Signum
Feed
Useful signal30 Sept 2026high confidence

Google DeepMind introduces SynthID Bio, watermarking for AI-designed proteins that preserves function in wet-lab tests

DeepMind published a methods paper and open-sourced code, in vitro data and weights for SynthID Bio, a family of watermarking methods for synthetic biology. For sequences, it biases amino acid choice (a SynthID Bio-enabled ProteinMPNN used with AlphaProteo). For structures, it fine-tunes part of AlphaFold 3's diffusion network so predicted coordinates carry a detectable signature. In wet-lab tests on three targets (VEGF-A, SARS-CoV-2 spike RBD, PD-L1), watermarked binders matched unwatermarked ones on hit rate, binding affinity and sequence diversity. AF3 watermarking is reported to keep accuracy with near-perfect detectability. Early work with the Hie lab (Stanford) and Arc Institute watermarked an Evo 2-designed bacteriophage genome, and early lab tests found it functional. A technical manuscript for that work is still to come. The watermark is not yet robust against deliberate tampering. DeepMind is inviting partnership proposals.

CapabilityGovernanceInfrastructure

Entities: Google DeepMind, SynthID Bio, SynthID, AlphaFold 3, AlphaProteo, ProteinMPNN

66Useful signal
1 source
1 primary
Was this useful?
01

What happened

Google DeepMind published a methods paper and released code, lab data and weights for SynthID Bio, which hides a detectable signature in AI-designed biological sequences and structures. For protein sequences it nudges amino acid choices in a modified ProteinMPNN used with AlphaProteo. For structures it fine-tunes part of AlphaFold 3 so predicted coordinates carry the mark. In wet-lab tests on three targets (VEGF-A, SARS-CoV-2 spike RBD, PD-L1), watermarked binders matched unwatermarked ones on hit rate, binding affinity and sequence diversity. DeepMind also says early work with the Hie lab and Arc Institute watermarked an Evo 2-designed bacteriophage genome that appeared functional, but that manuscript is not yet out.

02

Why it matters

This is a credible first step towards provenance checks in biosecurity. DNA synthesis screeners and database curators (PDB, UniProt, GenBank) could eventually use watermarks to flag AI-generated sequences or confirm an order came from a model with safeguards. Today, though, nothing is deployed: no screener or database has adopted it, and it only covers models whose developers choose to apply it. DeepMind itself says it can be defeated by deliberate tampering, which is exactly the case a bad actor would use, so the near-term effect is mostly on research norms and policy discussion rather than on actual risk reduction.

03

What is noise

Framing around "bioresilience" and "first-ever" is PR gloss on what is a proof of concept. The "near-perfect detectability" claim for AF3 comes from the developer's own tests, and it does not cover adversarial removal. Three targets is a small sample, and the phage genome result is an unpublished early finding, not established evidence.

04

Watch next

  1. 01Independent red-team results showing whether the watermark survives mutation, re-synthesis or deliberate removal, since robustness is the main open weakness
  2. 02Any named adoption by DNA synthesis providers (such as Twist Bioscience) or by database maintainers, and whether it is integrated into screening workflows
  3. 03Publication of the Hie lab and Arc Institute bacteriophage manuscript with functional data, plus whether other model developers (for example Evo 2 or open-weight protein models) adopt the method

Coverage

1 story

More capability signals

Full feed →