
An AI-generated image can carry an invisible watermark. Google DeepMind now wants to apply the same basic idea to something much less familiar: proteins designed with artificial intelligence. Its new SynthID Bio system is an early attempt to leave a detectable signature in a biological design without stopping that design from working.
In a September 30 research announcement, DeepMind called SynthID Bio a proof of concept. Researchers say they embedded a subtle signal in AI-designed protein sequences and predicted three-dimensional structures. The striking part is that the signature could still be checked after a digital design was turned into a physical protein in the laboratory.
Why would anyone need that? AI systems are making it easier to design proteins with useful properties for medicine and research. They also make it possible to produce sequences that do not look much like anything in existing databases. Laboratories that manufacture genetic material need to screen orders for risk, while scientists who rely on shared databases need to know whether a structure is natural, predicted or engineered. A reliable mark could provide one extra clue about where a design came from.
The technical challenge is more demanding than marking a picture. A protein is not merely information on a screen. Its sequence determines how it folds and what it may do. If a watermark changes those properties, it is useless to the scientists who need the protein. DeepMind says its methods adjust the choice of amino acids or the coordinates of a predicted structure in ways that preserve biological function.
The team tested watermarked protein binders against three targets, including VEGF-A, PD-L1 and part of the SARS-CoV-2 spike protein. DeepMind says the marked versions performed comparably with unmarked designs in laboratory measures such as binding strength and success rate. It also reports that a watermark built into a portion of AlphaFold 3’s prediction system retained strong detection while preserving prediction accuracy. These are research results, not evidence that every possible AI-designed protein can now be traced.
SynthID Bio could be useful at the point where a DNA-synthesis provider checks an unfamiliar order. A verified watermark might indicate that the design came from a known model with particular safeguards. That would not prove the order is harmless, and it would not replace customer checks or biological screening. It would give reviewers another piece of provenance information when the sequence itself is unfamiliar.
This is a different setting for a problem we have already seen with invisible SynthID marks on AI media. A signal is only valuable if people know to check it, the detector works reliably and the mark survives attempts to remove it. DeepMind acknowledges that resistance to deliberate tampering remains a research challenge. It is releasing methods and research materials so others can test and improve the approach.
The larger point is that AI provenance may no longer end at text, audio or video. As models begin designing molecules that can be made in the real world, the question becomes how labs and regulators establish a trustworthy trail from model to physical product. SynthID Bio does not settle that question. It does make the need for an answer much harder to ignore.







