SynthID Bio is a suite of watermarking methods adapted for synthetic biology that embeds imperceptible signatures directly into biological code. The approach produces a signal that can be verified not only in digital models but also on synthesized, physical proteins, while preserving biological function in laboratory tests.
Why this matters
Generative AI is accelerating protein engineering — from structure prediction with AlphaFold to de novo design with systems such as AlphaProteo and ProteinMPNN, and more recently design of bacteriophages. These tools also create new challenges: AI‑designed sequences can evade traditional DNA synthesis screening, and mislabeled synthetic 3D structures can contaminate public databases and mislead subsequent research.
How SynthID Bio works
SynthID Bio adapts its watermarking strategy to the data type. For sequences, it subtly guides amino acid choices; for predicted 3D structures, it adjusts atomic coordinates. These changes create a reliable detection signal intended to survive both digital and experimental workflows. The authors report that these adjustments did not compromise the proteins’ biological function in their tests.
Experimental validation: watermarked protein binders
To validate the approach for protein binders (molecules designed to selectively bind other proteins), the team used AlphaProteo together with a SynthID Bio‑enabled version of ProteinMPNN. In wet‑lab testing against three target proteins — VEGF‑A, the SARS‑CoV‑2 spike protein RBD, and PD‑L1 — the watermarked designs matched the hit rate, binding affinity, and natural sequence diversity of unwatermarked controls. The report states these are the first demonstrated cases of watermarked, biologically functional protein binders.
Watermarking protein folding models
For folding predictions, SynthID Bio fine‑tunes a small part of AlphaFold 3’s diffusion network so that the model weights themselves encode a detectable signature in predicted 3D coordinates. According to the authors, this preserves AlphaFold 3 prediction accuracy while delivering near‑perfect detectability, maintaining key structural feature distributions and resisting digital noise or minor coordinate perturbations.
Strengthening biosecurity and scientific integrity
The team positions SynthID Bio as an additional layer in a multi‑layered biosecurity strategy. Because converting digital designs into physical molecules requires orders to DNA synthesis providers — who screen requests against databases of known threats — a verifiable signal that links a sequence to a trusted model can reduce the need for exhaustive manual reviews when sequences are unfamiliar.
Sarah Carter, a biosecurity policy expert and Principal at Science Policy Consulting, who reviewed the work, described SynthID Bio as an important tool for tracking the provenance of biological designs. James Diggans (Vice President, Policy and Biosecurity, Twist Bioscience) provided early feedback, noting that watermarking could help focus screening resources and make biosecurity processes more efficient as AI‑designed biology scales.
SynthID Bio could also help maintain the integrity of community resources such as the Protein Data Bank, UniProt and GenBank by helping to flag or correctly label synthetic submissions.
Future directions
The authors note that no single intervention will eliminate all biosecurity risks. Key next steps include improving watermark robustness against deliberate tampering and pairing watermarking with provenance metadata approaches (analogous to C2PA for digital media) or central repositories of AI‑generated biological data.
In ongoing work with the Hie lab (Stanford University) and Arc Institute, the team integrated SynthID Bio into Evo 2 to watermark the genome of an Evo 2–designed bacteriophage; early in vitro testing in bacterial cultures reportedly confirmed functionality. The authors intend to provide further technical details in a forthcoming manuscript.
To support community review and further research, the team is publishing a methods paper, open‑sourcing code and in vitro data, and releasing model weights to the research community. They invite partnership inquiries at synthidbio@google.com, asking correspondents to provide a high‑level proposal and not to include confidential or proprietary information.
Acknowledgements
The project was initiated by Pushmeet Kohli. Research and technical development were led by Alexander I. Cowen‑Rivers and David Stutz, with Pushmeet Kohli advising. Key engineering and research contributions came from Guillermo Ortiz‑Jimenez, Jeremy Ratcliff, Vinicius Zambaldi, Lindsay Willmore, Josh Abramson, Harshnira Patani, Christina Kouridi, Florian Stimberg, Mel Vecerik, Alex Chu, Sukhdeep Singh, Sumanth Dathathri, Eliseo Papa, Valentin De Bortoli, Arnaud Doucet, Jue Wang, and Sven Gowal. The team thanks Adaptyv Bio for help with in vitro validation.
The extension of this work to watermark bacteriophage DNA is a collaboration between Google DeepMind and the Hie lab at Stanford and Arc Institute, with contributions from Jeremy Ratcliff, Aleks Petrov, Alexander I. Cowen‑Rivers, David Stutz, Elisa L. H. Wong, Victor Martin Palacios, Francesca Pietra, Alfred Piccioni, Tristan Oliver Kwan, Tor Lattimore, Sumanth Dathathri, and Pushmeet Kohli at Google DeepMind, and Brian Hie, Samuel King, and Aditi Merchant at Arc Institute and Stanford.
Additional contributors to the research article and technical work are acknowledged by name, and the authors thank Demis Hassabis for encouragement and support.



