1 OCT 2026 — Google DeepMind has shown it can hide a watermark in AI-designed proteins without stopping them from working. SynthID Bio, described in Nature on 30 September, is the method. The catch, reported in the same paper, is that running a watermarked protein through another design tool can largely remove the mark.
The aim is to let companies that make DNA to order, as well as databases that store protein structures, tell whether a design came from an AI model.
Why it is needed
Companies that synthesise DNA screen orders against databases of known toxins and pathogens. AI can now design proteins with sequences that look like nothing in those databases, yet may still do a similar job once made. "Novel AI designs can bypass traditional DNA synthesis screening," DeepMind says in its announcement.
A watermark does not say what a protein does. It only says that an AI tool produced it, which a screener could use to decide which orders need a closer look.
How it works
For sequences, the method nudges which amino acids a design tool picks, leaving a statistical pattern a detector can find. For 3D structures, DeepMind fine-tuned part of AlphaFold 3 so its predictions carry tiny, imperceptible shifts in atom positions. Because the mark is built into the model's weights, it is present no matter who runs the model.
What the tests showed
In laboratory tests, watermarked proteins designed to latch onto three targets, including the SARS-CoV-2 spike protein and the cancer-related PD-L1, bound as well as unwatermarked versions, the paper reports. For structures, the detector found more than 99.8% of watermarked predictions while falsely flagging 0.1% of others, with negligible loss of accuracy.
The catch
The authors tested attempts to remove the mark. Redesigning a watermarked protein's sequence with another tool, keeping its shape, "largely" removed the watermark, the paper says. The watermark also carries only one bit of meaning (that a tool made it) and cannot say which tool or who used it.
The biosecurity researcher Tessa Alexanian told Nature's news team that it is best seen as one more tool in a layered defence against biological threats. DeepMind calls making the mark harder to tamper with a key challenge.
Who would use it
Nature reports that the watermark would be detected with a secret key shared with trusted partners such as DNA manufacturers. James Diggans of Twist Bioscience, a DNA synthesis company, said in DeepMind's post that it "could strengthen screening". DeepMind says it is releasing the code, laboratory data and model weights to researchers, and has applied the method to DNA of a bacteriophage designed with the Evo 2 model, in work with Stanford and the Arc Institute.
The paper calls the system a proof of concept. Whether it becomes a safeguard depends on other model builders adopting something like it, since a mark applied by only one company's tools can be avoided by using another tool.