What is SynthID Bio: Google’s watermark for AI designed proteins
Google has been secretly embedding invisible watermarks into images created by AI, as well as text and videos, for the last three years. But now it’s trying something similar with proteins. Proteins, yes. The components of your enzymes, muscles and most medicines. This must be a joke, huh? Nope. AI technologies have reached the point where it’s able to create proteins capable of bypassing conventional DNA synthesis detection, which is a big problem for researchers, synthesis firms and biosecurity enthusiasts. That’s SynthID Bio from Google.
SurveyAlso read: The appliance price hike is here: 5 things buyers need to know
What is SynthID Bio
It is an artificial intelligence approach to watermarking created by Google DeepMind and used in synthetic biology. Its appeal is in its catchy and simple concept: to leave a mark in the DNA sequence in such a way that one could later verify it on the actual protein rather than on a computer file.
For DNA sequences, it subtly influences which amino acids are chosen by the model. For protein structures, it changes atomic coordinates. And no biologist will notice any difference. This is how it works.
Does the watermark break the protein
Warranted concern. A watermark that hampers functionality is mere vandalism with an added step. Google assures it does not. The researchers combined AlphaProteo with a SynthID Bio-equipped version of ProteinMPNN to design binders, compounds specifically designed to bind to other proteins, for three targets: VEGF-A, the SARS-CoV-2 spike protein receptor-binding domain (RBD), and PD-L1. The results of wet-lab testing show that watermarked designs perform similarly to non-watermarked designs in terms of hit rate, binding affinity, and sequence diversity.

Also read: First Muse, now Dots: AI is becoming cute, less deadly for now
Regarding structure prediction, Google further trained a small portion of the AlphaFold 3 diffusion network, thus placing the watermark in the network weights. No matter who uses it, the output bears the watermark. Google promises nearly perfect detectability. The announcement does not give any numbers regarding that claim; take it as such until the paper arrives.
Why biosecurity people care
Consider DNA synthesis screening as the front door. Want a custom-made protein? Then, you request the DNA to be synthesized by a company and have it screened against the databases of dangerous sequences. This system relied on an easy-to-understand premise: an unknown sequence should represent something that has not been discovered yet, a natural organism. But AI destroys this premise. With AI models, one could create completely new DNA sequences that would not look like any sequences from the danger watch-list, and the manual verification is a lengthy process. A watermark gives a hint that the sequence is generated by the model with certain guarantees. The same applies to public databases such as the Protein Data Bank, UniProt, and GenBank.
The catch
It resembles a lock, but actually functions like a name tag. A watermark will help catch honest mistakes and sloppy provenance, but a determined malicious actor would never willingly use the watermarked model. Google acknowledges that making the signal tamper resistant remains a problem to be solved, but it is going to release the code, lab data, and model weights to researchers. It’s wonderful for research purposes. But in terms of security, I’d say it’s a gamble.
It should be noted that Google does not over-hype it either. The company positions SynthID Bio as one of the layers in a multilayered approach, similar to a Swiss cheese model of defense, and states that there are no silver bullets when it comes to cybersecurity interventions. James Diggans of Twist Bioscience referred to it as a valuable addition to the biosecurity arsenal.
The most interesting part comes at the very bottom. In collaboration with the lab of Brian Hie from Stanford University and the Arc Institute, Google has applied its watermarks to the genome of a bacteriophage, which is essentially a virus that can infect bacteria with the help of the Evo 2 genomic framework. Preliminary testing has been successful and a technical paper will follow soon. There is nothing about India in the announcement, so the question remains as to whether Indian biotech companies and DNA synthesizers would join the network.
Also read: GPT-6.1 Sol: Everything that’s better than the week old GPT-6 Sol
A journalist with a soft spot for tech, games, and things that go beep. While waiting for a delayed metro or rebooting his brain, you’ll find him solving Rubik’s Cubes, bingeing F1, or hunting for the next great snack. View Full Profile
