Google DeepMind Develops ‘Invisible’ Watermark to Track AI-Generated Proteins

Watermark

Artificial intelligence is rapidly moving beyond text, images and software into the biological sciences. Now, Google DeepMind is extending its watermarking technology into synthetic biology with SynthID Bio, a system designed to identify proteins and other biological designs created with AI—without disrupting their biological function.

The development could become an important new layer of AI biosecurity, particularly as generative AI makes it easier to design proteins that do not naturally occur in biology.

A Watermark Hidden Inside the Biology

Unlike a conventional label attached to a digital file, SynthID Bio places an imperceptible and verifiable signature directly into an AI-generated biological design.

For protein sequences, the technology subtly influences the selection of amino acids during generation. For predicted three-dimensional protein structures, it modifies atomic coordinates in a controlled way. The objective is to create a detectable statistical pattern while leaving the protein’s functional characteristics intact.

That distinction is critical. A watermark that changes how a protein behaves would have limited scientific value. Google DeepMind says its laboratory experiments indicate that the watermarked proteins retained their biological performance.

The research has been published in Nature, where the system is described as a function-preserving approach for watermarking AI-generated proteins.

Why AI-Designed Proteins Need Provenance

AI systems such as AlphaFold 3, AlphaProteo and ProteinMPNN are changing how researchers approach biological design. Instead of simply analyzing naturally occurring proteins, AI can help scientists create entirely new protein sequences and structures for research and therapeutic applications.

That progress also creates a provenance problem.

A newly designed protein may not resemble anything in existing databases. Traditional screening systems often depend on comparing biological sequences against known sequences associated with potential risks. An AI-generated sequence could be sufficiently novel that conventional matching provides little information about where it came from or how it was created.

SynthID Bio is intended to add another signal: Was this biological design generated by an AI system equipped with the watermarking technology?

That information could be particularly useful when unfamiliar sequences reach DNA synthesis providers or enter scientific databases.

Tested on Three Protein Targets

Google DeepMind tested the approach using AI-designed protein binders targeting VEGF-A, the SARS-CoV-2 spike protein receptor-binding domain and PD-L1.

The researchers combined AlphaProteo’s protein-design capabilities with a watermark-enabled version of ProteinMPNN, which generates amino-acid sequences for designed protein structures. According to Google DeepMind, the resulting watermarked proteins maintained comparable hit rates, binding affinity and sequence diversity to their non-watermarked counterparts.

This is one of the most important aspects of the research: the watermark is intended to remain detectable without turning the biological design into a materially different or dysfunctional protein.

Extending Watermarks to 3D Protein Structures

SynthID Bio is not limited to amino-acid sequences.

Google DeepMind has also adapted the technology for predicted protein structures generated through AlphaFold 3. Researchers incorporated watermarking into part of AlphaFold 3’s diffusion network so that the resulting three-dimensional coordinates contain a detectable signature.

The company reports that the approach maintained AlphaFold 3’s prediction accuracy while achieving near-perfect watermark detection in its experiments. The watermark also remained detectable after digital noise or minor changes to the coordinates were introduced.

This could matter because biological information increasingly exists in multiple forms—from amino-acid sequences to computationally predicted structures.

A New Layer for DNA Synthesis Screening

One potential application is DNA synthesis screening.

When researchers want to create a physical biological molecule from a digital design, DNA synthesis providers can screen the requested sequence against databases of known biological threats. But highly novel AI-generated sequences can complicate this process because they may not closely resemble previously characterized dangerous sequences.

A detectable watermark could provide an additional provenance signal. Rather than relying only on sequence similarity, screening systems could potentially determine whether an unfamiliar sequence originated from a known AI model with safety mechanisms in place.

Google DeepMind describes this as another layer in a broader, multi-layered biosecurity system—not a standalone solution.

Protecting Scientific Databases From AI-Generated Confusion

The technology could also have implications for scientific data repositories.

Databases such as the Protein Data Bank, UniProt and GenBank are important resources for researchers around the world. As AI-generated biological structures and sequences become more common, clearly distinguishing synthetic designs from naturally occurring biological data could become increasingly important.

An embedded watermark could help identify AI-generated entries and support better labeling or additional review during database submissions.

This could help address a different problem from biosecurity: scientific information integrity.

If researchers cannot reliably distinguish between natural biological data and AI-designed material, downstream analyses could become more difficult to interpret.

SynthID Bio Moves Beyond Proteins

Google DeepMind is already exploring whether the same concept can be applied to more complex biological objects.

In collaboration with researchers at Stanford University and the Arc Institute, the team has integrated SynthID Bio into Evo 2, a genomic AI model, to watermark the genome of an AI-designed bacteriophage. Google DeepMind says early laboratory testing found that the watermarked bacteriophages remained functional in bacterial cultures.

The company says it plans to publish further technical work on applying watermarking to more complex biological systems.

That suggests the longer-term ambition extends beyond simply tagging AI-designed proteins. The goal is to establish a broader provenance infrastructure for AI-generated biology.

Watermarking Is Not a Complete Biosecurity Solution

Despite the promise, SynthID Bio comes with important limitations.

Google DeepMind acknowledges that future work will need to make watermarks more resistant to deliberate tampering. A determined actor could attempt to modify an AI-generated sequence or structure to weaken or remove its identifying signal.

Nature also notes that the digital marker can potentially be erased, highlighting why watermarking should not be treated as an infallible detection mechanism.

For that reason, Google DeepMind envisions SynthID Bio working alongside other safeguards, including provenance metadata, model-level protections, screening systems and repositories of AI-generated biological designs.

The company has also released its methods paper, code and in-vitro data to encourage further research and collaboration across the biosecurity community.

The Bigger Picture: AI Needs Provenance in Biology

AI-generated content has already created a major provenance challenge in media. SynthID Bio suggests that a similar challenge is emerging in synthetic biology, where the consequences can extend beyond misinformation to questions of scientific integrity and biosecurity.

As AI systems become increasingly capable of designing biological molecules, knowing what was created, how it was created and which system created it could become almost as important as the design itself.

Google DeepMind’s SynthID Bio represents an early attempt to build that provenance directly into biological designs—quietly marking AI-generated proteins while allowing researchers to use them for their intended scientific purpose.

The bigger question now is whether biological watermarking can evolve quickly enough to keep pace with AI’s rapidly expanding ability to design life at the molecular level.

Read more: Microsoft Introduces Quine, an AI Research System Built to Tackle Biology’s Complexity

GlobalBizOutlook is the platform that provides you with best business practices delivered by individuals, companies, and industries around the globe. Learn more

GlobalBizOutlook is the platform that provides you with best business practices delivered by individuals, companies, and industries around the globe. Learn more

Advertise with GlobalBiz Outlook

Request Media Kit to get Following:

  • Detailed Demographic Data
  • Affilate Partnership Opportunities
  • Subscription Plans as per Business Size

Enter Your Details to Read the Magazine

Advertise with GlobalBiz Outlook

Are you looking to reach your target audience?

Fill the details to get 

  • Detailed demographic data
  • Affiliate partnership opportunities
  • Subscription Plans as per Business Size