Google DeepMind is taking its SynthID watermarking technology somewhere far more unusual than images, videos, audio, or text: synthetic biology.
The company has introduced SynthID Bio, a family of watermarking techniques designed to place an imperceptible, detectable signature directly into AI-generated biological designs. The goal is to make it possible to identify and trace AI-designed proteins even after those designs leave the computer and become real, physical molecules.
And importantly, DeepMind says the watermark can be added without compromising the protein’s biological function in its laboratory tests.
That distinction matters. With digital content, a watermark can usually be judged by whether it changes the appearance or quality of a file. In biology, even a small change to a protein sequence can potentially affect how that protein folds or behaves. DeepMind therefore had to design SynthID Bio around a much tougher constraint: make the biological design identifiable without breaking what the protein is supposed to do.
SynthID is going from pixels to proteins
SynthID has already become one of Google’s main technologies for identifying AI-generated content. The system embeds an imperceptible watermark into AI-generated images, audio, text and video so that specialized detection technology can later look for the signal.
SynthID Bio applies the same broad idea to synthetic biology, but the implementation is very different.
For protein sequences, the system subtly guides the selection of amino acids to create a detectable pattern within the biological sequence. For predicted three-dimensional protein structures, it can instead adjust atomic coordinates to introduce the watermark.
The interesting part is that the signature isn’t merely attached to a digital file describing a protein. DeepMind says the watermark can remain verifiable in the synthesized physical protein itself.
That gives researchers and companies a potential way to determine whether a biological design originated from an AI system equipped with SynthID Bio, rather than simply checking metadata that could disappear when a file is copied or converted.
The company tested it on real protein binders
DeepMind put SynthID Bio through wet-lab testing using protein binders. These are proteins designed to selectively attach themselves to specific target proteins and are an important class of molecules in biomedical research.
The team combined its AlphaProteo protein-binder design system with a SynthID Bio-enabled version of ProteinMPNN, a commonly used protein sequence generation method.
The resulting watermarked binders were tested against three targets: VEGF-A, the receptor-binding domain of the SARS-CoV-2 spike protein, and PD-L1.
According to DeepMind, the watermarked designs performed comparably to their unwatermarked counterparts across hit rate, binding affinity and natural sequence diversity. The company describes the work as the first demonstration of watermarked protein binders that remain biologically functional.

In other words, DeepMind wasn’t simply proving that it could hide a digital marker inside a protein sequence. It was testing whether the resulting molecule still did the job it was designed to do.
That is arguably the most important part of the announcement.
It could help with AI-generated biology screening
DeepMind sees SynthID Bio as another layer in the growing effort to secure AI-assisted biological research.
AI systems are becoming increasingly capable of designing new biological sequences and structures. That creates obvious scientific opportunities, but it also creates a provenance problem: a newly generated biological sequence may look nothing like known hazardous sequences, making conventional screening more difficult.
DeepMind says SynthID Bio could provide DNA synthesis providers with another signal when they receive an order. If a sequence carries a verifiable watermark associated with a model that has appropriate safety measures, the watermark could help establish where that design came from and potentially make screening workflows more efficient.
The technology isn’t intended to replace existing safeguards. DeepMind explicitly frames biosecurity as a layered defense, with watermarking acting as one additional verification layer alongside measures such as model-level safeguards, customer vetting and biological sequence screening.
That distinction is important because a watermark does not magically make a biological sequence safe. It can provide information about provenance, but it is not itself a guarantee that a design cannot be harmful.
DeepMind is watermarking protein structures, too
SynthID Bio isn’t limited to sequences.
For predicted three-dimensional protein structures, DeepMind has adapted the technology to work with AlphaFold 3. The company says it fine-tuned part of AlphaFold 3’s diffusion network so that the watermark becomes embedded in the model’s predicted atomic coordinates.
That approach means the predicted structure can carry a detectable signature as part of the generation process rather than having a watermark manually added afterward.
DeepMind reports that its testing preserved AlphaFold 3’s prediction accuracy while achieving near-perfect watermark detectability. It also says the watermark maintained important structural feature distributions and remained detectable despite digital noise or minor changes to coordinates.
The broader idea is pretty fascinating: instead of watermarking a picture of a molecule, the model can produce the molecule’s digital structure with the signature already built in.
There’s another problem: scientific databases
DeepMind also sees SynthID Bio as a way to protect the integrity of scientific databases.
Repositories such as the Protein Data Bank, UniProt and GenBank contain enormous amounts of biological information and are used by researchers around the world. As AI-generated biological designs become more common, mislabeled synthetic data could potentially make its way into those repositories and be mistaken for naturally occurring or experimentally validated biological information.
A provenance signal could help databases identify synthetic entries or flag them for additional review.
That’s a less dramatic use case than biosecurity, but potentially just as important for researchers. If AI-generated biological designs become part of everyday scientific workflows, knowing where a sequence or structure came from could become increasingly important.
It’s still an early technology
DeepMind is careful not to present SynthID Bio as a complete solution to biological AI safety.
The company describes the technology as an important first step, while acknowledging that making the watermark resistant to deliberate tampering remains a significant challenge. It also suggests combining the technology with provenance metadata systems, similar in spirit to C2PA for digital media, as well as centralized repositories of AI-generated biological data.
That’s probably the right way to look at it.
SynthID Bio isn’t putting a tiny “Made by AI” sticker on a protein. It’s an attempt to make provenance part of the biological design itself, while preserving the function researchers actually care about.
And that could become increasingly useful as AI moves further into biology. When an AI model can design something that eventually exists as a physical molecule in a laboratory, knowing that the molecule came from an AI system — and being able to verify that claim later — becomes a very different problem from identifying an AI-generated image.
Google DeepMind has now brought SynthID into that world.
Discover more from GadgetBond
Subscribe to get the latest posts sent to your email.
