AI & ML 4 min read

DeepMind Can Watermark AI-Designed Proteins. Redesigning Them Largely Erases the Mark.

SynthID Bio hides a signal in protein sequences and AlphaFold 3 structures without hurting function, the Nature paper shows. It says only "AI-made", and resequencing can remove it.

Maya Lin
Digital Platforms Analyst
Published 1 Oct 2026, 7:09 AM (SGT)
Share:
Illustration of glowing blue DNA double helices Illustration of glowing blue DNA double helices Photo by Sunriseforever on Pixabay
Advertisement

1 OCT 2026 — Google DeepMind has shown it can hide a watermark in AI-designed proteins without stopping them from working. SynthID Bio, described in Nature on 30 September, is the method. The catch, reported in the same paper, is that running a watermarked protein through another design tool can largely remove the mark.

The aim is to let companies that make DNA to order, as well as databases that store protein structures, tell whether a design came from an AI model.

Why it is needed

Companies that synthesise DNA screen orders against databases of known toxins and pathogens. AI can now design proteins with sequences that look like nothing in those databases, yet may still do a similar job once made. "Novel AI designs can bypass traditional DNA synthesis screening," DeepMind says in its announcement.

A watermark does not say what a protein does. It only says that an AI tool produced it, which a screener could use to decide which orders need a closer look.

3Target proteins for which watermarked binders were made and tested
99.8%+Detection rate for watermarked structures at a 0.1% false-positive rate
0 bitsInformation carried beyond "AI-made"
RemovableResequencing attacks largely erased the sequence watermark

How it works

For sequences, the method nudges which amino acids a design tool picks, leaving a statistical pattern a detector can find. For 3D structures, DeepMind fine-tuned part of AlphaFold 3 so its predictions carry tiny, imperceptible shifts in atom positions. Because the mark is built into the model's weights, it is present no matter who runs the model.

What the tests showed

In laboratory tests, watermarked proteins designed to latch onto three targets, including the SARS-CoV-2 spike protein and the cancer-related PD-L1, bound as well as unwatermarked versions, the paper reports. For structures, the detector found more than 99.8% of watermarked predictions while falsely flagging 0.1% of others, with negligible loss of accuracy.

The catch

The authors tested attempts to remove the mark. Redesigning a watermarked protein's sequence with another tool, keeping its shape, "largely" removed the watermark, the paper says. The watermark also carries only one bit of meaning (that a tool made it) and cannot say which tool or who used it.

Advertisement

The biosecurity researcher Tessa Alexanian told Nature's news team that it is best seen as one more tool in a layered defence against biological threats. DeepMind calls making the mark harder to tamper with a key challenge.

Who would use it

Nature reports that the watermark would be detected with a secret key shared with trusted partners such as DNA manufacturers. James Diggans of Twist Bioscience, a DNA synthesis company, said in DeepMind's post that it "could strengthen screening". DeepMind says it is releasing the code, laboratory data and model weights to researchers, and has applied the method to DNA of a bacteriophage designed with the Evo 2 model, in work with Stanford and the Arc Institute.

The paper calls the system a proof of concept. Whether it becomes a safeguard depends on other model builders adopting something like it, since a mark applied by only one company's tools can be avoided by using another tool.

Advertisement
Maya Lin
Digital Platforms Analyst

Maya Lin covers SaaS platforms, workflow automation, creator tools, and productivity software for RECATOOLS.

View author profile → · Editorial policy

About this byline Maya Lin is a RECATOOLS editorial persona used for platform and productivity coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Corrections policy

Advertisement