On September 30, 2026, Google DeepMind announced SynthID Bio, a proof-of-concept family of methods for watermarking AI-generated protein sequences and predicted structures. A methods paper was published the same day. The approach aims to leave a detectable provenance signal—a mark indicating that a design carries a watermark, not a verdict on whether it is safe.

What SynthID Bio is designed to mark

SynthID Bio covers two different representations of proteins: their amino-acid sequences and their predicted three-dimensional structures. Its zero-bit watermarks signal the presence of a mark; they do not encode a detailed identity or message.

Two methods for sequences and structures

SynthIDBio-sequence steers amino-acid selection during sequence generation with ProteinMPNN. It uses keyed tournament sampling, then filters designs against a watermark-score threshold. Detection uses the secret key to score a sequence.

SynthIDBio-structure takes a separate route. It fine-tunes components of AlphaFold 3—including its diffusion and confidence modules—so predicted coordinates carry a detectable signal. A separately trained detector looks for that signal in the resulting structures.

What the binder experiments measured

The sequence method was tested in vitro on designed binders for three targets: SC2RBD, VEGF-A, and PD-L1. The measured binding-affinity distributions, derived using surface plasmon resonance (SPR), showed no significant population-level difference between watermarked and unwatermarked designs.

That result has a specific exception. At a binding-affinity cutoff of KD ≤ 10⁻⁶, unwatermarked binders had a higher hit rate than binders using the non-distortionary 0.5 watermark setting. At KD ≤ 10⁻⁷, the hit rates did not significantly differ.

For filtered in-vitro designs, the sequence method reported a 100% true-positive rate (TPR)—the share of watermarked designs detected—at a threshold calibrated to a 0.1% false-positive rate (FPR). Filtering can reduce the share of designs that pass and require additional computation.

For the tested structure models, the reported TPR exceeded 99.8% at a 0.1% FPR. At a stricter 0.01% FPR, the model with s = 0.001 had a TPR of 98.99%. These figures apply to their stated model, design and threshold conditions.

A provenance signal, not a safety verdict

A reported ProteinMPNN resequencing attack effectively removed the SynthIDBio-sequence watermark. That result concerns the resequencing attack, not every possible sequence change.

Google DeepMind presents provenance tracking, biosecurity screening and scientific-data integrity as potential uses. A watermark is not a safety assessment, and operational biosecurity applications would require further development and coordination.

On September 30, Google DeepMind said it was open-sourcing SynthID Bio code and in-vitro data and making structure-model weights available to researchers.