SynthID Bio: Google DeepMind watermarks AI-designed proteins without breaking their function

On September 30, 2026, Google DeepMind researchers published “Function-preserving watermarking of AI-generated proteins” in Nature, with David Stutz as first author among 21. The paper introduces SynthIDBio, a family of methods for marking protein sequences and structures so that their origin in an AI model can later be verified. SynthIDBio-sequence embeds a watermark while the sequence is being generated by subtly steering which amino acids are chosen. SynthIDBio-structure is a fine-tuned AlphaFold 3 model whose predicted coordinates carry an imperceptible signature; because the change lives in the model weights, the mark persists no matter who runs the model.

The central claim is that the watermark does not cost function. In wet-lab tests against three targets, VEGF-A, the SARS-CoV-2 spike protein receptor-binding domain and PD-L1, watermarked binder designs matched the hit rate, binding affinity and natural sequence diversity of unwatermarked designs, with near-perfect watermark detection accuracy. DeepMind’s announcement calls them the first watermarked, biologically functional protein binders. For structures, DeepMind reports near-perfect detectability while preserving AlphaFold 3 prediction accuracy. DeepMind said it is open-sourcing the code and in vitro data and releasing weights to researchers; Adaptyv Bio helped with in vitro validation, and Stanford’s Hie lab, the Arc Institute and Twist Bioscience are named as collaborators or early reviewers.

Why it matters: SynthID began as a watermark for AI text, images and video. Carrying it into biology gives DNA synthesis providers and database curators a possible automated signal that a sequence came from a model with safeguards, which is a concrete biosecurity tool rather than a policy proposal.

What it does not show: the authors describe it as a proof of concept. Robustness against deliberate removal, for example by re-designing or mutating a sequence, still needs research, and a watermark only marks designs from cooperating models; a sequence from an unwatermarked open model carries no signal at all.