On September 30, 2026, Google DeepMind introduced SynthID Bio, a family of methods for invisibly watermarking proteins designed by artificial intelligence (AI). The method embeds an invisible statistical signature by subtly steering amino acid selection in the protein sequence and slightly shifting atomic coordinates in the predicted 3D structure. A paper describing the methodology was published in the journal Nature, and the code, laboratory (in vitro) data, and model weights were released openly.
This mark differs from previous digital watermarks: it can be verified not only in the digital model but also in the synthesized physical protein. SynthID Bio brings Google's proven SynthID watermarking technology into synthetic biology — read more in the Google DeepMind blog.
Function preserved in laboratory tests
DeepMind used its AlphaProteo protein binder design method together with a SynthID Bio–capable version of ProteinMPNN. In wet-lab tests on three target proteins — VEGF-A, the RBD portion of the SARS-CoV-2 spike protein, and PD-L1 — the marked designs performed identically to unmarked variants: target hit rate, binding affinity (KD), and natural sequence diversity were the same. DeepMind calls them the first marked, biologically functional protein binders in history.
"SynthID Bio is an important piece of the puzzle of tracing the origin of biological designs. By linking designs to the model developer, these marks let developers lead on safety and make it easier for synthesis providers to verify customers using those models." — Sarah Carter, biosecurity policy expert, head of Science Policy Consulting (Google DeepMind)
Integration with AlphaFold 3 and Evo 2
For structure prediction, SynthID Bio fine-tunes a small part of AlphaFold 3's diffusion network — the watermarking capability lives in the model weights themselves. As a result, predicted 3D coordinates carry a detectable mark no matter who runs the model. According to DeepMind, detection is near-perfect, while AlphaFold 3's prediction accuracy and the distribution of structural features are preserved.
DeepMind also partnered with Stanford University's Hie Lab and the Arc Institute to integrate SynthID Bio into the Evo 2 genomic model and watermarked a designed bacteriophage genome. Early tests in bacterial cultures confirmed that the marked phages work — Ars Technica covered this as well.
Biosecurity and database integrity
Biosecurity relies on layered defense: model-level safeguards and measures like customer screening cover each other's gaps. DNA synthesis screening stands at the front line of this defense: to turn a digital protein design into a physical molecule, orders go to DNA synthesis providers, and they compare requests against a database of known threats. An unfamiliar sequence could once be assumed to be a not-yet-discovered natural organism, but since AI can create entirely new sequences, screeners can no longer draw that conclusion. SynthID Bio provides an automatic verification signal here — proving that an order came from a trusted model with built-in safeguards.
According to James Diggans, vice president of policy and biosecurity at Twist Bioscience, watermarking is a promising addition to the biosecurity toolkit that can strengthen screening and direct resources toward sequences requiring deeper review.
The method can also help preserve the integrity of open databases such as the Protein Data Bank, UniProt, and GenBank. Most of these databases accept public submissions, and incorrectly labeled synthetic records could disproportionately harm biosecurity decisions. At submission time, the mark helps ensure synthetic records are correctly labeled or set aside for additional review.
Limitations
DeepMind acknowledges the limitations as well: the mark is not yet resistant to deliberate tampering; detecting it requires a secret key held by the model developer, and the key is shared only with trusted partners — synthesis companies and database curators. SynthID Bio is not a commercial product but a research concept.




