Skip to content
nanoai

DeepMind watermarks AI-designed proteins without breaking them

A Nature paper shows a hidden signature can ride inside working protein binders. It helps honest designers prove where a sequence came from. It does not stop a determined one.

By The Nano AI Staff3 min read

AI research graphic showing Google DeepMind's SynthID Bio technology watermarking AI-designed proteins, with colorful molecular protein structures, DNA imagery, laboratory test equipment, and a Nature research publication reference.
Image: AI Generated

Key takeaways

  • SynthID Bio hides a checkable signature in AI-designed proteins that still worked in lab tests.
  • It helps DNA makers verify orders from trusted tools but cannot flag unwatermarked designs.
  • The paper estimates a known binder can be rewritten to lose the mark and often still work.

Google DeepMind has shown that a hidden, checkable signature can be built into proteins designed by AI without stopping them from working. The method, SynthID Bio, was published in Nature on Wednesday, September 30, and DeepMind says it is open-sourcing the code and lab data and releasing the model weights to the research community.

The paper calls the work “a proof-of-concept that function-preserving biological watermarking is feasible”. That is the right size for the claim. It is a useful tool for honest designers. It is not a way to catch dishonest ones.

How you hide a mark in a protein

A protein is a chain of amino acids, and design software chooses which one goes where. SynthID Bio nudges those choices using a secret key, so the finished sequence carries a statistical pattern that can be checked with the key. A second version fine-tunes AlphaFold 3, DeepMind’s structure model, so that the mark sits in the predicted 3D positions of atoms.

The detection numbers are strong in the paper’s tests. With a threshold set to allow 0.1% false alarms, the sequence method caught 100% of watermarked designs, and the structure method’s detection rate exceeded 99.8% for every model tested.

The harder question was whether the mark would damage the protein. DeepMind made binders, proteins built to latch on to a target, against three targets: VEGF-A, the receptor-binding domain of the SARS-CoV-2 spike, and PD-L1. Adaptyv Bio helped run the lab tests. The paper found “no significant population-level differences” in binding strength between watermarked and unwatermarked binders.

Who would check it

DeepMind’s main pitch is DNA synthesis screening. Companies that make DNA to order have to check whether a sequence could be dangerous, and unfamiliar designs can mean slow manual reviews. DeepMind says SynthID Bio can provide “an automated verification signal, proving an order originated from a trusted model with built-in safeguards”. James Diggans of Twist Bioscience called watermarking “a promising new addition to the biosecurity toolbox that could strengthen screening”.

Look at what that sentence promises. The watermark vouches for designs from cooperating tools, so it speeds up the easy cases. It says nothing about a design made with software that adds no watermark, which is where the biosecurity worry actually lives.

What the paper admits

The authors are candid about the limits. The sequence method is a zero-bit scheme, meaning it signals that a watermark is present but carries no other information, and it is “susceptible to further resequencing” with ProteinMPNN, the same kind of design tool it builds on. The paper’s own estimates show what that means. An attacker who starts from a known watermarked binder and rewrites its sequence, using structure-based filters, would still get working binders at estimated hit rates of 97%, 70% and 66% across the three targets. Stripping the mark, in other words, need not cost much function.

The structure version has its own gap. The paper says it does not yet hold up to relaxation, a standard clean-up step applied to predicted structures. DeepMind lists resistance to deliberate tampering as a key challenge still ahead.

Where it goes next

DeepMind is already pushing past proteins. With the Hie lab at Stanford University and the Arc Institute, it built SynthID Bio into Evo 2, a genome model, to watermark the genome of a bacteriophage that Evo 2 designed. Sarah Carter, a biosecurity policy expert, called the tool “an important piece of the puzzle for tracking the provenance of biological designs”.

A piece, not the puzzle. What to watch is whether DNA synthesis companies build watermark checks into their screening, whether other makers of design software, especially open-source ones, adopt the scheme, and whether outside researchers who now have the code can strip the mark more cheaply than the paper estimates.

  • SynthID
  • Google DeepMind
  • Biosecurity
  • Protein design
  • Nature

Sources

  1. Function-preserving watermarking of AI-generated proteins — Nature (Stutz et al., Google DeepMind), Sep 30, 2026
  2. SynthID Bio: Watermarking methods for synthetic biology — Google DeepMind, Sep 30, 2026
  3. Google DeepMind’s watermarked AI proteins still work in the lab — The Next Web, Oct 1, 2026

Follow The Nano AI: Instagram · X · LinkedIn · YouTube

Was this article helpful?

Comments

No comments yet. Start the conversation.

Be respectful. Comments are moderated.

Related stories

The AI briefing, without the noise.

The stories that matter in AI, sourced and explained. Free, and you can unsubscribe at any time.