Google's SynthID Bio watermarks AI-designed proteins
Google DeepMind has extended its SynthID watermarking system to biology, embedding a verifiable signal in AI-designed proteins without changing how well they bind.

Google DeepMind has introduced SynthID Bio, a version of its watermarking technology built for AI-designed proteins. The system embeds an imperceptible, verifiable watermark directly into biological designs, including AI-generated protein sequences and predicted 3D structures, and the company says the mark is added without compromising the design's function.
The watermark is meant to survive the lab
The claim that matters is not that a signal can be embedded, but that it stays embedded. Google DeepMind says that in laboratory tests across a set of target proteins, watermarked designs matched both the performance and the natural diversity of unwatermarked versions of the same molecules. The company describes the result as a provenance layer, intended to strengthen biosecurity and preserve the integrity of open scientific databases that increasingly hold machine-generated designs alongside experimental data.
What the published examples show
The visual released with the announcement shows a watermarked VEGF-A protein binder with the watermark signal colour-coded amino acid by amino acid across the predicted structure, and a binding affinity of 0.344 micromolar for that binder. Further figures compare binding affinity, measured as KD, between watermarked and unwatermarked designs across three targets, and set an AlphaFold 3 prediction for a structure called 7PPA against both its ground-truth structure and the watermarked version.
SynthID moves from media to molecules
SynthID was built to label synthetic media, and Google describes it as a tool to watermark and identify AI-generated content. Applying the same approach to protein design puts a provenance check on work that increasingly feeds into wet-lab experiments, so that a sequence carrying a mark can be traced back to a generative model instead of being indistinguishable from one written by hand.
Our opinion
Watermarking biology is a harder problem than watermarking images, and the reason is the folding. A pixel can be nudged almost anywhere without changing what the picture shows, but a protein sequence is constrained by the shape it has to fold into and the job it has to do, so any robust mark has to be carried by a design that still binds. That is why the laboratory result, watermarked designs binding as well as the unwatermarked ones, is the whole story here, and why the telling number in the announcement is a binding affinity rather than a detection rate. It is worth being clear about what SynthID Bio does not do, too: a watermark shows a design was machine-generated, not that it is safe, and the biosecurity benefit only arrives if databases and laboratories actually check for the mark. Provenance is a useful layer, but it is only worth as much as the number of people looking at it.