Plate Nº 82 · recorded October 10, 2026

Biology & EvolutionReported finding

Google DeepMind Embeds Invisible Watermarks in AI-Designed Proteins

Google DeepMind's SynthIDBio identified more than 99.8% of watermarked AI-designed 3D protein structures in lab tests, per Nature. The tool hides codes inside protein sequences and atomic coordinates.

By Nathan Brooks3 min read540 words

In brief

  1. SynthIDBio detected more than 99.8% of watermarked 3D protein structures and 100% of sequences in lab tests.
  2. The study was published October 1, 2026 in Nature (DOI: 10.1038/s41586-026-10965-y).
  3. Researchers tested binders against three targets, including part of the coronavirus spike protein.
  4. Standard structural 'relaxation' steps can erase the 3D watermark, but not the sequence version.
  5. The sequence-watermark code is open source on GitHub.
Google DeepMind develops invisible watermarks for AI-designed proteins
Plate Nº 82Google DeepMind develops invisible watermarks for AI-designed proteins — AI-generated

A Google DeepMind system called SynthIDBio correctly identified more than 99.8% of AI-generated 3D protein structures carrying an invisible watermark in laboratory tests, according to a paper published October 1, 2026 in Nature. The tool hides secret codes directly inside the molecular blueprints AI systems use to design new proteins, without disrupting how those proteins fold or function.

The technology targets a real accountability gap in synthetic biology. AI tools now design novel proteins and predict their 3D shapes at scale, but those outputs can be hard to trace. Researchers and regulators have warned about biosecurity risks, including the potential misuse of AI-designed biological molecules, and the spread of fake or misleading scientific data.

How does the watermark work?

A team led by David Stutz at Google DeepMind built SynthIDBio in two versions, selected by what the AI produces. When a model writes a protein's amino acid sequence—the order of building blocks that make up a protein—the mark hides as a coded pattern inside that sequence. When a model predicts a protein's 3D structure, the watermark hides inside the coordinates of individual atoms.

What did the lab tests involve?

The team built the watermarks into real proteins in the lab. Researchers constructed protein binders—molecules designed to latch onto specific targets—against three of them:

  • a portion of the coronavirus spike protein
  • a human protein tied to blood vessel growth
  • a human protein involved in regulating immune responses

The binders went through two key checks: whether the watermarks changed how the proteins behaved, and whether a separate detection tool could recover the hidden codes.

How well did it work?

The watermarked versions attached to all three targets with strength comparable to unmodified proteins. The detector recovered 100% of watermarked sequences and more than 99.8% of watermarked 3D structures. Adding the marks did not meaningfully change protein function or the accuracy of predicted structures. The study appeared in Nature under the title "Function-preserving watermarking of AI-generated proteins."

What are the limits?

The 3D structure watermark has one clear weakness: a routine laboratory procedure can erase it. In structural biology, scientists routinely "relax" predicted structures to smooth out geometric irregularities introduced by AI. That cleaning step can destroy the digital pattern.

"However, robustness to relaxation is lacking, but we expect that this could be addressed by explicitly considering relaxation while training SynthIDBio-structure," the researchers wrote.

The sequence watermark does not face this problem. Its code lives inside the amino acid order itself, so it survives downstream processing.

Why does this matter for science?

Beyond intellectual property concerns, protein watermarks could help trace the origin of synthetic biological molecules and verify that published structures came from the AI system claimed. The team framed the work as an early but meaningful milestone.

"SynthIDBio presents a technical proof of concept that function- and quality-preserving biological watermarking is possible," the authors wrote.

What's next?

Researchers can already experiment with the sequence version, which the team released as open-source code on GitHub. The 3D structure version remains a research tool for now. Both will need further testing to see if they hold up against the many real-world edits proteins undergo after design.

via Phys.org Biology (Source)

Filed under

  • ai
  • protein-design
  • synthetic-biology
  • biosecurity
  • deepmind
Share this article:

More from Nathan Brooks

Nathan Brooks

Show full bio

Market editor covering consumer brands and retail at SciBeat.

202 articles

Nearby plates

« Previous articleNext article »