A mark that travels with the design
A protein can be designed by an AI system and then made in a laboratory. Once the design leaves the model, a separate lab or database may have little evidence of how it was produced. Google DeepMind researchers have tested a way to put that clue inside the design itself. Their methods, called SynthID Bio, were published in Nature on September 30.
One method gently changes which amino-acid building blocks a design model chooses. Another changes the predicted three-dimensional structure generated by a modified AlphaFold 3 model. A detector with the right key can look for the pattern. It is closer to an embedded signature than to a visible label on a file.
What the laboratory actually showed
The team made protein binders aimed at three targets: VEGF-A, PD-L1 and part of the SARS-CoV-2 spike protein. In these laboratory tests, the watermarked versions had binding hit rates and affinities comparable with versions made without the mark. The paper also reports highly detectable watermarks in predicted structures with little change to its measured accuracy tests.
That is a meaningful constraint to clear. A watermark that makes a protein stop doing its intended job would have limited value to researchers. But the experiment tested selected binders and model outputs. It did not establish that every protein design, every production process or every later edit will preserve both function and detectability.
Provenance is not a safety verdict
The possible use is practical: a synthesis provider or research database could receive a clue that a sequence or structure came from a particular model. That could help decide which submissions need closer human review. It would not prove the material is harmless. A trusted source can still make a risky design, and an unmarked design is not automatically dangerous.
The authors call this a proof of concept. They say real deployment would need more work and coordination, including stronger resistance to deliberate tampering. The next test is not another elegant demonstration alone, but whether a reliable provenance signal survives messy, varied workflows outside the lab.
Sources
- Nature: Function-preserving watermarking of AI-generated proteinsPrimary peer-reviewed paper published September 30, describing sequence and structure methods, binder tests and deployment limits.
- Google DeepMind: Introducing SynthID BioPrimary research-team explanation of the September 30 publication, three test targets and planned future work.



