Announced 30 Sept 2026 · Sources checked
What did DeepMind release?
DeepMind’s blog, posted 30 September 2026, presents SynthID Bio as a way to embed an imperceptible signature in biological code that remains verifiable after a protein is synthesised, while preserving function in laboratory testing. The accompanying Nature paper, titled “Function-preserving watermarking of AI-generated proteins,” calls the same system SynthIDBio and describes it as a proof of concept.
The motivation is provenance. AI tools such as AlphaFold, AlphaProteo and ProteinMPNN can produce sequences and structures that look unlike known natural proteins. DeepMind argues that those designs can slip past homology-based DNA-synthesis screens, and that mislabeled synthetic structures could pollute public databases. A watermark, in this telling, is one more layer in a “Swiss cheese” biosecurity stack, not a complete defence.
That is the same class of claim as text provenance tools, with a harder constraint: the mark has to survive wet chemistry, not only a file save. Our coverage of OpenAI’s EU text watermarks is the digital analogue; do not treat either mark as a certificate of safety or authorship.
How are sequences watermarked?
SynthIDBio-sequence sits on ProteinMPNN, the usual resequencer after a backbone has been designed. It applies tournament sampling from SynthID-text: a secret key and the preceding residues bias which amino acid is chosen at each step. With the key, a detector recomputes those scores and looks at the average g-value. Without it, the sequence should look ordinary.
Because ProteinMPNN is typically sampled at low temperature, the authors also test a stronger, distortionary setting that reuses keys across tournament layers. Designs are then filtered on AlphaFold 3 structural metrics and on a g-value threshold calibrated to a target false-positive rate on held-out unwatermarked designs, PDB sequences and UniRef50.
The in vitro set reused 15 known AlphaProteo binder backbones per target rather than starting de novo, to gather more affinity measurements per sequence. That is a function-preservation test on resequences, not a claim that watermarking helps you invent a new binder. For the neighbouring protein-design story, see Claude’s enzyme-discovery work.
What did the wet-lab tests show?
The three targets were VEGF-A, the SARS-CoV-2 spike receptor-binding domain, and PD-L1. DeepMind reports low-nanomolar binders for the spike RBD and subnanomolar binders for VEGF-A and PD-L1. Across those targets it says watermarked designs matched the hit rate, binding affinity and natural sequence diversity of unwatermarked versions, and calls them the first watermarked, biologically functional protein binders.
The Nature methods are more specific. For each backbone the team tested a parent sequence, five unwatermarked resequences, six non-distortionary watermarked sequences at temperature 0.5, and six distortionary sequences at temperature 0.1, plus negative controls. Excluding controls, that is 222 unwatermarked and 267 watermarked sequences per watermarking setting. Affinity was measured by surface plasmon resonance.
A two-tailed Wilcoxon rank-sum test found no significant population-level differences in SPR affinities between unwatermarked and watermarked binders. At a g-value threshold calibrated for a 0.1% false-positive rate, the authors report a 100% true-positive rate on those designs. There was a significant hit-rate difference at the weaker KD ≤ 10⁻⁶ threshold favouring unwatermarked sequences over the non-distortionary 0.5 setting; they report no significant hit-rate difference at KD ≤ 10⁻⁷. Adaptyv Bio helped with in vitro validation, according to the DeepMind acknowledgements.
| Method | Where the mark lives | Detection |
|---|---|---|
| SynthIDBio-sequence | Amino-acid choices in ProteinMPNN | Secret key; average g-value |
| SynthIDBio-structure | Fine-tuned AlphaFold 3 coordinates | Secret detector, not shipped to users |
How are structures watermarked?
Open-weight folding models can bypass a sampling-time mark, so SynthIDBio-structure fine-tunes AlphaFold 3’s diffusion module with a watermarking loss and trains a PointNet-style detector on intra-residue geometry. DeepMind’s blog says a small part of the diffusion network is adapted; Nature says the diffusion and confidence modules are fine-tuned and that the detector stays secret. On AlphaFold 3’s evaluation set the authors report true-positive rates above 99.8% at 0.1% false positives, with no drop in LDDT or template-modelling score at the smallest training noise (s = 0.001 Å). Related genome-scale work from the same lab is covered in our AlphaGenome Atlas note.
The mark is built to survive rigid transforms and the three-decimal rounding of common CIF files. Mild Gaussian noise of 0.01 Å leaves detection mostly intact. Detection is weaker on very short structures (under about 16 residues) and rises above 99% once the chain is longer.
What are the documented limits?
Nature is explicit. A ProteinMPNN resequencing attack on 38,396 binders “effectively removes” the sequence watermark. If the attacker starts from a known binder and keeps structure-based filters, estimated hit rates fall to 97% (spike RBD), 70% (PD-L1) and 66% (VEGF-A); without those filters the estimates drop further. Constrained relaxation of watermarked structures with OpenMM and the Amber99sb force field “successfully destroys” the structure watermark. Larger coordinate noise (0.1 Å) also wipes weaker structure marks.
DeepMind’s own forward-looking section lists robustness against deliberate tampering as a key remaining challenge. Manual edits, expression tags, or appending a short unwatermarked stretch will dilute the sequence signal. A malicious user can also ignore the watermarked tool and use an unmarked ProteinMPNN. Keys and detectors are secret; that helps hosted APIs and does little for a fully open local pipeline unless further methods appear.
The blog describes early work with Brian Hie’s lab at Stanford and the Arc Institute: SynthID Bio integrated into Evo 2 to watermark a designed bacteriophage genome, with early bacterial-culture tests said to confirm function. A technical manuscript is promised; those results are not in the Nature paper we checked.
What would have to happen before this is operational?
Sarah Carter, who reviewed the work, and Twist Bioscience’s James Diggans both describe watermarking as an extra screening signal, not a replacement for existing checks. DeepMind suggests pairing marks with C2PA-like metadata or a central repository of AI-generated biological data. The Nature discussion says operational use needs industry coordination, careful false-positive targets, and incentives so honest users will accept extra compute. Until those exist, treat SynthID Bio as a published method, not a procurement checkbox. Our guide to verifying AI answers still applies when a vendor says a sequence “came from a trusted model.”
DeepMind says it is publishing the methods paper, open-sourcing code and in vitro data, and releasing weights. We inspected the google-deepmind/synthidbio GitHub page; it did not yet carry a complete README or a license we could verify, so we are not assigning a repository licence here.
Common questions
Does a SynthID Bio mark mean a protein is safe?
No. It is a provenance signal that a watermarked model produced the sequence or structure, if the secret detector still fires. It does not measure toxicity, immunogenicity or dual-use risk.
Can someone remove the watermark?
Nature reports that ProteinMPNN resequencing can remove the sequence mark and that constrained relaxation can destroy the structure mark. DeepMind lists stronger tamper resistance as future work.
Is the detector public?
No. The paper says the structure detector remains secret and is not shared with users of the fine-tuned AlphaFold 3 model. Sequence detection also needs the secret sampling key.
What to remember
SynthID Bio shows that a protein can carry a secret mark and still bind in DeepMind’s assays. The same paper shows how to strip both sequence and structure marks. Use it as evidence that function-preserving bio-watermarking is possible, not as a finished biosecurity control.
Sources & further reading
How this story was made
Written by Kristian Kostov with AI assistance and checked against the linked sources. Company performance claims are attributed to the company. Analysis reflects AiLookout’s interpretation; we have not independently tested the products discussed. Cover photography is illustrative and does not depict the specific announcement or product.
Our editorial standards





