METAL for iPhone

Read AI news in the METAL app.

Download METAL and discover fresh AI stories every day.

Download on the App Store

For iPhone · Free download

Search for METAL AI Magazine in the App Store on your iPhone.

METAL

Google DeepMind unveils SynthID Bio

Google DeepMind has unveiled SynthID Bio, which embeds watermarks in the sequences and 3D structures of AI-designed proteins. In wet-lab tests on three target proteins, the watermarked designs kept their function, and the company is releasing the code and weights.

Google DeepMind unveils SynthID Bio

Image: METAL

Summary

  • On September 30, Google DeepMind unveiled SynthID Bio, which embeds an imperceptible watermark in the sequences and predicted structures of AI-designed proteins.
  • In experiments on three targets, VEGF-A, the SARS-CoV-2 spike receptor-binding domain and PD-L1, watermarked designs matched unwatermarked ones on hit rate, binding affinity and sequence diversity.
  • DeepMind presents the technology as a provenance signal for DNA synthesis screening and public database curation, and is publishing a methods paper along with code and weights.

Google DeepMind on September 30 unveiled SynthID Bio, a technology that embeds watermarks in proteins designed by AI. Rather than marking a digital file, it places an imperceptible signature in the biological code itself, and that signature can be verified on the physically synthesized protein. The company said that in laboratory testing the watermark did not impair the protein's biological function. It is the first time SynthID, previously used for images and text, has been carried into synthetic biology.

The starting point is a gap in biosecurity. According to DeepMind, generative AI is now tackling biological problems, from AlphaFold predicting protein structures, to AlphaProteo and ProteinMPNN designing new proteins, and more recently the design of bacteriophages, viruses that infect bacteria. Yet novel AI designs can slip past traditional DNA synthesis screening, and mislabeled synthetic 3D structures can pollute public databases and mislead downstream research. The watermark targets both points.

The method changes with the type of data. For protein sequences it subtly guides the choice of amino acids, and for predicted 3D structures it adjusts atomic coordinates, producing a detectable signal. The test case was protein binders, molecules built to latch selectively onto other proteins. The researchers generated designs using the company's binder design method AlphaProteo together with a SynthID Bio-enabled version of ProteinMPNN.

The results came from three target proteins. In wet-lab experiments against VEGF-A, a blood vessel growth factor, the receptor-binding domain of the SARS-CoV-2 spike protein, and the immune checkpoint protein PD-L1, watermarked designs matched unwatermarked ones on hit rate, binding affinity and natural sequence diversity. DeepMind said this produced the first protein binders that are both watermarked and biologically functional. Adaptyv Bio took part in the lab validation.

The approach on the structure prediction side is bolder. SynthID Bio fine-tunes a small part of AlphaFold 3's diffusion network, building the watermarking ability into the model's weights. As a result, a detectable signature remains in the predicted 3D coordinates no matter who runs the model. According to the company, the method preserved AlphaFold 3's prediction accuracy while achieving near-perfect detectability, kept the distributions of key structural features, and held up against digital noise and small coordinate changes.

PD-L1, 코로나19 스파이크 수용체 결합 부위, VEGF-A 세 표적에서 워터마크를 넣은 설계(파랑)와 넣지 않은 설계(주황)의 결합 친화도 분포를 비교한 바이올린 도표. 두 분포가 거의 같은 범위에 놓인다

The first place this technology would be used is DNA synthesis screening. Turning a digital protein design into a physical molecule requires an order to a DNA synthesis provider, which checks the order against databases of known threats. In the past, an unfamiliar sequence could safely be assumed to be an undiscovered natural organism, but AI creates new sequences with little resemblance to known hazards. DeepMind explained that instead of research stalling while unfamiliar orders are reviewed by hand, the watermark could serve as an automated signal proving an order came from a trusted model with built-in safeguards.

Reaction from the synthesis industry converged on that point. James Diggans, Vice President of Policy and Biosecurity at Twist Bioscience, who gave early feedback on the paper, said "AI is expanding what scientists can design, and DNA synthesis companies have an important role in helping that innovation scale responsibly." He added that watermarking could be a new tool to strengthen screening and focus resources on sequences that warrant closer review. Sarah Carter, a biosecurity policy expert and Principal at Science Policy Consulting who reviewed the work, said "SynthID Bio is an important piece of the puzzle for tracking the provenance of biological designs," adding that by linking designs to the model developer, it lets developers lead on safety.

Through the lens of legal liability, this watermark is a proof-of-origin device. Once the model that produced a design is recorded in the molecule, synthesis providers gain a basis to check an order's history, and model developers get to design their own chain of accountability for what their models produce. The biosecurity nonprofit NTI, in a commentary, described a setup in which a provider uses a key to confirm that a watermark is present and matches the information submitted by the customer, and noted that a watermark alone does not prevent deliberate misuse. NTI saw the technology as a layer that could mesh with IBBIS's Common Mechanism, the Biodesign Metadata Security Standard being developed by NTI | bio and Lattice Automation, and the BioTrust customer screening model from Sentinel Bio. DeepMind itself framed SynthID Bio as one layer in a Swiss cheese model, where independent safeguards cover each other's blind spots.

Database curation is another use. In repositories that accept public submissions, such as the Protein Data Bank, UniProt and GenBank, mislabeled entries can badly skew biosecurity decisions, and the risk grows as AI-generated biological data accumulates. DeepMind said SynthID Bio could ensure synthetic entries are properly labeled or flagged for further review during submission. The company named stronger resistance to deliberate tampering as a challenge ahead, and proposed pairing the watermark with provenance metadata similar to C2PA for digital media, or with central repositories of AI-generated biological data.

The scope is moving beyond proteins to genomes. With the Hie lab at Stanford University and Arc Institute, DeepMind integrated SynthID Bio into the genomic model Evo 2 and watermarked the genome of a bacteriophage designed by Evo 2. In early testing in bacterial cultures, the watermarked bacteriophages were functional, and the company said it will release a technical manuscript soon. METAL has previously reported on Claude designing proteins that went on to bind, and the faster design gets, the more weight falls on putting a name tag on what it produces.

How it is being released also matters. According to the DeepMind announcement METAL reviewed, the company is publishing a methods paper, open-sourcing the code and in vitro data, and releasing the weights to the research community. The project was initiated by Pushmeet Kohli, and the research was led by Alexander Cowen-Rivers and David Stutz. For a watermark to become a standard for provenance, it must be a signal that synthesis providers, databases and other model developers can all read, not one company's tool, and releasing the code and weights is the first move toward meeting that condition.

Comments