Google DeepMind Hides a Watermark Inside AI-Designed Proteins

A Google DeepMind team has hidden a mark inside proteins designed by artificial intelligence, so that the molecule itself shows a machine made it. The system, called SynthIDBio, appeared in Nature on Sept. 30, 2026.
The authors say a record of which tool produced a sequence or a structure is becoming important for biosecurity and for the reliability of public biological databases, and that a watermark is one way to carry that record without a central registry. SynthIDBio has two parts: one marks the sequences that a protein design model writes, and one is a fine-tuned version of AlphaFold 3, the structure prediction model, that marks the shapes it predicts.
To check that marking does not break a protein, the group redesigned the sequences of existing binders for three targets, among them part of the SARS-CoV-2 virus, then measured in the laboratory how tightly the new versions stuck. On its own measurements, it reports no significant difference in binding strength between 222 unmarked and 267 marked sequences, and that a detector tuned to a 0.1% false-alarm rate flagged every marked design it tested. SynthIDBio is the team's own system, and the paper reports no independent evaluation of those results.

For predicted structures, the authors report detection above 99.8% at the same false-alarm setting, with a negligible effect on how accurate the structures are. The sequence watermark can also be removed by putting a design back through the sequence step, and fewer of the resulting proteins were then estimated to bind their target.
The authors call the work a proof of concept, and say that using it for biosecurity screening or for checking database entries would need further research, industry-wide coordination and standards. The code and the laboratory data are posted on GitHub, along with instructions for obtaining the structure model's weights.
Sources
- NaturePeer-reviewed
