-Designed Proteins

On September 30, 2026, Google DeepMind announced SynthID Bio, a way to embed invisible, checkable watermarks in proteins designed by AI. The company says it could help DNA synthesis companies screen orders and help scientific databases label AI-generated entries. The aim is to strengthen biosecurity as AI designs more biology. It is still a proof of concept, and all claims come from Google.

About 7 min read

Google DeepMind Launches SynthID Bio: Hidden Watermarks for AI-Designed Proteins
Image: Mokaair (Original editorial artwork)

What is SynthID Bio?

According to Google's announcement on September 30, 2026, SynthID Bio extends Google's existing SynthID watermarking technology to synthetic biology, the field in which scientists design and build new biological molecules. A watermark here is a hidden signature: it cannot be noticed by looking at the design, but it can be detected later to show where the design came from. Google DeepMind describes SynthID Bio as a family of watermarking methods developed specifically for synthetic biology and calls it a proof of concept. It embeds these watermarks directly into biological designs, such as AI-generated protein sequences and predicted 3D structures.

Google DeepMind emphasizes two points. First, the watermark can be verified not only in the digital design but also in the physical protein once it has been made. Second, the proteins kept their biological function in laboratory tests.

Google DeepMind Launches SynthID Bio: Hidden Watermarks for AI-Designed Proteins
Mokaair editorial verification flow · Image: Mokaair (Original editorial artwork)
Read the full description

Sources are collected, independently checked, then reviewed by Jev.

How it works: two approaches for sequences and structures

According to Google DeepMind, SynthID Bio adapts its approach to the type of data. For protein sequences, which list a protein's building blocks (amino acids) in order, it subtly guides which amino acids are chosen. For predicted 3D structures, which describe a protein's shape, it adjusts the positions of atoms. In both cases the changes create a signal that can be detected later.

The first test involved protein binders, which are molecules built to selectively latch onto other proteins. Google DeepMind says it validated the method using AlphaProteo, its binder design method, together with a SynthID Bio-enabled version of ProteinMPNN, a commonly used tool for generating protein sequences.

The second test involved protein folding, meaning the prediction of a protein's 3D shape. Here SynthID Bio fine-tunes a small part of the diffusion network inside AlphaFold 3, Google DeepMind's structure-prediction model. This builds the watermark into the model's weights, the internal settings the model learned during training. As a result, predicted structures carry a detectable signal no matter who runs the model.

The two watermarking approaches compared (source: Google DeepMind, not independently verified)
ItemSequence watermarking (protein binders)Structure watermarking (protein folding)
What gets watermarkedAI-generated protein sequencesPredicted 3D structures
HowGuides the choice of amino acidsAdjusts atomic coordinates by fine-tuning a small part of the AlphaFold 3 diffusion network
Tools usedAlphaProteo and a SynthID Bio-enabled ProteinMPNNAlphaFold 3
Results reported by Google DeepMindIn wet-lab experiments on three target proteins, hit rate, binding affinity and sequence diversity matched unwatermarked versionsPrediction accuracy preserved, near-perfect detectability, and the watermark withstands digital noise or minor coordinate changes

Google DeepMind states that the three test targets were VEGF-A, the SARS-CoV-2 spike protein RBD and PD-L1. The tests were wet-lab experiments, meaning they were done with real molecules in a laboratory rather than only on a computer. The company says the watermarked designs matched unwatermarked ones in three respects: hit rate, binding affinity and natural sequence diversity. Binding affinity is how strongly a binder attaches to its target; Google DeepMind measured it as KD, where a lower value means a stronger binder. The company calls these the first-ever watermarked, biologically functional protein binders. It also says Adaptyv Bio helped with in vitro validation, meaning tests carried out in the lab outside living organisms.

Why it matters: biosecurity and database integrity

To turn a digital protein design into a physical molecule, a scientist places an order with a DNA synthesis provider. The provider screens each request against databases of known threats. Google DeepMind notes that novel AI designs could bypass this traditional screening. It also warns that mislabeled synthetic 3D structures could pollute public databases and mislead later research. The company compares biosecurity to a "Swiss cheese" model, in which several independent safety measures cover each other's blind spots. It presents SynthID Bio as a verification layer built into the biological design itself.

Google DeepMind explains why this matters for screening. In the past, an unfamiliar sequence could safely be assumed to be an undiscovered natural organism. Because AI can create entirely new sequences, screeners can no longer make that assumption. Checking such orders by hand can stall research. The company says SynthID Bio can provide an automated verification signal showing that an order came from a trusted model with built-in safeguards. For databases such as the Protein Data Bank, UniProt and GenBank, the company says SynthID Bio could help label synthetic entries properly or flag them for further review when they are submitted.

The Google DeepMind post also quotes two outside experts. Sarah Carter, a biosecurity policy expert who reviewed the work, calls SynthID Bio "an important piece of the puzzle for tracking the provenance of biological designs." James Diggans of Twist Bioscience, who gave early feedback on the paper, calls watermarking "a promising new addition to the biosecurity toolbox." Both quotes appear in Google DeepMind's own post.

Limitations and next steps

  • Robustness: Google DeepMind says a key challenge is making the watermark more resistant to deliberate tampering.
  • Combining with other tools: the company says SynthID Bio could be paired with provenance metadata approaches, which attach origin information to a file, similar to C2PA for digital media. It could also be paired with central repositories of AI-generated biological data.
  • More complex targets: Google DeepMind says it worked with the Hie lab at Stanford University and Arc Institute to integrate SynthID Bio into Evo 2, an advanced genomic model. The goal was to watermark the genome of a bacteriophage (a virus that infects bacteria) designed by Evo 2. Early laboratory testing in bacteria cultures confirmed that these watermarked bacteriophages are functional, and the company says it will share more details in a technical manuscript soon.
  • Open research: the company says it is publishing a methods paper, open-sourcing the code and in vitro data, and releasing the model weights to the research community.

What it means for general readers

Most people will never use SynthID Bio directly. It does reflect a trend: AI is no longer only generating text and images but is also helping design biology, and labeling where content came from is extending from digital media to biological data. If DNA synthesis providers and databases adopt mechanisms like this, researchers may find it easier to tell which data was generated by AI. For now, however, SynthID Bio remains what Google DeepMind calls a proof of concept.

Frequently asked questions

When was SynthID Bio announced, and by whom?

Google and Google DeepMind announced SynthID Bio on September 30, 2026.

Does adding a watermark stop the proteins from working?

According to Google DeepMind, no. In wet-lab experiments on three targets (VEGF-A, the SARS-CoV-2 spike protein RBD and PD-L1), watermarked designs matched unwatermarked ones in hit rate, binding affinity and sequence diversity. These results were published by Google alone.

Does the watermark exist only in computer files?

No. Google DeepMind says the watermark can be verified not only in the digital design but also in the physical protein once it has been made.

Can SynthID Bio completely prevent misuse of biological designs?

No. Google DeepMind says no single biosecurity measure is a silver bullet and presents SynthID Bio as one layer in a multi-layered defense. The company also acknowledges that making the watermark resist deliberate tampering is still an open challenge.

Can researchers use it?

Google DeepMind says it is publishing a methods paper, open-sourcing the code and in vitro data, and releasing the model weights to the research community.

Browse the latest news in this topic

Latest travel guides

Sources

Lifestyle