The DeepMind team at Google has published a way to watermark AI-designed proteins, an attempt to close a biosecurity gap that has been open for about a year. The system, called SynthIDBio, builds on Google's SynthID technology, which already embeds hidden, key-dependent signals in AI-generated images, text and audio.

Proteins are a much harder canvas. They are built from only 20 amino acids, and many positions in a sequence cannot be altered without destroying the molecule's function — so there is far less room to hide a signal than in a photo. The team worked with ProteinMPNN, one of the most widely used AI protein design tools, which places amino acids one at a time along a chosen backbone. SynthIDBio intervenes at each step: using a key and the identity of previously chosen residues, it proposes an amino acid, and ProteinMPNN accepts it only if the protein still folds and works. The watermark therefore ends up scattered across the whole sequence, and detection means scanning the full protein with the right key and measuring how often the suggested residues appear.

The practical payoff is screening. When researchers order synthetic DNA, suppliers already check sequences against known viral and toxic proteins — but a novel AI-designed protein has no known relatives to compare against, so it slips through. If universities and biotech companies hand out keys, a synthesizer can quickly confirm that an unknown protein is a trusted AI design and concentrate scrutiny on the sequences that are not.

In tests, watermarked proteins designed to bind specific natural targets still bound them. The authors are candid about the limits: the scheme is only as secure as the key distribution, very short proteins carry too little signal, appending a large unwatermarked domain can dilute the mark, and other design tools that do not build sequences one residue at a time may not integrate at all. Detection is statistical, so the threshold choice trades false positives against false negatives. Even so, it is a rare case of an AI safety idea being shipped as working code before the risk materialised.