← Back to Spotlight
Spotlight

Invisible watermarks for AI-designed proteins preserve their function

From Pepkio Team · 6 October 2026 · 3 min read

Google DeepMind researchers report today in Nature a new toolkit, SynthIDBio, that can watermark AI-generated protein sequences and structures without breaking their biological activity. The work, led by senior author Pushmeet Kohli with first author David Stutz, is a proof-of-concept that provenance tracking is possible for engineered proteins — a capability that could help secure DNA synthesis screening and keep public databases free of misleading AI-generated entries.

The team developed two complementary approaches. SynthIDBio-sequence embeds a watermark directly into the amino-acid sequence while a protein is being designed, using a sampling trick borrowed from text watermarking. SynthIDBio-structure instead fine-tunes the AlphaFold 3 model to hide an imperceptible watermark in the 3D coordinates of a predicted structure. In both cases, the watermark can be detected with near-perfect accuracy using a secret key, while the resulting proteins behave almost identically to unmarked ones.

Crucially, the sequence watermark was validated in the lab. The researchers designed protein binders against three targets — the SARS-CoV-2 receptor binding domain, vascular endothelial growth factor A, and programmed death ligand 1 — and showed that watermarked versions had binding affinities in the low nanomolar to subnanomolar range, statistically indistinguishable from non-watermarked binders. Detection was near-perfect after filtering for a false positive rate of 0.1%. For structures, watermarked predictions from the fine-tuned AlphaFold 3 maintained key accuracy metrics like LDDT and template modelling scores, with detection rates above 99.8% even when the structures were lightly perturbed.

The potential applications are significant. Watermarks could give DNA synthesis providers a lightweight signal that a sequence came from a trusted, AI-powered design tool — a piece of provenance that could help triage orders without slowing down legitimate research. They might also let curators of databases like the Protein Data Bank or GenBank flag AI-generated entries before they contaminate the resources used to train future models.

Still, the authors are careful to frame this as a technical demonstration, not a deployable security system. The current watermarks are zero-bit — they only say “AI-generated,” not which model or user — and the sequence watermark can be removed by resequencing, although that also tends to harm the binder’s function. The structure watermark, while robust to noise and rotation, can still be erased by physical relaxation. Making these methods operational will require further refinement, plus industry-wide agreements on detection keys and thresholds.

SynthIDBio is a first step toward answering a growing question in the age of generative biology: when an AI designs a protein, how do we know where it came from? The answer may be hidden in the very atoms of the molecule.