Science & Tech · United States of America
Google DeepMind proposes watermarking system for AI-designed proteins
SynthIDBio embeds detectable signals during protein design while seeking to preserve function. Its usefulness depends on protein length, compatible design tools and secure management of detection keys.
Google DeepMind has proposed embedding statistical watermarks in AI-designed proteins without disrupting their intended function. The method could assist DNA screening, but its coverage, reliability and key management remain limitations.
- SynthIDBio embeds signals through selected amino-acid choices.
- ProteinMPNN can reject choices that threaten protein function.
- Detection requires the cryptographic key and full-sequence scanning.
- Short or padded sequences may weaken the watermark.
- The method does not guarantee DNA-order security.
What's new
- DeepMind researchers proposed SynthIDBio for watermarking AI-designed proteins. [s1]
- The method was integrated into the ProteinMPNN design process. [s1]
- Researchers reported that watermarked proteins still bound their intended targets. [s1]
- Detection software scans complete sequences using the watermarking key. [s1]
Google’s DeepMind team has proposed a method at Google for placing detectable watermarks in AI-designed proteins without impairing their intended activity, Ars Technica reported on Sept. 30, 2026. The research presents the system, called SynthIDBio, as a possible biosecurity tool for distinguishing designs from trusted organizations during DNA-order screening.1
A signal embedded during design
Proteins are chains assembled from 20 amino acids, with their sequence influencing how they fold and function. According to Ars Technica, SynthIDBio uses a cryptographic key and the amino acids already selected for a sequence to recommend the next building block. Those recommendations collectively create a signal spread across the protein rather than placing a single identifying tag at one position.1
The researchers incorporated SynthIDBio into ProteinMPNN, an AI protein-design tool developed by the Baker Lab. ProteinMPNN places amino acids along a specified protein backbone while assessing whether the resulting sequence should remain functional. If a watermark-related suggestion is incompatible with that requirement, the design tool rejects it, according to Ars Technica.1
This arrangement is intended to give protein function priority over the watermark. The watermark therefore emerges only from suggested amino acids that ProteinMPNN accepts as compatible with the design. Google’s team used the combined system to create proteins intended to interact physically with particular natural proteins and reported that the watermarked designs bound their targets.1
How detection works
Identifying the watermark requires possession of the relevant key. Detection software examines the full amino-acid sequence and measures how frequently the choices associated with SynthIDBio appear. The result is statistical: a sequence is classified by comparing the strength of the detected pattern with a chosen cutoff.1
That statistical approach creates trade-offs. Changing the cutoff affects the rates of false positives and false negatives, Ars Technica reported. Sequence length also matters because very short proteins may contain too few watermark-related amino acids to produce an identifiable signal. The report said detection can work once a protein is sufficiently long, but the dossier provides no universal minimum length.1
The signal may also be weakened if someone attaches a watermarked sequence to an unwatermarked protein, diluting its frequency across the combined chain. In addition, not every AI protein-design package uses a process into which SynthIDBio can be inserted. The proposed method therefore does not automatically cover all proteins created with AI tools.1
A proposed aid to DNA screening
DNA synthesizers screen orders for sequences that encode potentially threatening proteins, including viral proteins and toxins. AI-designed proteins may be harder for existing screening software to assess. Ars Technica reported that the proposed watermark could allow synthesizers to recognise designs produced by trusted organizations and concentrate additional scrutiny on untrusted designs.1
The proposal is not a complete security system. Its effectiveness would depend on how cryptographic keys are issued, shared and protected, as well as whether relevant protein-design tools adopt the method. Ars Technica concluded that the approach “it doesn’t guarantee the security of DNA orders, but it simplifies the threat-screening process.” Its practical value in the form described remains unclear.1
Phys.org framed the development as an extension of the broader role of watermarks, which have been used with bank notes, fine art, digital photographs and software. Such marks can help establish authenticity and trace origin. SynthIDBio applies that general purpose to amino-acid sequences rather than to physical objects or digital media.2
Why it matters
For readers in Europe, the proposal is relevant as a potential method for helping DNA synthesizers distinguish AI-designed proteins associated with trusted sources from designs requiring closer review. It may support biosecurity screening, but the reported limitations mean it cannot by itself secure DNA orders or cover every protein-design system.12
Videos
Related stories
Version history
- version 1 ·

