Can an AI-designed protein carry a detectable watermark without losing its function?
A peer-reviewed Nature paper reports lab-tested watermarks in designed protein binders and a separate mark in predicted structures. The result is a proof of concept for provenance—not a safety certificate or a universal detector for synthetic biology.
Editorial responsibility: The Impact of AI Editorial Desk · Report a factual concern
Research topic
Whether watermarks can be embedded in AI-designed protein sequences and predicted structures while preserving measured function and structural quality
At a glance
- 1Researchers tested sequence watermarks on 15 known binder backbones for each of three targets, with 18 designs per backbone, and measured binding in the laboratory.
- 2The study reports comparable binding-affinity distributions and near-perfect detection under tested conditions, while identifying attacks and processing steps that can weaken the watermark.
- 3A watermark identifies participating model output; it does not establish that a protein is safe, benign, correctly labelled or created without later modification.
Living evidence record
Impact record IAI-18B49W1
Evidence stage
Studied
Confidence
Supported
Reporting basis
Multi-source analysis
Independent support
Present
Record status
Monitoring
Last checked
1 October 2026
Source trail
2 direct sources across 2 source types.
People impact
Documented in this record.
Uncertainty
Limits and next checks are explicit.
Stages describe the evidence available—not whether a technology is good or bad. See the public method.
What SynthID Bio is trying to prove
The Nature paper introduces two related provenance methods. SynthIDBio-sequence changes the sampling process used to choose amino acids, distributing a secret-key signal through an AI-designed protein sequence. SynthIDBio-structure fine-tunes an AlphaFold 3-compatible model so that a detector can recognise a signal hidden in predicted three-dimensional coordinates. In both cases the scientific question is harder than watermarking an image: the mark must survive in a biological object without materially damaging the function or structural quality for which that object was designed.
Google DeepMind presents the work as a proof of concept for synthetic-biology provenance. That description matters. The system is not a public detector for every AI-designed protein, and it cannot identify output from models whose developers do not embed a compatible mark. It is also not a replacement for conventional sequence screening, laboratory containment, risk assessment or records showing who ordered and synthesized a design.[1][2]
How the sequence experiment was constructed
For laboratory validation, the researchers used three protein targets: the SARS-CoV-2 receptor-binding domain, vascular endothelial growth factor A and programmed death ligand 1. For each target they selected 15 backbones from historically successful AlphaProteo binder campaigns. Each backbone generated 18 tested designs: one previously validated parent sequence, five non-watermarked sequences and 12 watermarked sequences split across two watermarking settings. This produces a structured comparison across targets and backbones rather than a single demonstration molecule.
Binding affinity was calculated from at least two technical replicates for designs with quantifiable binding curves; the reported sample count in individual comparison bins ranged from 43 to 69. The authors report no significant shift in affinity distributions or binder hit rates attributable to watermarking. That supports the narrow claim that the mark can coexist with measured binding in these designs. Starting with backbones already known to bind, however, is deliberately more favourable than a full de-novo discovery pipeline and limits what the experiment establishes about unfamiliar targets.[1]
Detection is strong under the tested conditions, not universal
The paper reports near-perfect watermark detection while maintaining measured function, and describes structural watermarking with negligible change in global accuracy on the AlphaFold 3 evaluation set. The structure detector uses geometric features such as atom-to-atom distances and torsion angles, making the signal inherently resistant to simple rotations, translations and reflections. Noise is added during training so that ordinary coordinate rounding does not erase the mark.
Robustness has boundaries. Manual sequence edits dilute the signal, partial resequencing and appended material can change detection, and the structure mark is not yet robust to every relaxation procedure used in molecular modelling. The structure implementation is a zero-bit detector: it identifies the presence of the mark but does not encode a user identity or detailed provenance record. The authors also did not establish whether it can be reliably distinguished from other future biological watermarks at operational scale.[1]
What biosecurity teams could—and could not—do with it
A participating DNA-synthesis provider could use a valid watermark as one additional signal that a submitted sequence originated from a cooperating design model. A biological database could route marked submissions for provenance checks before incorporating them into resources used by researchers and downstream AI systems. In both settings, the value depends on shared standards, protected keys, reliable detectors and carefully selected false-positive and false-negative thresholds.
