Biomedicine
How protein watermarks leave a trace of AI design
DeepMind’s SynthID Bio attempts to embed provenance signals in protein sequences or predicted three-dimensional structures. The work highlighted by Hassabis and Pichai is a proof of concept that preserves biological function in tested designs, not a universal detector of AI-generated biology.
A watermark is more than a label attached to a file. For sequences, the method subtly guides amino-acid selection; for predicted structures, it adjusts atomic coordinates to carry a detectable signal. The sequence approach aims to retain a verifiable provenance trace after a design is synthesized into a physical protein.
The team used AlphaProteo and a watermarked version of ProteinMPNN to design proteins that bind to particular targets. Across VEGF-A, the SARS-CoV-2 spike receptor-binding domain and PD-L1, it reported comparable hit rates, binding strength and sequence diversity for watermarked and unwatermarked designs. Testing binding to those targets does not establish that every possible function is unaffected.
For structure prediction, the team fine-tuned part of AlphaFold 3’s diffusion network so that output coordinates carry a signal. It reported preserved prediction accuracy and detection that withstands digital noise or small coordinate changes. Resistance to deliberate tampering remains a research challenge.
The proposed use is an additional provenance signal for synthesis screening and biological databases. An unfamiliar sequence could be a natural discovery or an AI design; mislabeled synthetic structures could also affect later research. Watermarks help distinguish origins but cannot alone establish whether a design is dangerous. Adoption and stronger resistance to tampering remain future work.