On September 30, 2026, Google DeepMind announces SynthID Bio, a proof-of-concept family of methods for watermarking AI-designed protein sequences and predicted structures. The aim is to help identify a design’s provenance: one method marks the sequence, while another marks a predicted 3D structure.
The distinction matters because the methods work on different biological data—and the reported tests found different vulnerabilities for each.
SynthID Bio marks protein sequences and predicted structures
A watermark is a detectable signal embedded in data. SynthID Bio applies that idea to AI-designed proteins, with separate methods for their amino-acid sequences and their predicted structures. The sequence signal is designed to be detectable in a synthesized protein, not just in its digital design.
A watermark can help indicate a design’s provenance. It is not a safety certification for a protein.
Two methods, two biological objects
SynthIDBio-sequence changes how ProteinMPNN samples amino-acid sequences, using tournament sampling to embed the signal. Detection relies on a secret key and a watermark-score threshold.
SynthIDBio-structure takes a different route: it fine-tunes components of AlphaFold 3 and trains a detector so the signal is embedded during structure prediction. The methods can be compared by what they mark, how they work and the specific manipulation tested against each.
| Method | Watermarked object | Technical approach | Tested vulnerability |
| SynthIDBio-sequence | Protein sequence | Embeds a signal during ProteinMPNN sampling; detection uses a secret key and score threshold. | ProteinMPNN resequencing effectively removed the watermark in the tested attack. |
| SynthIDBio-structure | Predicted 3D biomolecular structure | Fine-tunes AlphaFold 3 components and a detector to embed the signal during prediction. | Constrained relaxation with OpenMM and Amber99sb destroyed the watermark in the reported experiment. |
What the protein tests found—and their limits
The binder experiments started with 15 previously designed backbones for each of three targets: VEGF-A, the SARS-CoV-2 spike protein receptor-binding domain (SC2RBD), and PD-L1. The tests evaluated resequenced binders, rather than a full de novo design process.
Across the tested binders, the measured surface plasmon resonance (SPR) binding-affinity distributions showed no significant population-level difference between watermarked and non-watermarked groups. The hit-rate results had a specific qualification: at a threshold of KD ≤ 10⁻⁷, there was no significant difference; at KD ≤ 10⁻⁶, non-watermarked binders had a higher hit rate than the non-distortionary group made with a 0.5 temperature setting. These results describe the tested targets and designs, not every protein.
For filtered in-vitro sequence designs, the reported true-positive rate (TPR)—the share of watermarked examples detected—was 100% at a threshold calibrated to a 0.1% false-positive rate (FPR). On a separate AlphaFold 3 evaluation set, the three structure-watermark models exceeded 99.8% TPR at 0.1% FPR. Those figures belong to their respective test sets and conditions.
The two approaches also failed under different tested manipulations. ProteinMPNN resequencing effectively removed the sequence signal in the reported attack. For the structure method, constrained relaxation with OpenMM and the Amber99sb force field destroyed the watermark.
Potential uses and separate Evo 2 work
Potential applications include checking the provenance of designs during DNA-synthesis screening and labeling entries in biological databases. Those uses would require further research, coordination and standardization.
Google DeepMind also reports a separate, ongoing collaboration with Stanford University and Arc Institute to watermark an Evo 2-designed bacteriophage genome. The company says early testing in bacterial cultures found the watermarked phages functional. That work is distinct from the protein-binder experiments.