
30 Sep 2026
Google DeepMind launches SynthID Bio to watermark AI-designed proteins
Google DeepMind said Wednesday it introduced SynthID Bio, a family of watermarking methods that embed a verifiable signature into AI-generated protein sequences and predicted 3D structures while preserving biological function in lab tests.
AI can invent proteins that look nothing like known pathogens, which breaks the old “is this natural?” shortcut for DNA synthesis screens and public databases. SynthID Bio is DeepMind’s attempt to put a durable provenance mark inside the biology itself so trusted-model designs can clear faster and synthetic entries can be labeled. That is infrastructure for the age of generative biology, not a new drug.
On Wednesday, 30 September 2026, Google DeepMind introduced SynthID Bio. The post is “Introducing SynthID Bio,” on the DeepMind blog. The page prints September 30, 2026, under Science. It does not print an hour. The byline names Pushmeet Kohli, David Stutz, Ali Cowen-Rivers, and Jeremy Ratcliff. The line under the title calls the work a proof of concept for watermarking AI-generated proteins while preserving biological function. A watermark, here, is a hidden mark a later check can still find, the way a faint pattern can show where a photograph came from. Synthetic biology is the work of designing biological parts, including proteins, that do not have to be copied from an organism that already exists. DeepMind says SynthID Bio embeds an imperceptible signature directly into that biological code. Imperceptible means a person reading the sequence, or a usual lab measurement, is not meant to notice the mark. The company says the signature can be checked not only on the digital model but on the synthesized physical protein, and that laboratory testing still showed the protein doing its biological job. Those lines are Google DeepMind’s. Google’s own blog the same day, “We’re introducing SynthID Bio,” carries a shorter version and points readers to the DeepMind post. That page also prints Sep 30, 2026, and it does not print an hour.
SynthID Bio is a family of methods, not one switch. DeepMind says the method changes with the kind of data. For a protein sequence, it subtly guides which amino acids are chosen. An amino acid is one of the small units strung together to make a protein. The sequence is the order of those units, the way letters make a word. For a predicted three-dimensional structure, it adjusts atomic coordinates, the positions of the atoms in that predicted shape, enough to leave a signal a check can detect. DeepMind says those adjustments did not compromise the protein’s biological function in its experiments. It says that matters if the protein is going to be useful in treating disease or in research. Those lines are Google DeepMind’s. The post does not say a watermarked protein has been given to a patient.
The sequence test is about protein binders. DeepMind defines a binder as a molecule built to latch onto one chosen protein. The team used AlphaProteo, its method for designing binders, together with a version of ProteinMPNN that has SynthID Bio turned on. ProteinMPNN, DeepMind says, is a commonly used method for writing a protein sequence. Wet-lab testing means the designs were actually made and measured, not only drawn on a computer. The test covered three targets DeepMind names: VEGF-A, the receptor-binding domain of the SARS-CoV-2 spike protein, and PD-L1. VEGF-A is a signal protein the body uses when it grows blood vessels. The receptor-binding domain is the patch on the spike of the virus that causes COVID-19, the patch that grabs a cell. PD-L1 is a protein some cells use to quiet an immune attack. Those three glosses are the ordinary names of the targets. DeepMind names the targets. It does not define them, and it does not say the watermarked binders are a medicine. DeepMind says the watermarked designs matched the unwatermarked ones on hit rate, binding affinity, and natural sequence diversity. Hit rate is how often a design actually binds. Binding affinity is how tightly it holds. DeepMind measures that hold as KD, and says a lower number is a stronger binder. Natural sequence diversity is how much the successful designs still differ from one another in amino-acid order, rather than collapsing into copies of one string. DeepMind says the experiment created the first watermarked protein binders that are still biologically functional. That “first” is DeepMind’s claim. Google’s shorter post says that, across target proteins, watermarked designs matched the performance and natural diversity of unwatermarked versions. It does not reprint the three target names.
The shape test is about protein folding, which is the prediction of a protein’s three-dimensional form. DeepMind says SynthID Bio fine-tunes a small part of AlphaFold 3’s diffusion network, so the watermark is built into the model’s weights. AlphaFold 3 is DeepMind’s model for predicting that shape. The diffusion network, in that sentence, is the part of the model that builds the predicted coordinates step by step. Weights are the saved numbers the model uses when it runs. DeepMind says the predicted coordinates then carry a detectable signature no matter who runs the model. It says the watermark keeps AlphaFold 3’s prediction accuracy, offers near-perfect detectability, keeps the usual structural patterns in place, and still reads after digital noise or a small change to the coordinates. Near-perfect is DeepMind’s description. The post does not print that detection as a percentage. A figure labeled 7PPA shows three shapes side by side: the AlphaFold 3 prediction, the known structure, and the watermarked structure. Those lines are Google DeepMind’s.