The risky interpretation would be to treat detection as an express lane around normal screening. A malicious actor might attach a harmful unmarked fragment to a watermarked design, or use a different model that applies no mark. The paper explicitly argues for layered screening: watermark status should sit alongside similarity- and function-based checks, not override them. Absence of a mark cannot prove human authorship, and presence cannot prove benign intent or biological safety.[1][2]
Why people outside the laboratory should care
As AI-designed proteins move toward medicines, diagnostics, industrial enzymes and research reagents, provenance affects more than laboratory workflow. Patients, regulators and manufacturers may need to know which model contributed to a candidate, which version produced it and whether subsequent edits changed the design. Researchers also depend on public protein databases; machine-generated records with false metadata could contaminate evidence used for future experiments or model training.
Provenance infrastructure can improve accountability only if governance determines who may detect a mark, how disputes and false accusations are handled, and whether sensitive design information remains private. A detector controlled solely by its developer creates different trust problems from an independently auditable standard. Public policy will need to separate the useful question—where did this object come from?—from the larger questions of safety, efficacy, ownership and responsibility.[1]
What would change the assessment
Confidence would rise with blinded replication by laboratories unaffiliated with Google, broader protein classes and functions, full de-novo designs, and stress tests covering synthesis, purification, storage, common structural-relaxation workflows and deliberate removal attacks. Operational trials should report false-positive and false-negative rates at the very low error levels required by synthesis providers and public databases, not only average research benchmarks.
The assessment would weaken if independent teams find material loss of function, easy removal without functional cost, false detections in natural proteins or incompatible marks across developers. For now, the peer-reviewed result is a substantial technical demonstration: some AI-designed proteins and predicted structures can carry a detectable signal without losing the tested properties. It is not yet evidence that the biological design ecosystem has an interoperable or enforceable provenance system.[1][2]
What this means for people
- Patients and research participants need provenance records to support—not replace—evidence about a biological product's safety and efficacy.
- Laboratories and synthesis providers could gain an additional triage signal, but still need conventional screening and human review.
- Scientists relying on public databases may benefit from clearer identification of machine-generated sequences and structures.
Global context
Protein design, DNA synthesis and biological databases operate across borders. A watermark developed by one company becomes useful infrastructure only if independent laboratories, synthesis providers, database operators and regulators can agree how it should be detected, audited and combined with existing screening obligations.
What the evidence does not yet show
- The laboratory validation used known binder backbones and three targets, not a representative sample of all proteins or a complete de-novo discovery programme.
- Detection relies on participating models, protected keys and chosen operating thresholds; unmarked output and later modifications remain possible.
- The structure watermark lacks robustness to some relaxation procedures and currently identifies a mark rather than a specific user or full provenance history.
What to watch next
- Independent laboratory replication across enzymes, antibodies, therapeutic candidates and proteins with functions beyond binding.
- Operational false-positive and false-negative rates in DNA-synthesis screening and public biological databases.
- Interoperable standards defining detector access, key governance, auditability and treatment of edited or partly watermarked sequences.
Evidence trail
Sources used for this report
Links checked 1 October 2026
This report is labelled multi-source analysis. We summarise and analyse source material in our own words; company statements remain attributed claims until independently supported. Translated summaries preserve the meaning of the original source and link back to it. Read our editorial standards.
Continue the story
Related reporting
AI Risks & Safety
Does the White House AI accord create enforceable safety rules?
Six major AI companies signed a four-layer commitment covering internal controls, external evaluation and board oversight. The text is concrete enough to audit later—but voluntary, undefined and silent on publication, deadlines and sanctions.
5 min · 4 sources
AI Risks & Safety
OpenAI holds GPT-6.1 Astra release after safety tests fall short
The company confirmed on 28 September that the planned October launch would not go ahead. Reuters and AP report concerns about scope, authorization and how the model describes its actions; detailed test results remain private.
4 min · 2 sources
AI Risks & Safety
Anthropic's IPO prospectus puts AI safety risks before investors, Reuters reports
Reuters says a prospective filing devotes roughly 80 of 261 main-body pages to risks, including possible loss of control over advanced models. The complete document was not independently available for this analysis.
4 min · 1 source
Reader discussion
Add evidence, experience or a question
No account is required. Reader notes are published after a brief civility, relevance and safety check; disagreement is welcome.
Published reader notes
0No published reader notes yet. You can start the evidence-led discussion above.
Prefer a private correction or response? Contact the newsroom.