Google DeepMind Gives AI-Designed Proteins a Watermark


Proteins were once only created by nature. But it’s now possible to design completely new proteins from scratch using AI. The possibilities are endless. AI-designed proteins could become powerful drugs battling medical scourges, sentinels for the environment, or even the building blocks of synthetic life—including dangerous new pathogens.

Biosecurity is an obvious concern. But there’s another problem too: biological AI slop. AI-generated structures could pollute the databases scientists rely on to test theories or tweak protein functions. Without a way to distinguish experimentally validated structures from ones that AI simply dreamt up, scientists could spend months building on a rotten foundation.

To prevent this, AI-designed proteins could soon carry a watermark. Adapted from a technology that labels AI-generated text, images, audio, and video, a new Google DeepMind method called SynthID Bio sneaks a subtle signal into proteins during the design process. The tool could be built directly into protein-design systems such as AlphaFold and RFdiffusion.

“AI is expanding what scientists can design, and DNA synthesis companies have an important role in helping that innovation scale responsibly,” said James Diggans at Twist Bioscience in South San Francisco, who was not involved in the work but provided early feedback.

Not everyone is sold on blanket watermarking. The process can jostle protein structure just enough to produce a less optimal, if still functional, version of the molecules. For protein scientists tackling non-sensitive research questions, this could amount to “added complexity” that worries them, Oliver Crook at the University of Oxford told Science.

DeepMind acknowledges that SynthID Bio is just a first step towards tracking AI-generated biological molecules, and plenty of kinks still need ironing out. But they hope to start a conversation about the pros and cons of watermarks and how to best implement them. Ideally, watermarks allow research to continue freely while still preventing dangerous AI designs from crossing into the physical world.

Gap in the Guardrails

There’s no doubt AI is transforming biological research. From deciphering protein structures and mapping their interactions to dreaming up entirely new proteins, these tools have opened a new window on the mechanics of life.

But it’s a double-edged sword.

Last year, a study found that existing biosecurity software struggles to recognize synthetic toxins generated by freely available AI tools. And a more recent study in which scientists used AI to design entirely new bacteriophages—viruses that infect bacteria—earned scientific praise and set off alarm bells. The work showed AI can write biological functions at whole-genome scale, a scientific triumph that, in the wrong hands, could potentially help create a bioweapon.

Thankfully, a major guardrail is already in place. Cells build proteins from DNA instructions. So, to synthesize a protein, researchers must send the molecule’s genetic blueprint to a commercial provider. There, the provider can compare the sequence to a large database of “controlled” DNA sequences. Suspicious sequences are flagged for human review to make sure they don’t encode toxins or proteins from pathogens.

But AI-designed proteins complicate the picture. If a sequence widely differs from anything in the database, it could slip through the cracks, even if the resulting protein is a brand new toxin. AI tools can also tweak sequences just enough to evade detection. Conversely, a dangerous sequence might fly under the radar if it looks too much like one already labeled safe.

One workaround is to screen not just for matching sequences, but also for expected biological function. But that means those conducting the screening need to have some idea of what the resulting protein might do—a tall order for a new sequence unlike anything in nature.

A watermark might offer a simpler alternative.

A Digital Trail

DeepMind adapted its new method from SynthID-Text, released in 2024 to watermark AI-generated content.

The watermark is not an individual stamp slapped onto an existing sequence. Rather, it emerges from nuances in language during generation. When producing text, AI predicts how likely each word is to follow the words before it. SynthID-Text nudges those choices—for example, favoring “researcher” over “scientist”—without changing a sentence’s meaning. An average user wouldn’t notice. But across longer chats, the tiny tweaks add up to a statistical signature that a detector can recognize as “made by AI.”

Proteins are also strings of “letters,” or amino acids, that follow biophysical rules as they fold into three-dimensional shapes. SynthID Bio applies a similar trick to its predecessor, subtly altering design decisions, such as which amino acid comes next. It also slightly adjusts the protein’s final form through tiny shifts in its atoms’ locations. The approach fine-tunes a small part of AlphaFold3 for structural prediction, so proteins generated by the model inherently carry the watermark, regardless of who runs it.

Proteins are finicky, and even minute changes can scramble their function. So the team put its watermarking system through a series of stress tests, generating proteins designed to latch onto multiple targets, including those related to regulating the immune system, blood vessel growth, and viral proteins. In lab tests, the watermarked versions performed just as well as their unwatermarked counterparts, making them “the first-ever watermarked and biologically functional protein binders,” wrote the team.

But there’s a catch: The watermark can be scrubbed. If you run a marked protein through another design tool to generate a new but functionally similar sequence, the tag effectively disappears. Also, SynthID Bio can’t currently be used to identify the creator of a protein, limiting its ability to trace illicit use or to mark intellectual property.

Other systems are in the works. FoldMark, for example, embeds a unique 32-bit digital watermark into a protein’s structure by slightly changing its geometry. The team tested the system on several proteins and found they retained normal function. In simulations, the system could distinguish among as many as one million hypothetical users. Another idea is to give scientists a private “identifier” to watermark the proteins they create. A DNA synthesis provider could then check the sequence to see if an order came from an authorized user.

Regardless of the method, watermarking raises an inevitable question: Who gets the decoder key? DNA synthesis companies are one obvious choice. But there’s little agreement on who else should get access. A recent survey of 130 stakeholders including biosecurity experts, government agencies, policymakers, and academics did not land on a general consensus.

To keep the conversation going, DeepMind is releasing its SynthID Bio code and experimental data to researchers. The company is also expanding the technology to more complex biological systems. In collaboration with Arc Institute and Stanford University, the team has watermarked the genomes of AI-designed bacteriophages, without disabling them, in early tests.

“We believe this work has the potential to address some of the biosecurity risks associated with genome design,” wrote the team. “By working openly with partners across biosecurity, gene synthesis, and policy, we can ensure safety and responsibility keeps pace with AI-driven discovery.”



Source link

  • Related Posts

    Lucid Motors’ EV output falls to lowest level in almost two years

    Lucid Motors built 2,954 electric vehicles (EVs) in the third quarter of this year, a 54% drop from a year ago, as the company purposely limits production to better meet…

    Continue reading
    Are Extended Warranties On TVs And Laptops Ever Really Worth It?

    For starters, extended warranties are typically focused around defects, and any TV, laptop or similarly expensive device is likely to be covered by the manufacturer for 90 days to a…

    Continue reading

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    SmartCentres Real Estate Investment Trust to Release 2026 Third Quarter Results and Host Conference Call

    In Photos: British Airways Unveils All-New Airbus A380 Interior With World’s Largest Business Class Cabin

    In Photos: British Airways Unveils All-New Airbus A380 Interior With World’s Largest Business Class Cabin

    IND vs WI, 1st T20I – Morne Morkel on Mayank Yadav, Prince Yadav – ‘You want guys with fantastic attitudes’

    IND vs WI, 1st T20I – Morne Morkel on Mayank Yadav, Prince Yadav – ‘You want guys with fantastic attitudes’

    Lucid Motors’ EV output falls to lowest level in almost two years

    Lucid Motors’ EV output falls to lowest level in almost two years

    Zelda: Majora’s Mask Soundtrack Joins Nintendo Music This Week

    Zelda: Majora’s Mask Soundtrack Joins Nintendo Music This Week

    MPI’s theEVENT Reaches Capacity in Vancouver; EMEC 2027 Registration Opens for Galway