{"id":93952,"topic":"ai","source":"helpnetsecurity.com","title":"Google’s SynthID Bio can watermark AI-designed protein binders without breaking them - helpnetsecurity.com","url":"https://www.helpnetsecurity.com/2026/10/01/synthid-bio-watermark/","url_hash":"aedf3f2ae842cdbfedbba4bee7c5702bef2c1717","author":"","summary":"<a href=\"https://news.google.com/rss/articles/CBMic0FVX3lxTE9jMVhtcG04eGR5enJzR3o1QzdjTHpCQ29ZNEpfdTdhNkNKOTZrblJwUm9jRUZFSVh2U1RRejdkQzluamJsb1dyWnAtSnJYYlZiS0lsQlVwZzFnRGRpXzY5LUh0Qy1PbDVlU0RFR29ZYlEyX1E?oc=5\" target=\"_blank\">Google’s SynthID Bio can watermark AI-designed protein binders without breaking them</a>&nbsp;&nbsp;<font color=\"#6f6f6f\">helpnetsecurity.com</font>","content":"Google’s SynthID Bio can watermark AI-designed protein binders without breaking them\nGoogle DeepMind has built SynthID Bio, a watermark for AI-designed proteins, and shown in wet-lab tests on protein binders that it leaves their function intact. The method hides a signature in the amino acid sequence of a designed protein and in the atomic coordinates of a predicted 3D structure. DeepMind says the signature can be checked on the physical protein after synthesis.\nDeepMind aims the watermark at DNA synthesis screening. Providers who turn digital protein designs into physical molecules check each order against databases of known threats. AI can now produce sequences with little resemblance to known hazards, so screeners can no longer assume an unfamiliar sequence comes from an undiscovered natural organism. Verifying an unfamiliar order by hand can stall research. A watermark would give screeners an automated signal that an order came from a trusted model, one with safeguards built in.\nLab tests\nDeepMind tested protein binders, molecules designed to grab a particular target protein. It paired its AlphaProteo design method with a SynthID Bio version of ProteinMPNN, a commonly used sequence generator, and ran wet-lab tests on three targets: VEGF-A, the receptor-binding domain of the SARS-CoV-2 spike protein, and PD-L1. On all three, watermarked designs matched unwatermarked versions on hit rate, binding affinity and natural sequence diversity. Hit rate is the share of designs that bind their target, so a match means the watermark did not cost researchers working binders on these three targets.\nFor structure prediction, DeepMind fine-tuned a small part of AlphaFold 3’s diffusion network, which builds the watermark into the model’s weights. Anyone who runs the model gets predicted coordinates that carry the signature. AlphaFold 3 keeps its prediction accuracy, and the signal holds up against digital noise and minor coordinate changes. DeepMind calls detectability near-perfect without citing a rate in its blog post.\nDatabases get a second use\nDeepMind also points the watermark at public databases such as the Protein Data Bank, UniProt and GenBank. Many accept public submissions, and mislabeled entries can have an outsized negative effect on biosecurity decisions. At submission, the watermark could help flag synthetic entries for labeling or review.\nWhat it cannot do yet\nDeepMind lists resistance to deliberate tampering as a challenge still to be met. It suggests pairing the watermark with provenance metadata or central repositories of AI-generated biological data, and describes SynthID Bio as one layer next to model-level mitigations and customer vetting, each with potential gaps.\nJames Diggans, VP of policy and biosecurity at Twist Bioscience, gave early feedback on the paper. He calls watermarking “a promising new addition to the biosecurity toolbox that could strengthen screening.”\nEarly phage results\nIn ongoing work with the Hie lab at Stanford University and Arc Institute, DeepMind integrated SynthID Bio into Evo 2, a genomic model, to watermark the genome of an Evo 2-designed bacteriophage, a virus that infects bacteria. Early lab testing in bacteria cultures confirmed the watermarked phages are functional. DeepMind says a technical manuscript will follow.