SynthID Bio attempts to add provenance directly to the biological design. Rather than attaching a separate label to a protein file, the system embeds a detectable pattern into the sequence or structure itself. DeepMind says that means the mark can remain verifiable even after a digital sequence is turned into a physical protein.
For protein sequences, the method influences which amino acids are selected during generation. DeepMind demonstrated the technique using ProteinMPNN, a widely used protein sequence design system developed by the Baker Lab.
ProteinMPNN builds a sequence by selecting amino acids that are compatible with a specified protein backbone and other design requirements. SynthID Bio adds another signal during that process, favoring amino acids associated with the watermark when those choices remain compatible with the intended protein.
That distinction matters because proteins offer far less room for modification than images or other digital media. They are built from only 20 amino acids, and changing even a single position can sometimes alter folding or destroy biological activity. Other regions are more tolerant, allowing chemically similar amino acids to be substituted without significantly changing function.
SynthID Bio uses that flexibility rather than forcing watermark information into positions where it would interfere with the protein. The resulting signal is distributed across the sequence and detected statistically using the corresponding watermark key.
DeepMind tested the method on protein binders created with its AlphaProteo design approach and a SynthID Bio-enabled version of ProteinMPNN. The laboratory experiments covered three targets: VEGF-A, the receptor-binding domain of the SARS-CoV-2 spike protein and PD-L1.
According to DeepMind, the watermarked proteins performed comparably with unwatermarked designs across hit rate, binding affinity and natural sequence diversity. The company describes the results as the first biologically functional protein binders carrying this type of watermark.
SynthID Bio also applies watermarking to predicted protein structures, although the implementation is different. DeepMind fine-tuned a small portion of AlphaFold 3’s diffusion network so that the model’s predicted atomic coordinates contain a detectable signature.
Because the capability is built into the model weights, DeepMind says the resulting 3D structures carry the signal regardless of who operates the model. The company reported that the modified system maintained AlphaFold 3’s prediction accuracy while providing near-perfect watermark detection and resistance to minor coordinate changes or digital noise.
One intended application is DNA synthesis screening. Providers typically examine incoming orders for sequences associated with known biological threats before manufacturing DNA. AI-generated proteins complicate that process because a novel sequence may not resemble anything already cataloged.
A detectable watermark could give synthesis providers another piece of information when reviewing such orders. If a sequence contains a watermark associated with a trusted model or organization, the provider could verify its origin and devote additional scrutiny to unfamiliar designs that lack that provenance signal.
The system would not establish that a DNA order is inherently safe. Instead, it could narrow the set of sequences requiring more intensive investigation and add another verification layer to existing screening procedures.
DeepMind also sees a possible role in scientific databases including the Protein Data Bank, UniProt and GenBank. AI-generated structures or sequences submitted without proper labeling could create problems for researchers who later treat those records as naturally occurring biological data. A built-in watermark could help identify synthetic submissions or flag them for additional review.
The approach still has technical and operational limitations. Detection depends on how watermark keys are managed and distributed, and very short proteins may not contain enough usable positions to produce a strong signal. Watermarks could also become harder to detect if a marked protein is combined with a substantial unwatermarked sequence.
The sequence technique is not automatically compatible with every protein design model either. SynthID Bio fits naturally with systems such as ProteinMPNN that generate proteins incrementally, but other design architectures may require different integration methods.
Detection itself is statistical rather than absolute. Setting a threshold involves balancing false positives against false negatives, meaning deployment would require decisions about how much evidence is sufficient to classify a sequence as watermarked.
DeepMind is also investigating ways to make the system more resistant to intentional modification. The company says watermarking could eventually operate alongside other provenance systems, including metadata or repositories that track AI-generated biological material.
The work is already being extended beyond individual proteins. DeepMind said it integrated SynthID Bio with the Evo 2 genomic model through ongoing research with the Hie lab at Stanford University and Arc Institute. The collaborators used the system to watermark the genome of an Evo 2-designed bacteriophage, with early laboratory testing showing that the resulting phages remained functional in bacterial cultures.
DeepMind is publishing the methods paper and releasing the code, in vitro data and model weights to researchers. The company presents SynthID Bio as one layer of a broader biosecurity system rather than a complete defense, with further work needed before biological watermarking can become a broadly adopted verification mechanism.
This analysis is based on reporting from Google DeepMind & ars TECHNICA.
Image courtesy of Google DeepMind.
This article was generated with AI assistance and reviewed for accuracy and quality.