DeepMind places the watermark inside a larger biosecurity picture, and not as the whole defense. Biosecurity, here, is the work of keeping designed biology from becoming a hazard. The post uses a Swiss-cheese picture: several safety layers, each with holes, stacked so a hole in one layer is covered by the next. It names safeguards inside the model, and checks on who the customer is, as other layers that still have gaps. SynthID Bio, it says, is a verification layer set into the biological design itself. The first place it points that layer is DNA synthesis screening. To turn a digital protein design into a physical molecule, a lab orders the DNA from a company that synthesizes it, and that company checks the order against lists of known threats. DeepMind says an unfamiliar sequence used to be treated, as a working assumption, as a natural organism nobody had catalogued yet. It says AI can now write sequences that look little like known hazards, so that assumption no longer holds, and a person reading every unfamiliar order can stall research that is not a threat. A watermark, DeepMind says, can be an automated signal that an order came from a trusted model that already carries safeguards. The same post says the mark could help public databases label a synthetic entry, or flag it for another look, as part of how a submission is filed. It names the Protein Data Bank, UniProt, and GenBank. The Protein Data Bank stores three-dimensional structures. UniProt stores protein sequences. GenBank stores DNA sequences. DeepMind says a mislabeled entry in files like these can weigh heavily on a biosecurity decision, and that the problem can grow as AI-generated biology is added. Those lines are Google DeepMind’s. The post does not say a synthesis company has switched its live screen to SynthID Bio, and it does not say any of those databases now requires the mark.
Two people outside DeepMind are quoted in the post. Sarah Carter, described as a biosecurity policy expert and a principal at Science Policy Consulting, reviewed the work. She said SynthID Bio is an important piece of the puzzle for tracking where a biological design came from. She said linking a design to the lab that built the model lets those developers lead on safety, and lets synthesis companies move faster on screening for customers who used those models. James Diggans, vice president for policy and biosecurity at Twist Bioscience, gave early feedback on the paper. He said AI is expanding what scientists can design, and that DNA synthesis companies have a role in helping that work scale responsibly. He said that for Twist, watermarking is a promising addition to the biosecurity toolbox, one that could strengthen screening, point effort at sequences that need a closer look, and make biosecurity more efficient as AI-designed biology advances. Those quotations are theirs, printed in DeepMind’s post. Diggans’s “could” is a view of a tool that might help a screen. It is not a statement that Twist has put SynthID Bio into the orders it already accepts.
DeepMind says no single biosecurity step is a silver bullet. It calls SynthID Bio the move of SynthID, the watermark it already uses on other AI outputs, into synthetic biology, and a first step toward identifying and tracking AI-generated sequences and structures. The open problems it names include making the watermark hold up better against deliberate tampering. Tampering, here, means someone changes the sequence or the coordinates on purpose to scrape the mark off. That line is DeepMind’s own account of work that is not finished. The post also says the watermark can sit beside provenance metadata, a side file that records where a design came from, similar to C2PA for digital pictures and audio, or beside a central store of AI-generated biological data. C2PA is a standard for attaching that kind of origin record to a digital file. DeepMind does not say that pairing is already in use. In separate, ongoing work with the Hie lab at Stanford University and the Arc Institute, DeepMind says it built SynthID Bio into Evo 2, which it calls an advanced model of genomes, and watermarked the genome of a bacteriophage that Evo 2 designed. A genome is the full genetic text. A bacteriophage is a virus that infects bacteria, not people. DeepMind says early tests in bacteria cultures found that these watermarked bacteriophages still function. It says more detail will come in a technical manuscript. The company says it is publishing a methods paper, open-sourcing the code and the in vitro data, and releasing the model weights to researchers. In vitro means the measurements were made in lab dishes, not in a person. The acknowledgements thank Adaptyv Bio for help with that lab validation. A note at the end asks groups that want to partner to write synthidbio@google.com with a short proposal, and not to include confidential information. Those lines are Google DeepMind’s. The post does not announce a regulation that requires the watermark, a clearance from the Food and Drug Administration, or a dollar figure for the project.
The picture is Google DeepMind’s SynthID Bio announcement graphic. On a dark field, the title reads “Introducing SynthID Bio.” Ribbon drawings of protein structures sit beside the words, the folded shapes the post uses when it shows a watermark inside a design. It is the official social card from the announcement. It is not a photograph of a laboratory bench, and it does not print a calendar date.
In plain terms, Google DeepMind said on Wednesday that it can place a checkable signature inside an AI-designed protein, either in the order of amino acids or in the predicted three-dimensional coordinates, and still have the protein work in lab tests. On three binder targets, it says watermarked designs matched unwatermarked ones on how often they bound, how tightly they held, and how varied the sequences stayed. The uses it describes are a faster check when someone orders synthetic DNA, and a label on synthetic entries in public biology databases. It also says the mark is not, by itself, a full biosecurity defense, and that making the mark survive a deliberate attempt to remove it is still unfinished work.
RELATED
Sources
- Google DeepMind — Introducing SynthID Bio, 30 Sep 2026
deepmind.google
- Google blog — SynthID Bio, 30 Sep 2026
blog.google



















