Google DeepMind has introduced SynthID Bio, a watermarking system for AI-designed proteins. The tool embeds a subtle signature directly into the biological code—either amino acid sequences or predicted 3D structures—without compromising the protein's function in laboratory tests. Both Ars Technica and Google's own announcement describe this as a response to a growing biosecurity gap: AI can generate entirely novel proteins that evade traditional DNA synthesis screening, which assumes unfamiliar sequences may be natural organisms.

Ars Technica explains how the system works in detail: a variant of Google's SynthID guides amino acid selection in tools like ProteinMPNN, only incorporating watermark-compatible amino acids where they do not disrupt folding or activity. Google adds that for structure prediction, SynthID Bio fine-tunes part of AlphaFold 3 so the predicted coordinates inherently carry a detectable signal. Both sources emphasize that the watermark remains verifiable on the physical, synthesized protein—not just in digital form.

According to both reports, wet-lab testing on three target proteins (VEGF-A, the SARS-CoV-2 spike RBD, and PD-L1) showed that watermarked binders matched unwatermarked versions in hit rate, binding affinity, and sequence diversity. Google calls these the first watermarked and biologically functional protein binders. The sources agree the approach is a meaningful new layer for biosecurity, but Google is careful to note that no single intervention is a silver bullet; watermarking is best used alongside other safeguards like model-level mitigations and synthesis screening.