cd /news/ai-safety/google-deepmind-unveils-synthid-bio-… · home › topics › ai-safety › article
[ARTICLE · art-142730] src=officechai.com ↗ pub= topic=ai-safety verified=true sentiment=↑ positive

Google DeepMind Unveils SynthID Bio, Creates World’s First Watermarked AI-Designed Proteins That Still Work In The Lab

Google DeepMind introduced SynthID Bio, a watermarking method that tags AI-generated proteins without damaging their function, and said it is the first time AI-designed proteins that are both watermarked and functional have been successfully synthesised. DeepMind paired AlphaProteo with a SynthID Bio-enabled version of ProteinMPNN and reported that in wet-lab tests against VEGF-A, the SARS-CoV-2 spike protein RBD and PD-L1, watermarked designs matched unwatermarked ones on hit rate, binding affinity and natural sequence diversity; it also fine-tuned part of AlphaFold 3's diffusion network so predicted coordinates carry the signature in the model's weights. Pushmeet Kohli, who leads science and strategic initiatives at Google DeepMind, said SynthID has already watermarked more than 100 billion images and videos and over 60,000 years of audio, and DeepMind is working with the Hie lab at Stanford University and the Arc Institute to apply SynthID Bio to the genomic model Evo 2.

read4 min views1 publishedSep 30, 2026
Google DeepMind Unveils SynthID Bio, Creates World’s First Watermarked AI-Designed Proteins That Still Work In The Lab
Image: Officechai (auto-discovered)

Google DeepMind has introduced SynthID Bio, a family of watermarking methods designed to tag AI-generated proteins without damaging their function. The company says it is the first time AI-designed proteins that are both watermarked and functional have been successfully synthesised.

The work extends SynthID, DeepMind’s watermarking technology for AI-generated images, video, audio and text, into synthetic biology. Unlike a watermark on a picture, though, a biological watermark has to survive inside a physical molecule that must fold, bind and behave exactly as its unmarked equivalent would.

How it works #

SynthID Bio adapts to the kind of data it is marking. For protein sequences, it subtly nudges the choice of amino acids as the sequence is generated. For predicted 3D structures, it adjusts atomic coordinates. In both cases, the aim is to leave a signal that can be detected later, including on the synthesised physical protein and not just on the digital model.

DeepMind tested the approach on protein binders, which are molecules built to latch onto specific target proteins. It paired AlphaProteo, its binder design system, with a SynthID Bio-enabled version of ProteinMPNN, a widely used protein sequence generation method.

In wet-lab tests against three targets, VEGF-A, the SARS-CoV-2 spike protein RBD and PD-L1, the watermarked designs matched unwatermarked ones on hit rate, binding affinity and natural sequence diversity, according to DeepMind.

For structure prediction, the team fine-tuned a small part of AlphaFold 3’s diffusion network so that the watermarking ability sits in the model’s weights. That means predicted coordinates carry the signature regardless of who runs the model. DeepMind says this preserves AlphaFold 3’s prediction accuracy while offering near-perfect detectability, and that the signal holds up against digital noise and minor coordinate changes.

Why it matters for biosecurity #

The pitch is largely about biosecurity. DNA synthesis providers screen orders against databases of known threats, but AI can now generate sequences that look nothing like known hazards. An unfamiliar sequence can no longer be safely assumed to be a harmless natural organism, and verifying it often means slow manual review that can stall legitimate research.

SynthID Bio could offer an automated signal that an order came from a trusted model with built-in safeguards. DeepMind frames it as one layer in a “Swiss cheese” model of defence, alongside model-level mitigations and customer vetting.

Sarah Carter, a biosecurity policy expert who reviewed the work, said watermarks “empower developers to lead on safety” and help synthesis providers streamline screening for customers who use those models. James Diggans of Twist Bioscience called watermarking a promising addition to the biosecurity toolbox that could help focus resources on sequences that warrant closer review.

Keeping public databases clean #

The second use case is scientific integrity. Open databases such as the Protein Data Bank, UniProt and GenBank accept public submissions, and the rising volume of AI-generated predictions risks polluting them with mislabelled entries. Watermarks could help flag synthetic submissions for proper labelling or review.

Pushmeet Kohli, who leads science and strategic initiatives at Google DeepMind, described it as a way to preserve the “scientific commons”, noting that breakthroughs like AlphaFold depend on clean public data. Kohli also said SynthID has already been used to watermark more than 100 billion images and videos and over 60,000 years of audio, and is used by partners including OpenAI, NVIDIA and Kakao.

From proteins to genomes #

DeepMind is also working with the Hie lab at Stanford University and the Arc Institute to apply SynthID Bio to Evo 2, a genomic model. The team watermarked the genome of an Evo 2-designed bacteriophage, a virus that infects bacteria, and early testing in bacterial cultures suggests the watermarked phages remain functional. A technical manuscript is expected soon.

Limits and what’s next #

DeepMind is clear that watermarking is not a silver bullet. Its main stated challenge is making the watermark more robust against deliberate tampering. It suggests pairing SynthID Bio with provenance metadata, similar to C2PA for digital media, or with central repositories of AI-generated biological data.

The company is publishing its methods paper, open-sourcing the code and in vitro data, and releasing the weights to the research community. It is also inviting partnership proposals from groups in biosecurity, gene synthesis and policy.

The release comes as AI’s role in biology keeps expanding, from structure prediction to de novo design to drug discovery. DeepMind CEO Demis Hassabis has predicted that AI could give humanity a real shot at solving all disease within 10-15 years, and as the tools that design proteins and even genomes get more powerful, the case for building provenance and safeguards into them at the outset only gets stronger. As Kohli put it, progress should be measured not just by the complexity of the biology AI can model, but by the “foresight and responsibility” with which those capabilities are guided.

── more in #ai-safety 4 stories · sorted by recency
── more on @google deepmind 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/google-deepmind-unve…] indexed:0 read:4min 2026-09-30 · —