Google DeepMind Is Now Watermarking AI-Designed Proteins to Prevent Biological Risks
Google DeepMind has introduced a watermarking system to identify AI-generated proteins, a move aimed at enhancing biosecurity despite remaining limitations.
Artificial intelligence is rapidly changing how we approach biology, moving beyond simply cataloging the natural world to designing entirely new proteins from scratch. While this progress promises breakthroughs in medicine and material science, it introduces a significant challenge: how to distinguish authentic, functional biological designs from synthetic models that could be used for malicious purposes or clutter scientific databases with unreliable data.
To address these mounting security and data integrity concerns, researchers at Google DeepMind have introduced a tool called SynthID Bio. This system embeds a subtle, detectable signal into the molecular architecture of proteins as they are generated by AI systems, such as AlphaFold and RFdiffusion.
Tracking the Digital Fingerprint of Synthetic Life
The approach draws inspiration from existing watermarking technologies used for AI-generated text and media. In the case of protein design, the system introduces minute, statistically significant variations in the amino acid sequence and atomic structure during the generation process. Because the model applies these tweaks during the initial design phase, the resulting protein naturally carries this embedded signature.
According to the research team, these modifications are engineered to be imperceptible to the protein’s functional performance. In laboratory trials, watermarked proteins designed to bind to specific targets—such as those involved in immune regulation or viral protein interactions—performed as effectively as their unwatermarked counterparts.
James Diggans, a scientist at Twist Bioscience in South San Francisco, noted that the role of DNA synthesis companies is critical as these innovations scale. While he was not directly involved in the development of SynthID Bio, his feedback highlights the ongoing industry focus on integrating responsible innovation with emerging biological capabilities.
Addressing Potential Security Gaps
The need for such tools has intensified as AI demonstrates a growing capacity for complex biological engineering. Recent studies have raised alarms regarding the ability of AI to generate synthetic toxins or even design functional bacteriophages that replicate within bacterial hosts. Currently, biosecurity relies on commercial DNA synthesis providers who cross-reference incoming orders against databases of known pathogens. However, AI-designed molecules that do not match existing sequences can sometimes bypass these screening protocols.
While watermarking offers a potential solution, the technology faces practical hurdles. Experts warn that these signatures can be scrubbed if a sequence is reprocessed through another design tool. Furthermore, there is no current industry consensus on who should manage the decryption keys required to read these watermarks, or how to balance security requirements with the academic freedom of researchers.
Oliver Crook, a researcher at the University of Oxford, has pointed out that while these systems are promising, they add a layer of technical complexity that some scientists may find burdensome for non-sensitive research. His comments, reported by Science, underscore the tension between rigorous oversight and the need for fluid scientific inquiry.
Future Directions in Biological Security
Beyond the DeepMind initiative, other groups are exploring different ways to secure synthetic biological data. Projects like FoldMark propose embedding 32-bit digital tags into the geometry of protein structures, while other models suggest using private identifiers to verify the provenance of a digital sequence before it is synthesized.
DeepMind has moved to open-source its code and data, encouraging broader collaboration across the biosecurity, policy, and academic communities. The company is already expanding its scope, recently testing the ability to watermark the genomes of AI-designed bacteriophages without impeding their biological function in collaboration with the Arc Institute and Stanford University.
As these tools evolve, the primary goal remains creating a transparent trail for synthetic molecules. Whether this technology will become a standard safeguard depends on whether stakeholders can align on a global strategy to implement these “digital signatures” without stifling the next wave of life-saving research.
This article has been fact checked for accuracy, with information verified against reputable sources. Learn more about us and our editorial process.
Last reviewed on .
Article history
- Latest version
Reference(s)
- “Twist Bioscience | We lead innovation in DNA synthesis.” <https://www.twistbioscience.com/>.
- <https://www.science.org/content/article/method-watermark-ai-designed-proteins-could-deter-bioweapons-protect-scientific-credit>.
- Zhang, Zaixi. “FoldMark: Safeguarding Protein Structure Generative Models with Distributional and Evolutionary Watermarking.” bioRxiv, September 26, 2026, pp. 2024.10.23.619960 bioRxiv, doi: 10.1101/2024.10.23.619960v8. <https://www.biorxiv.org/content/10.1101/2024.10.23.619960v8>.
Cite this page:
- Posted by Rohan Kumar