Google DeepMind published a technical proof-of-concept Sept. 30 for embedding an invisible, verifiable signature directly into an AI-designed protein -- not just in its digital blueprint, but in the physical molecule itself once synthesized. SynthID Bio extends the same watermarking approach Google has used on AI-generated images and text since 2023 into a new domain, where the stakes of a model's output escaping unverified are considerably higher than a mislabeled picture.
The timing follows the capability. Protein-design models like AlphaProteo and the genomic model Evo 2 can now generate candidate binders and genetic sequences far faster than the biosecurity screening infrastructure -- built around recognizing human- and nature-designed sequences -- was ever built to check. Anthropic has cited exactly that asymmetry in explaining why it still restricts its own biology-adjacent model access even as it loosens blanket refusals for vetted researchers.
SynthID Bio's method works in two places at once, covering both halves of what a protein design actually is. For the amino-acid sequence, a SynthID Bio-enabled version of ProteinMPNN -- a widely used open protein-design tool -- subtly steers which amino acid gets chosen at each position as AlphaProteo, DeepMind's own protein-binder design model, builds the candidate, embedding a signature without changing what the finished protein actually does. For the protein's predicted 3D shape, a fine-tuned version of AlphaFold 3 -- the structure-prediction model that won Demis Hassabis a share of the 2024 Nobel Prize in Chemistry -- marks the atomic coordinates themselves, so the signal survives even if only the folded structure, not the original sequence file, ever gets checked.
DeepMind tested the approach on three real protein-binder targets -- VEGF-A, the SARS-CoV-2 spike protein's receptor-binding domain, and PD-L1 -- and reports that watermarked designs matched unwatermarked ones on hit rate, binding affinity and natural sequence diversity in wet-lab validation. None of DeepMind's own reported results show the watermark costing the designed protein anything it would otherwise have. A separate, earlier-stage collaboration with Stanford and the Arc Institute watermarked a bacteriophage genome designed with Evo 2 and confirmed the phage stayed functional in bacterial cultures -- an early signal the approach generalizes past isolated proteins.
How a watermarked protein gets checked
- Generates a candidate protein with AlphaProteo or a SynthID Bio-enabled version of ProteinMPNN.
- Embeds a signature in both the amino-acid sequence and the predicted 3D structure, via a fine-tuned AlphaFold 3.
- Synthesizes the physical protein from the watermarked design.
- Screens the incoming order against threat databases and checks for the signature.
- Verifies the design's origin, in principle clearing a signed, trusted design faster than an unmarked one.
The intended use case is narrow and specific. When a customer submits a DNA synthesis order today, the provider already screens it against databases of known dangerous sequences -- a check that struggles against a genuinely novel, AI-designed sequence with no evolutionary history to match against. A detectable SynthID Bio signature lets that same screening step also confirm the sequence came from a model with safeguards built in, shifting the logic from exhaustive threat-matching toward risk-stratified triage: signed and trusted, or unmarked and reviewed more closely. DeepMind separately proposes using the same signal to flag AI-generated entries inside public databases like the Protein Data Bank, UniProt and GenBank, where a mislabeled synthetic sequence can otherwise look identical to a naturally occurring one.
Outside reaction has been measured rather than triumphant. "SynthID Bio is an important piece of the puzzle for tracking the provenance of biological designs," biosecurity policy expert Sarah Carter said, quoted directly in DeepMind's own announcement -- a qualified endorsement that names a contribution without calling it a solution.
"Watermarking offers a promising new addition to the biosecurity toolbox." -- James Diggans, vice president, Twist Bioscience
Diggans' title matters as much as his quote: Twist Bioscience is a DNA-synthesis company, one of the screening providers who would actually have to build this into a live pipeline for it to do anything. Google DeepMind and Anthropic are answering the same underlying question -- how to keep AI-designed biology from being misused -- with opposite instincts about where to intervene. Anthropic's Life Sciences Verification Program, opened to beta applicants two weeks earlier, restricts who can generate certain biology content in the first place, replacing blanket refusals with credential checks and after-the-fact monitoring for vetted researchers. SynthID Bio restricts nothing about who can generate; it marks what gets generated, betting that traceability after the fact does more good than refusal beforehand.
Two labs, two different answers to the same dual-use problem
| Google DeepMind -- SynthID Bio mark everything, trace after the fact | Anthropic -- Life Sciences Verification Program gate access before generation | |
|---|---|---|
| What's restricted | Nothing -- any design can carry a watermark | Specific biology requests Claude's public models currently refuse outright |
| Who decides trust | Gene-synthesis screening providers, checking for a signature after the fact | Anthropic itself, via credential checks before generation |
| What's meant to stop misuse | Tracing a harmful design back to its source model during screening | Blocking the request outright, or monitoring it offline for up to 30 days, before it's ever generated |
| Open question | Whether the watermark survives a deliberate attempt to remove it | Whether vetting catches a credentialed researcher later acting in bad faith |
Neither company claims its own answer is sufficient on its own, and the honest reading of the table above is that both labs are betting on a layer that only works if the other kind of safeguard exists somewhere else in the system too.
DeepMind's own list of next steps is the clearest signal of how far this sits from deployed infrastructure: standardizing the signal format across the DNA-synthesis industry, building the central repositories and provenance metadata the company itself says should accompany the watermark, and extending the method past isolated proteins to the much harder case of complex genomes. The code, in vitro data and model weights are open-sourced -- meaning the next real test of this isn't whether DeepMind's own lab results hold up, but whether gene-synthesis screening providers actually adopt a shared standard built around them. (An open-sourced watermark is, by definition, also an open-sourced description of exactly how the signal is embedded -- the same transparency that lets outside researchers verify it works is available to anyone studying how to work around it.)
- Google DeepMind published SynthID Bio, watermarking AI-designed proteins without changing what they do.
- The signature survives in both a protein's amino-acid sequence and its predicted 3D structure, confirmed in wet-lab tests on three targets.
- The intended use: gene-synthesis screening providers trace a sequence back to a safeguarded model before fulfilling an order.
- Anthropic is solving the same dual-use problem differently -- gating who can generate, rather than marking what gets generated.
- Caveat: DeepMind's own announcement names resistance to deliberate tampering as an unresolved challenge, not a solved one.