\nDeepMind is publishing the methods paper, open-sourcing the code and in vitro data, and releasing the weights to the research community.","image_url":"https://img.helpnetsecurity.com/wp-content/uploads/2026/10/01052932/synthid_bio-1500.webp","lang":"en","published_at":"2026-10-01T03:31:14+00:00","fetched_at":"2026-10-01T04:15:06+00:00","status":"read","starred":0,"extract_state":"ok","summary_auto":"Google’s SynthID Bio can watermark AI-designed protein binders without breaking them\nGoogle DeepMind has built SynthID Bio, a watermark for AI-designed proteins, and shown in wet-lab tests on protein binders that it leaves their function intact. The method hides a signature in the amino acid sequence of a designed protein and in the atomic coordinates of a predicted 3D structure.","cluster_id":null,"extract_retries":0,"extract_error":null,"contract_version":"news_item.v1","format_contract_version":"news_item_formats.v1","dedup_url":"https://www.helpnetsecurity.com/2026/10/01/synthid-bio-watermark/","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 3451 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":3451,"summary_length":382,"usable_text_length":3451,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":3451,"summary_length":382}},"news_item":{"id":93952,"canonical_url":"https://www.helpnetsecurity.com/2026/10/01/synthid-bio-watermark/","source_url":"https://www.helpnetsecurity.com/2026/10/01/synthid-bio-watermark/","title":"Google’s SynthID Bio can watermark AI-designed protein binders without breaking them - helpnetsecurity.com","source_name":"helpnetsecurity.com","author":null,"published_at":"2026-10-01T03:31:14+00:00","locale":"en","topic":"ai","tags":[],"rss_summary":"<a href=\"https://news.google.com/rss/articles/CBMic0FVX3lxTE9jMVhtcG04eGR5enJzR3o1QzdjTHpCQ29ZNEpfdTdhNkNKOTZrblJwUm9jRUZFSVh2U1RRejdkQzluamJsb1dyWnAtSnJYYlZiS0lsQlVwZzFnRGRpXzY5LUh0Qy1PbDVlU0RFR29ZYlEyX1E?oc=5\" target=\"_blank\">Google’s SynthID Bio can watermark AI-designed protein binders without breaking them</a>&nbsp;&nbsp;<font color=\"#6f6f6f\">helpnetsecurity.com</font>","full_text":"Google’s SynthID Bio can watermark AI-designed protein binders without breaking them\nGoogle DeepMind has built SynthID Bio, a watermark for AI-designed proteins, and shown in wet-lab tests on protein binders that it leaves their function intact. The method hides a signature in the amino acid sequence of a designed protein and in the atomic coordinates of a predicted 3D structure. DeepMind says the signature can be checked on the physical protein after synthesis.\nDeepMind aims the watermark at DNA synthesis screening. Providers who turn digital protein designs into physical molecules check each order against databases of known threats. AI can now produce sequences with little resemblance to known hazards, so screeners can no longer assume an unfamiliar sequence comes from an undiscovered natural organism. Verifying an unfamiliar order by hand can stall research. A watermark would give screeners an automated signal that an order came from a trusted model, one with safeguards built in.\nLab tests\nDeepMind tested protein binders, molecules designed to grab a particular target protein. It paired its AlphaProteo design method with a SynthID Bio version of ProteinMPNN, a commonly used sequence generator, and ran wet-lab tests on three targets: VEGF-A, the receptor-binding domain of the SARS-CoV-2 spike protein, and PD-L1. On all three, watermarked designs matched unwatermarked versions on hit rate, binding affinity and natural sequence diversity. Hit rate is the share of designs that bind their target, so a match means the watermark did not cost researchers working binders on these three targets.\nFor structure prediction, DeepMind fine-tuned a small part of AlphaFold 3’s diffusion network, which builds the watermark into the model’s weights. Anyone who runs the model gets predicted coordinates that carry the signature. AlphaFold 3 keeps its prediction accuracy, and the signal holds up against digital noise and minor coordinate changes. DeepMind calls detectability near-perfect without citing a rate in its blog post.\nDatabases get a second use\nDeepMind also points the watermark at public databases such as the Protein Data Bank, UniProt and GenBank. Many accept public submissions, and mislabeled entries can have an outsized negative effect on biosecurity decisions. At submission, the watermark could help flag synthetic entries for labeling or review.\nWhat it cannot do yet\nDeepMind lists resistance to deliberate tampering as a challenge still to be met. It suggests pairing the watermark with provenance metadata or central repositories of AI-generated biological data, and describes SynthID Bio as one layer next to model-level mitigations and customer vetting, each with potential gaps.\nJames Diggans, VP of policy and biosecurity at Twist Bioscience, gave early feedback on the paper. He calls watermarking “a promising new addition to the biosecurity toolbox that could strengthen screening.”\nEarly phage results\nIn ongoing work with the Hie lab at Stanford University and Arc Institute, DeepMind integrated SynthID Bio into Evo 2, a genomic model, to watermark the genome of an Evo 2-designed bacteriophage, a virus that infects bacteria. Early lab testing in bacteria cultures confirmed the watermarked phages are functional. DeepMind says a technical manuscript will follow.