DeepMind watermarks AI-designed proteins without breaking them
A Nature paper shows a hidden signature can ride inside working protein binders. It helps honest designers prove where a sequence came from. It does not stop a determined one.

Key takeaways
- SynthID Bio hides a checkable signature in AI-designed proteins that still worked in lab tests.
- It helps DNA makers verify orders from trusted tools but cannot flag unwatermarked designs.
- The paper estimates a known binder can be rewritten to lose the mark and often still work.
Google DeepMind has shown that a hidden, checkable signature can be built into proteins designed by AI without stopping them from working. The method, SynthID Bio, was published in Nature on Wednesday, September 30, and DeepMind says it is open-sourcing the code and lab data and releasing the model weights to the research community.
The paper calls the work “a proof-of-concept that function-preserving biological watermarking is feasible”. That is the right size for the claim. It is a useful tool for honest designers. It is not a way to catch dishonest ones.
How you hide a mark in a protein
A protein is a chain of amino acids, and design software chooses which one goes where. SynthID Bio nudges those choices using a secret key, so the finished sequence carries a statistical pattern that can be checked with the key. A second version fine-tunes AlphaFold 3, DeepMind’s structure model, so that the mark sits in the predicted 3D positions of atoms.
The detection numbers are strong in the paper’s tests. With a threshold set to allow 0.1% false alarms, the sequence method caught 100% of watermarked designs, and the structure method’s detection rate exceeded 99.8% for every model tested.
The harder question was whether the mark would damage the protein. DeepMind made binders, proteins built to latch on to a target, against three targets: VEGF-A, the receptor-binding domain of the SARS-CoV-2 spike, and PD-L1. Adaptyv Bio helped run the lab tests. The paper found “no significant population-level differences” in binding strength between watermarked and unwatermarked binders.
Who would check it
DeepMind’s main pitch is DNA synthesis screening. Companies that make DNA to order have to check whether a sequence could be dangerous, and unfamiliar designs can mean slow manual reviews. DeepMind says SynthID Bio can provide “an automated verification signal, proving an order originated from a trusted model with built-in safeguards”. James Diggans of Twist Bioscience called watermarking “a promising new addition to the biosecurity toolbox that could strengthen screening”.
Look at what that sentence promises. The watermark vouches for designs from cooperating tools, so it speeds up the easy cases. It says nothing about a design made with software that adds no watermark, which is where the biosecurity worry actually lives.
What the paper admits
The authors are candid about the limits. The sequence method is a zero-bit scheme, meaning it signals that a watermark is present but carries no other information, and it is “susceptible to further resequencing” with ProteinMPNN, the same kind of design tool it builds on. The paper’s own estimates show what that means. An attacker who starts from a known watermarked binder and rewrites its sequence, using structure-based filters, would still get working binders at estimated hit rates of 97%, 70% and 66% across the three targets. Stripping the mark, in other words, need not cost much function.
The structure version has its own gap. The paper says it does not yet hold up to relaxation, a standard clean-up step applied to predicted structures. DeepMind lists resistance to deliberate tampering as a key challenge still ahead.
Where it goes next
DeepMind is already pushing past proteins. With the Hie lab at Stanford University and the Arc Institute, it built SynthID Bio into Evo 2, a genome model, to watermark the genome of a bacteriophage that Evo 2 designed. Sarah Carter, a biosecurity policy expert, called the tool “an important piece of the puzzle for tracking the provenance of biological designs”.
A piece, not the puzzle. What to watch is whether DNA synthesis companies build watermark checks into their screening, whether other makers of design software, especially open-source ones, adopt the scheme, and whether outside researchers who now have the code can strip the mark more cheaply than the paper estimates.
- SynthID
- Google DeepMind
- Biosecurity
- Protein design
- Nature
Sources
- Function-preserving watermarking of AI-generated proteins — Nature (Stutz et al., Google DeepMind), Sep 30, 2026
- SynthID Bio: Watermarking methods for synthetic biology — Google DeepMind, Sep 30, 2026
- Google DeepMind’s watermarked AI proteins still work in the lab — The Next Web, Oct 1, 2026
Related stories

Anthropic finds open GLM-5.3 close to Mythos at building exploits
Zhipu's open-weight model wrote working Chrome-engine exploits in 50 of 410 attempts, against 56 for Anthropic's restricted Mythos Preview, and its refusals could be stripped for about $4,400 of compute.
3 min read

OpenAI’s chief scientist co-signs call to oversee self-improving AI
A 22-author paper, with Geoffrey Hinton, Yoshua Bengio and Anthropic’s Jack Clark among the names, says AI may soon automate most AI research and asks governments to prepare.
3 min read

Stanford lab lets GPT Astra run a humanoid through five skills
HomeBody gives a frontier chat model a Unitree G1 body, a digital twin of the room and a short list of motor skills, with no robot action model trained in between. It has not published success rates.
3 min read
Comments
No comments yet. Start the conversation.