The Invisible Signature: Google DeepMind Has Started Watermarking AI-Designed Proteins

Published:

AI can now design proteins that nature never made. That is mostly very good news: new binders, enzymes and drug candidates, made faster than any human team could manage. It also raises an awkward question that nobody has been able to answer well. When a strange new protein sequence turns up in a lab order or a public database, how do you know where it came from?

On Wednesday 30 September 2026, Google DeepMind offered one answer. In a paper in Nature titled “Function-preserving watermarking of AI-generated proteins”, and in a companion blog post, the lab introduced SynthID Bio, a way to hide an invisible signature inside proteins designed by AI. (The paper writes it as “SynthIDBio”; the blog uses two words.)

The headline result is simple. The watermarked proteins still worked.

First, What Is a Protein Watermark?

You have probably heard of watermarks for AI images and text. Google already uses a system called SynthID to tag content from its own generative models. The idea is to leave a faint statistical pattern that people can’t see, but that software holding a secret key can detect.

Proteins turn out to be well suited to the same trick.

A protein is a chain of building blocks called amino acids. There are 20 common ones, usually written as single letters. A designed protein is, in effect, a long string of those letters. The string folds into a 3D shape, and the shape decides what the protein does.

Here is the key point. For a given shape, there is often more than one letter that would work at a particular position. Design software picks between these near-equivalent options all the time. SynthID Bio quietly steers those picks in a pattern that only someone with the detection key can recognise.

Think of it like this. Imagine writing a letter where, every time you could say either “big” or “large”, you follow a secret rule for which one to use. The letter reads the same to anyone. But a person holding your rulebook could run through it and say, with high confidence, “this was written by someone using the rulebook.” SynthID Bio does that with amino acids instead of words.

What DeepMind Actually Did

The paper describes two related methods.

1. Watermarking protein sequences. The team built the watermark into ProteinMPNN, a widely used open tool that chooses amino-acid sequences to fit a designed protein shape. They used it to design “binders”, proteins made to grip onto a specific target protein, against three targets:

  • VEGF-A, a protein involved in blood-vessel growth
  • the receptor-binding domain of the SARS-CoV-2 spike protein, the part of the Covid virus that latches onto human cells
  • PD-L1, a protein involved in immune regulation and a common target in cancer immunotherapy

Then came the step that makes this a real result rather than a computer simulation. The designs were made and tested in the wet lab (actual test tubes, not software), with help from the protein-testing company Adaptyv Bio. According to DeepMind, the watermarked binders matched the unwatermarked ones on hit rate (how many designs actually worked), on binding strength and on sequence diversity. DeepMind calls them “the first-ever watermarked and biologically functional protein binders.”

On detection, the paper reports that with a threshold set so only 0.1% of unmarked designs would be wrongly flagged, the filtered watermarked designs in the lab study were detected 100% of the time.

2. Watermarking predicted 3D structures. The second method fine-tunes a small part of AlphaFold 3, DeepMind’s structure-prediction model, so that the 3D shapes it predicts carry a hidden signal in the exact positions of their atoms. The paper reports detection rates above 99.8% at the same 0.1% false-alarm level, with no meaningful loss of prediction accuracy. The mark also survived small amounts of added noise and the structure being rotated or moved.

Why This Matters: A Concrete Example

To see why anyone would bother, follow a designed protein from the screen to the bench.

Say a university lab uses an AI tool to design a new protein that might block a cancer target. To make it, they order the matching DNA from a gene-synthesis company. Those companies screen every order against databases of known dangerous sequences, such as toxins and pieces of pathogens.

For years, screeners could reasonably assume that an unfamiliar sequence was probably just an undiscovered natural one. DeepMind’s blog points out that AI breaks that assumption, because AI can produce sequences that look like nothing in any database. An unfamiliar order now might mean a harmless new design, or it might mean something engineered to slip past the checks. Working out which one usually means a slow manual review.

A watermark gives the screener one more piece of information: this sequence came from a known model that has its own safety measures built in. The order can then go through faster, and human attention can go to the orders that really need it.

James Diggans, vice-president of policy and biosecurity at the DNA-synthesis firm Twist Bioscience, who gave early feedback on the paper, said in DeepMind’s announcement that watermarking “could strengthen screening, focus resources on sequences that warrant closer review and make biosecurity more efficient.”

There is a second use, which is less dramatic but probably just as important. Public scientific databases such as the Protein Data Bank, UniProt and GenBank accept submissions from researchers all over the world. As AI-generated structures pile up, there is a real risk of mislabelled entries: a predicted or invented structure being treated as one measured from nature. A watermark could help flag synthetic entries when they are submitted.

