Google DeepMind has built a way to stamp AI-designed proteins with a hidden signature that survives in the physical molecule, and says lab tests show the stamp does not break how the proteins work. The tool, called SynthID Bio, was announced on 30 September in a post on Google DeepMind’s own blog. It carries the idea behind SynthID, DeepMind’s watermarking system for AI-made media, into biology.

The problem it targets is screening. Anyone who wants a custom protein orders the DNA from a synthesis company, and those companies check each order against databases of known threats. DeepMind writes that this check used to lean on a comfortable assumption: an unfamiliar sequence was probably just an undiscovered natural organism. AI can now invent sequences that resemble no known hazard, so the assumption fails, and clearing an odd order can mean slow manual review.

The method changes with the kind of data being marked. For protein sequences, it quietly steers which amino acids (the building blocks of a protein) the model picks, leaving a pattern a detector can read. For predicted 3D structures, it shifts atomic positions slightly. For AlphaFold 3, DeepMind’s structure-prediction model, the team fine-tuned a small part of the network so the mark lives in the model’s weights. Anyone running that model gets marked output.

The evidence is DeepMind’s own. In wet-lab tests on protein binders, which are molecules designed to latch onto a chosen target, the company paired its AlphaProteo design system with a watermark-enabled version of ProteinMPNN, a widely used sequence tool. It tried three targets: VEGF-A, the SARS-CoV-2 spike protein, and PD-L1. According to DeepMind, marked designs matched unmarked ones on hit rate, binding strength and sequence variety. The company calls them the first watermarked, working protein binders. For AlphaFold 3, it reports preserved accuracy and near-perfect detection, even after small coordinate changes or digital noise.

Two outside voices appear in the post, both people DeepMind chose to quote. Sarah Carter, a biosecurity policy expert at Science Policy Consulting who reviewed the work, said the watermarks let developers “lead on safety” and help synthesis providers streamline screening. James Diggans of Twist Bioscience, a DNA synthesis company, called watermarking “a promising new addition to the biosecurity toolbox.”

The post is frank about the main gap. The mark still has to become harder to remove by deliberate tampering. DeepMind also concedes that no one safeguard is enough, and pitches this as one layer among several. Our reading of the logic: a watermark can only vouch for output from developers who choose to use it. A bad actor working with an unmarked model leaves nothing to detect, so the signal helps most as a fast lane for trusted orders, not as a net for hostile ones.

DeepMind also floats a second use. Public archives such as the Protein Data Bank, UniProt and GenBank accept submissions from outsiders, and mislabeled AI-made entries could mislead later research. The company suggests the watermark could help flag synthetic entries at submission. That remains a proposal, not a deployed system.

The work is extending past single proteins. With the Hie lab at Stanford and Arc Institute, DeepMind says it built the watermark into Evo 2, a genomic model, and marked the genome of an Evo 2 designed bacteriophage (a virus that infects bacteria). Early tests in bacterial cultures showed the marked phages still function, DeepMind says, and a technical manuscript is promised.

On openness, DeepMind says it is publishing the methods paper, releasing the code and lab data, and sharing the model weights with researchers. That matters commercially as much as scientifically. Rival labs that ship protein design models now have a free reference implementation, and a synthesis company weighing a faster path for marked orders has something concrete to test. Any lab releasing a protein model in the next quarter should expect the question of why it carries no mark.

Reported by Google DeepMind on 30 September 2026, from the company’s own blog post by Pushmeet Kohli, David Stutz, Ali Cowen-Rivers and Jeremy Ratcliff.