Google DeepMind puts an invisible watermark inside lab-grown proteins

SynthID Bio hides a detectable signal inside AI-designed proteins and 3D structures without breaking what the molecule is supposed to do.

AI2Day NewsdeskEditor: Lee Brown4 min read
Photoreal editorial shot of a translucent 3D protein ribbon structure floating above a dark laboratory bench, faint glowing dot pattern subtly overlaid on the p
Share

Key points

  • Google DeepMind said on 30 September 2026 it has built the first watermark that survives inside a physical, lab-made protein, not just the digital file.
  • SynthID Bio was tested on protein binders aimed at three targets, including VEGF-A, the SARS-CoV-2 spike protein and the cancer marker PD-L1, and matched the binding strength of unmarked designs.
  • DNA synthesis firm Twist Bioscience gave early feedback and says the watermark could speed up safety screening of AI-designed orders.
  • DeepMind is releasing the methods paper, code, model weights and lab data for other researchers to test.
  • The launch lands three weeks after AI2Day reported researchers cracked Anthropic's invisible text watermarks in four hours.

Google DeepMind has extended its SynthID watermarking system, first built to tag AI-made images and text, into synthetic biology, the field where scientists design new proteins and organisms on a computer before growing them in a lab.

SynthID Bio hides a signal inside the protein itself. Not inside a PDF of the design. Inside the actual molecule that comes out of the machine.

That is genuinely new, and worth slowing down on.

What did DeepMind actually build?

SynthID Bio is a family of watermarking methods for AI-generated biology. It nudges the choice of amino acids, the chemical building blocks that make up a protein, and shifts the atomic coordinates of predicted 3D structures by tiny amounts. Those small changes form a pattern a detector can read later.

The trick is that the pattern has to survive the jump from screen to test tube. A watermark on a picture only has to survive being re-saved. A watermark on a protein has to survive being physically built out of atoms and still fold into the right shape.

DeepMind's team tested it on protein binders aimed at three targets: VEGF-A, the SARS-CoV-2 spike protein, and the immune-checkpoint protein PD-L1. The watermarked designs bound to their targets just as strongly as the unmarked ones, with no loss in hit rate or natural sequence diversity.

For 3D structure prediction, they fine-tuned part of AlphaFold 3's diffusion network so the watermark is baked into the model's weights. Anyone running that version gets marked outputs by default.

Why does this matter for biosecurity?

Because AI can now design biological sequences that look nothing like anything in nature, the companies that turn digital DNA orders into real molecules are flying partly blind. They screen orders against databases of known dangerous sequences. A novel AI design can slip past that check simply by being novel.

James Diggans, Vice President of Policy and Biosecurity at Twist Bioscience, said watermarking could let screeners quickly confirm an order came from a trusted model with its own safeguards, and focus human review on the orders that don't carry a signal.

Sarah Carter, a biosecurity policy expert and principal at Science Policy Consulting who reviewed the work, said the approach would let synthesis providers streamline screening for customers already using watermarked models.

Public databases like the Protein Data Bank, UniProt and GenBank are the other worry. AI-generated entries that get mislabelled as natural skew the data that later safety decisions are made on.

We've been tracking biosecurity developments since 16 July 2026, and this is the first time we've seen a watermarking claim backed by wet-lab binding data rather than simulation alone.

Can this watermark be removed?

Probably, and DeepMind admits as much. Making the signal harder to strip out deliberately is listed as future work.

That matters because the track record for invisible AI watermarks isn't great. In August, AI2Day reported that Anthropic's invisible text watermarks were cracked in about four hours by outside researchers. Google itself made the visible watermark on its image tools optional around the same time, while keeping the invisible one on by default.

So the honest read: SynthID Bio raises the cost of quietly passing off an AI-designed protein as something else, and gives synthesis firms a new signal to check. It doesn't turn biosecurity screening into a solved problem, and DeepMind isn't claiming it does. The company frames it as one slice of a layered defence, alongside human review and customer vetting.

DeepMind is also testing the approach on whole genomes, working with the Hie lab at Stanford and the Arc Institute to watermark a bacteriophage designed by the Evo 2 genomic model. Early cultures show the marked phages still work.

Watch for two things: whether major DNA synthesis providers actually plug SynthID Bio detection into their order screening, and whether independent researchers can strip the signal from a protein sequence without wrecking the molecule. Both answers should land within a year.

© 2026 AI2Day