Live·Open questions in longevity research
All news
AI in medicineIndustry & policy

Google DeepMind Embeds a Hidden Watermark in AI-Designed Proteins That Persists After Laboratory Synthesis

2 October 2026· 261002010

Google DeepMind Embeds a Hidden Watermark in AI-Designed Proteins That Persists After Laboratory Synthesis

SynthID Bio embeds an invisible signature into the amino acid sequence or the three-dimensional structure of an AI-designed protein. DeepMind synthesized and tested watermarked proteins that bind the SARS-CoV-2 spike, PD-L1 (a target for anticancer drugs), and VEGF-A (a target for drugs against excessive blood vessel growth). The work was published in Nature on September 30; DeepMind is offering the technology to DNA synthesis companies.

AlphaFold (which earned its creators the 2024 Nobel Prize in Chemistry) predicts a protein's shape from its amino acid chain, while ProteinMPNN does the reverse, selecting a chain to match a desired shape. Together they make it possible to design proteins that do not exist in nature. Companies that synthesize custom DNA sequences currently have no way to distinguish a trusted design from an arbitrary and potentially dangerous one: in 2025, Science showed that running a sequence through such an AI tool a second time is enough to evade screening against databases of known threats.

DeepMind's answer uses the same watermarking technology, SynthID, that has for several years distinguished AI-generated text and images in Google products from conventional content. Transferring the idea to proteins was not straightforward: for text, quality means readability, but for a protein it means a measurable ability to bind its target. Previous work had validated such protection only computationally, without synthesizing the proteins.

The team embedded a watermark in both links of the protein design chain. The ProteinMPNN watermark is applied during amino acid selection: at each step, two candidate amino acids "compete" according to a hidden function with a secret key, and the winner enters the sequence. This is the same trick used in text watermarking. This watermark can be removed by rerunning the same sequence through ProteinMPNN without the key: it exists only at the moment of generation. AlphaFold 3 uses a different approach: the developers fine-tuned the model itself, and the signature is baked into its weights, so it persists with every use, even when the model is openly available.

The sequence watermark was validated by synthesizing 489 protein variants, watermarked and unmarked, for all three targets: binding strength was nearly unchanged, and watermark detection was nearly error-free. The structural watermark was validated computationally on a set of known structures, without synthesis: detection accuracy exceeded 99.8%, equally for proteins, RNA, and DNA.

The sequence watermark has a limitation. The team tested a resequencing attack (rerunning a design through the freely available ProteinMPNN without the key) on 38,396 designs: when structural filters, a mandatory step in protein design, were applied after the attack, 66–97% of the surviving proteins were both unmarked and still functional; without this filtering step, only 3–33% were. The watermark embedded in AlphaFold 3's weights cannot be removed this way: it is a property of the model itself, not of a single run.

In a partnership with Brian Hie's lab at Stanford and the Arc Institute, the same idea was applied to Evo 2, a model that has already designed the genome of a bacteriophage, a virus that infects bacteria: a cocktail of such phages overcame E. coli resistance to a natural phage where a cocktail of closely related natural phages failed. The genome of another AI-designed phage has now been watermarked; the marked variant remained functional in culture.

James Diggans, Vice President for Biosecurity at Twist Bioscience, called watermarking "a promising new addition to the biosecurity toolkit." Sarah Carter, an independent biosecurity expert and a reviewer of the paper, noted that the watermark "ties a design to the model developer" and speeds up decisions about which orders warrant closer scrutiny.

Developers of "benign" AI tools currently have little incentive to adopt the technology: it increases computational costs and offers no direct benefit to them.

Originally published on Telegram by Ukhvat NewsView on Telegram
Sources
#synthid#protein-design#alphafold#biosecurity#watermarking#proteinmpnn