Skip to content
Skip to content

Independent e-magazine

the OUTSPOKEN digest

Google DeepMind Watermarked AI-Designed Proteins That Still Worked After Being Made in a Lab

SynthID Bio embeds a signature in AI-generated protein sequences and structures that survives physical synthesis without hurting how well the protein binds its target, a step meant to help trace the origin of synthetic biological material.

Outspoken Digest Technology Desk

Thursday, October 1, 2026/3 min read

A visualisation of a protein's three-dimensional structure, illustrative of the kind of AI-designed proteins described in this report and not one of the specific molecules named, photographed in October 2010
Photo: Idaho National Laboratory via Wikimedia Commons (CC BY 2.0)

Google DeepMind published details on Wednesday of SynthID Bio, a watermarking system that embeds an imperceptible, verifiable signature into AI-designed protein sequences and their predicted three-dimensional structures without compromising how the proteins actually perform once made. Google's own announcement of the technology said the goal is to "strengthen biosecurity and preserve the integrity of open scientific databases," giving regulators and gene synthesis screening providers a way to trace whether a given biological design originated from an AI system.

A watermark that survives being built in a lab

The breakthrough DeepMind is highlighting is not simply that a digital watermark can be embedded in a protein's design file, but that the signature survives physical synthesis and the resulting real protein still binds its intended target, something the company says has not previously been demonstrated for AI-designed proteins that are both watermarked and functional. That distinction matters because a watermark that only works on paper, surviving in a computer file but lost once a protein is actually synthesised in a wet lab, would be of limited use to anyone trying to trace real biological material back to its AI origin.

Tested against three real molecular targets

DeepMind validated the approach in laboratory tests across three target proteins, vascular endothelial growth factor, known as VEGF-A, the receptor-binding domain of the SARS-CoV-2 spike protein, and PD-L1, with the company's own writeup stating plainly that "in laboratory tests across target proteins, our watermarked designs successfully matched the performance and natural diversity of unwatermarked versions." Binding affinity measurements for the watermarked proteins showed distributions nearly identical to their unwatermarked counterparts across all three targets, evidence the watermarking process itself was not quietly degrading the molecules' real-world function.

Two different ways to embed the signal

The designs tested came from AlphaProteo paired with a SynthID Bio-enabled version of ProteinMPNN, DeepMind's protein design tools, while a second method the company describes fine-tunes part of the AlphaFold 3 diffusion network so that the watermark is embedded directly in the model's weights rather than in individual sequences, meaning any output the model produces carries the signature automatically regardless of who is running it. That second approach, baking the watermark into the model itself rather than applying it output by output, could make the system harder to strip out even if someone tried to deliberately remove or evade it.

Why biosecurity specialists want this now

OODAloop's write-up of the release said that as AI protein design tools become more capable and more widely used, the ability to trace a synthetic sequence back to the system that generated it has become a growing concern for gene synthesis screening providers responsible for flagging potentially dangerous orders, and for regulators trying to track the provenance of material moving through open scientific databases. A verifiable, synthesis-resistant watermark gives those gatekeepers a concrete signal to check against, rather than relying solely on the content of a sequence itself to judge whether it originated from an AI system.

A proof of concept, not yet a deployed standard

DeepMind has described SynthID Bio as a technical proof of concept rather than a finished, universally adopted standard, meaning its real-world impact on biosecurity will depend on whether gene synthesis companies, journals and regulators actually build the watermark detection step into their existing screening processes. The three successful wet-lab demonstrations give the approach a credible starting point, but turning a working prototype into an industry-wide safeguard against misuse of AI-designed biological material remains a considerably larger undertaking than the laboratory results published this week.

Published in The Outspoken Digest

Editorial desk

Outspoken Digest Technology Desk

Software, hardware, artificial intelligence and what they change for everyone else.

Newsletter

The Digest, in your inbox

One edition, sent when it is ready. No noise, and your address is never passed on.

We send a confirmation first. One click to leave, always.

Share this story

the OUTSPOKEN digest

Beyond boundaries. Independent stories on technology, culture, and the trends shaping how we live.