What It Does Not Prove

This is where it pays to read the paper itself, not just the press release. The authors are frank about the limits.

The watermark can be removed. The most important caveat: if someone runs a watermarked design back through ordinary, unwatermarked ProteinMPNN, the sequence watermark is wiped out. The paper notes that this is easy, because browser-based versions of ProteinMPNN are freely available, and that similar “regeneration attacks” still work against text and image watermarks too. The paper does report that this kind of removal also seemed to lower how often the designs worked, but the authors say more lab studies are needed to measure that properly.

For the 3D-structure watermark, the weak spot is a standard clean-up step called relaxation, in which software adjusts a structure’s atoms into a more physically realistic arrangement. The paper says relaxation “successfully destroys the watermark.”

Nature‘s news coverage put it plainly: the molecular stamp “can be scrubbed away.” Tessa Alexanian, a biosecurity researcher, told Nature the tool is best seen as one more layer of defence, not a fix on its own. DeepMind uses the same picture, describing biosecurity as a “Swiss cheese” model in which several imperfect layers cover each other’s holes.

It only says “AI made this”, nothing more. The current scheme is what researchers call “zero-bit”: it shows a watermark is present, but it can’t say which user or lab made the design. It also says nothing about whether a protein is safe. A watermark tells you something about where a design came from, not whether it is harmless.

It only works for tools that adopt it. The watermark is added by the design software. Someone using an open-source tool without it, or a model built to avoid it, produces unmarked proteins. So a missing watermark proves nothing about safety. The system is most useful for speeding up legitimate work, not for catching determined bad actors.

The lab results were not perfect across the board. The overall finding was that watermarking had little effect on how well the binders worked. But the paper also reports that, at one looser binding threshold, one watermark setting had a significantly lower hit rate than unwatermarked designs. That doesn’t overturn the main result, but it is a reminder that “no effect” here means “small, mostly not significant effects in this study”, not “zero cost forever”.

It is a proof of concept. The paper says so in as many words. The lab tests covered binders for three targets. Real-world use would need synthesis companies, database curators and other AI developers to agree on how keys are shared and checked. That is a policy and coordination problem as much as a technical one.

What Comes Next

DeepMind says it is open-sourcing the code and lab data and releasing model weights to researchers, so others can test and try to break the method. That is the right instinct for a security tool: watermarks only earn trust once outsiders have attacked them hard.

The lab also says it has added SynthID Bio to Evo 2, a genome-design model, working with the Hie lab at Stanford University and the Arc Institute. Together they watermarked the genome of an AI-designed bacteriophage, a virus that infects bacteria rather than people. DeepMind says early tests in bacterial cultures showed the watermarked phages worked, but that work has not yet been published in full; the lab says a technical paper is coming. Until then, treat it as a claim rather than a result.

The Bottom Line

SynthID Bio does not make AI-designed biology safe. Nothing on its own does. What it shows is narrower and still worth knowing: you can hide a reliable “made by AI” signature inside a working protein, and in these lab tests the protein still did its job.

That gives DNA-synthesis companies and database curators a new signal to work with, at a time when AI is producing sequences faster than humans can check them. It also comes with an honest asterisk. Anyone determined to remove the mark can probably do so with freely available tools.

So read it as a sensible first layer, published openly so others can test it, and not as a lock on the door. The harder work of agreeing who holds the keys, who checks them and what happens when a mark is missing is only beginning.

Sources

  1. Stutz, D. et al. “Function-preserving watermarking of AI-generated proteins.” Nature, published online 30 September 2026. https://www.nature.com/articles/s41586-026-10965-y
  2. Google DeepMind, “Introducing SynthID Bio” (Pushmeet Kohli, David Stutz, Ali Cowen-Rivers, Jeremy Ratcliff), 30 September 2026. https://deepmind.google/blog/introducing-synthid-bio/
  3. Google, “SynthID Bio watermarks AI-designed proteins”, 30 September 2026. https://blog.google/innovation-and-ai/models-and-research/google-deepmind/synthid-bio/
  4. Elie Dolgin, “Secret watermark labels proteins as ‘made by AI'”, Nature news. https://www.nature.com/articles/d41586-026-03033-y
  5. The Next Web, “Google DeepMind’s watermarked AI proteins still work in the lab”, 1 October 2026. https://thenextweb.com/news/google-deepmind-synthid-bio-watermark-ai-designed-proteins
TSN
TSNhttps://tsnmedia.org/
Welcome to TSN. I'm a data analyst who spent two decades mastering traditional analytics—then went all-in on AI. Here you'll find practical implementation guides, career transition advice, and the news that actually matters for deploying AI in enterprise. No hype. Just what works.

Related articles

Recent articles