{"slug": "google-deepmind-can-now-hide-a-watermark-inside-ai-designed-proteins-and-it-in", "title": "Google DeepMind can now hide a watermark inside AI-designed proteins, and it survives in the real molecule", "summary": "Google DeepMind announced SynthID Bio on Wednesday, a watermarking method that hides a secret-key signature in the amino-acid choices of AI-designed protein sequences and remains detectable after the design is synthesized into a physical molecule, according to a paper published in Nature. DeepMind built SynthID Bio into ProteinMPNN and a fine-tuned AlphaFold 3, and lab tests with Adaptyv Bio on binders targeting VEGF-A, the SARS-CoV-2 spike receptor-binding domain and PD-L1 showed the watermarked versions matched unwatermarked versions in hit rate, binding affinity and natural sequence diversity. DeepMind says it is releasing the code, lab data and model weights, while the paper calls the work a technical proof-of-concept that would need industry-wide coordination and standardization for real DNA-synthesis screening.", "body_md": "Pushmeet Kohli, Google DeepMind’s vice president of science and one of the authors of the SynthID Bio announcement, at SXSW London in June 2026 (file photo). Image: [Photographer.JuliaMustard](https://commons.wikimedia.org/wiki/File:Pushmeet_Kohli_at_SXSW_London_2026.jpg) / Wikimedia Commons, [CC BY-SA 4.0](https://creativecommons.org/licenses/by-sa/4.0/), cropped\n\nGoogle DeepMind has found a way to sign the proteins its AI designs. SynthID Bio, [announced on Wednesday](https://deepmind.google/blog/introducing-synthid-bio/) alongside a [paper in Nature](https://www.nature.com/articles/s41586-026-10965-y), hides an invisible watermark in the protein’s own building blocks, one that can still be detected after the design has been made into a physical molecule in a lab.\n\n## How do you watermark a protein?\n\nSynthID started as DeepMind’s way of marking AI-generated text, images and audio. SynthID Bio applies the same idea to biology. When an AI model designs a protein sequence, it usually has several almost equally good amino acids to choose from at each position. SynthID Bio nudges those choices in a pattern that only someone holding a secret key can recognise, much as the text version does with words.\n\nDeepMind built it into ProteinMPNN, a widely used tool for designing protein sequences, and into a fine-tuned version of AlphaFold 3, so that the 3D structures it predicts carry a hidden signature too. Because the watermark sits in the model’s weights, it is there “regardless of who runs the model,” DeepMind says.\n\n## Does the protein still work?\n\nThat was the real test. A watermark is useless if it breaks the protein. DeepMind designed binders, proteins built to latch onto a target, for three targets: VEGF-A, the receptor-binding domain of the SARS-CoV-2 spike protein and PD-L1. In lab tests run with Adaptyv Bio, the watermarked versions “matched the hit rate, binding affinity, and natural sequence diversity of unwatermarked versions,” the company says, making them the first watermarked protein binders shown to work.\n\nThe AlphaFold version kept the model’s prediction accuracy while offering what DeepMind calls “near-perfect detectability.” With Stanford’s Hie lab and the Arc Institute, the team has also watermarked the genome of a bacteriophage, a virus that infects bacteria, designed by the Evo 2 model. Early tests show those phages still function.\n\n## Why DNA screeners care\n\nThe main target is biosecurity. To turn a digital design into a real protein, scientists order DNA from synthesis companies, which screen orders against databases of known threats. AI can now design sequences that look like nothing in those databases, so an unfamiliar order can no longer be assumed to be a harmless natural one. A watermark could show quickly that a design came from a model with safeguards built in.\n\nSarah Carter, a biosecurity policy expert who reviewed the work, said:\n\nSynthID Bio is an important piece of the puzzle for tracking the provenance of biological designs.\n\nSarah Carter, Principal, Science Policy Consulting\n\nJames Diggans, vice president of policy and biosecurity at DNA maker Twist Bioscience, called it “a promising new addition to the biosecurity toolbox that could strengthen screening.” DeepMind says it is publishing the code, the lab data and the model weights for researchers.\n\n## What it can’t do yet\n\nThe paper calls SynthID Bio “a technical proof-of-concept.” Anyone designing a dangerous protein with a model that doesn’t add the watermark won’t be caught by it, and DeepMind says making the mark harder to strip out on purpose is still an open problem. Using it for real screening would need “industry-wide coordination and standardization,” the paper says. DeepMind describes it as one layer in a “Swiss cheese” defence, not a fix on its own.\n\nIt lands as AI biology tools get more capable. Claude recently [turned up a new CRISPR-like system on its own](https://madrobot.blog/2026/09/23/claude-discovers-crispr-like-enzyme-system-art/), and DeepMind’s new boss has said [Gemini 4 is coming sooner than expected](https://madrobot.blog/2026/09/25/gemini-4-coming-much-earlier-deepmind-kavukcuoglu/).\n\n## Why it matters\n\nThe fear that AI could help someone design a dangerous pathogen is one of the most serious in AI safety, and DNA synthesis screening is one of the few real checkpoints. A watermark that survives into the physical molecule gives screeners a new signal, but it only works if the companies building these models agree to use it.\n\n*Sources: [Google DeepMind](https://deepmind.google/blog/introducing-synthid-bio/), [Nature: “Function-preserving watermarking of AI-generated proteins”](https://www.nature.com/articles/s41586-026-10965-y).*", "url": "https://wpnews.pro/news/google-deepmind-can-now-hide-a-watermark-inside-ai-designed-proteins-and-it-in", "canonical_source": "https://madrobot.blog/2026/09/30/google-deepmind-synthid-bio-watermark-ai-designed-proteins-dna-biosecurity/", "published_at": "2026-09-30 15:31:00+00:00", "updated_at": "2026-09-30 15:50:10.295660+00:00", "lang": "en", "topics": ["ai-safety", "ai-research", "artificial-intelligence", "ai-policy"], "entities": ["Google DeepMind", "SynthID Bio", "ProteinMPNN", "AlphaFold 3", "Adaptyv Bio", "Nature", "Pushmeet Kohli", "Evo 2"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/google-deepmind-can-now-hide-a-watermark-inside-ai-designed-proteins-and-it-in", "markdown": "https://wpnews.pro/news/google-deepmind-can-now-hide-a-watermark-inside-ai-designed-proteins-and-it-in.md", "text": "https://wpnews.pro/news/google-deepmind-can-now-hide-a-watermark-inside-ai-designed-proteins-and-it-in.txt", "jsonld": "https://wpnews.pro/news/google-deepmind-can-now-hide-a-watermark-inside-ai-designed-proteins-and-it-in.jsonld"}}