\nDeepMind is publishing the methods paper, open-sourcing the code and in vitro data, and releasing the weights to the research community.","excerpt":"Google’s SynthID Bio can watermark AI-designed protein binders without breaking them\nGoogle DeepMind has built SynthID Bio, a watermark for AI-designed proteins, and shown in wet-lab tests on protein binders that it leaves their function intact. The method hides a signature in the amino acid sequence of a designed protein and in the atomic coordinates of a predicted 3D structure.","extraction":{"state":"ok","confidence":0.9,"error":null,"explanation":"High confidence: full text extraction produced 3451 characters.","diagnostics_url":"/api/diagnose?url=https%3A//www.helpnetsecurity.com/2026/10/01/synthid-bio-watermark/","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 3451 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":3451,"summary_length":382,"usable_text_length":3451,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":3451,"summary_length":382}}},"display_formats":["compact","card","full","digest_section","json"]},"daily_stack_record":{"title":"Google’s SynthID Bio can watermark AI-designed protein binders without breaking them - helpnetsecurity.com","url":"https://www.helpnetsecurity.com/2026/10/01/synthid-bio-watermark/","summary":"Google’s SynthID Bio can watermark AI-designed protein binders without breaking them\nGoogle DeepMind has built SynthID Bio, a watermark for AI-designed proteins, and shown in wet-lab tests on protein binders that it leaves their function intact. The method hides a signature in the amino acid sequence of a designed protein and in the atomic coordinates of a predicted 3D structure.","source":"helpnetsecurity.com","date":"2026-10-01T03:31:14+00:00","content":"Google’s SynthID Bio can watermark AI-designed protein binders without breaking them\nGoogle DeepMind has built SynthID Bio, a watermark for AI-designed proteins, and shown in wet-lab tests on protein binders that it leaves their function intact. The method hides a signature in the amino acid sequence of a designed protein and in the atomic coordinates of a predicted 3D structure. DeepMind says the signature can be checked on the physical protein after synthesis.\nDeepMind aims the watermark at DNA synthesis screening. Providers who turn digital protein designs into physical molecules check each order against databases of known threats. AI can now produce sequences with little resemblance to known hazards, so screeners can no longer assume an unfamiliar sequence comes from an undiscovered natural organism. Verifying an unfamiliar order by hand can stall research. A watermark would give screeners an automated signal that an order came from a trusted model, one with safeguards built in.\nLab tests\nDeepMind tested protein binders, molecules designed to grab a particular target protein. It paired its AlphaProteo design method with a SynthID Bio version of ProteinMPNN, a commonly used sequence generator, and ran wet-lab tests on three targets: VEGF-A, the receptor-binding domain of the SARS-CoV-2 spike protein, and PD-L1. On all three, watermarked designs matched unwatermarked versions on hit rate, binding affinity and natural sequence diversity. Hit rate is the share of designs that bind their target, so a match means the watermark did not cost researchers working binders on these three targets.\nFor structure prediction, DeepMind fine-tuned a small part of AlphaFold 3’s diffusion network, which builds the watermark into the model’s weights. Anyone who runs the model gets predicted coordinates that carry the signature. AlphaFold 3 keeps its prediction accuracy, and the signal holds up against digital noise and minor coordinate changes. DeepMind calls detectability near-perfect without citing a rate in its blog post.\nDatabases get a second use\nDeepMind also points the watermark at public databases such as the Protein Data Bank, UniProt and GenBank. Many accept public submissions, and mislabeled entries can have an outsized negative effect on biosecurity decisions. At submission, the watermark could help flag synthetic entries for labeling or review.\nWhat it cannot do yet\nDeepMind lists resistance to deliberate tampering as a challenge still to be met. It suggests pairing the watermark with provenance metadata or central repositories of AI-generated biological data, and describes SynthID Bio as one layer next to model-level mitigations and customer vetting, each with potential gaps.\nJames Diggans, VP of policy and biosecurity at Twist Bioscience, gave early feedback on the paper. He calls watermarking “a promising new addition to the biosecurity toolbox that could strengthen screening.”\nEarly phage results\nIn ongoing work with the Hie lab at Stanford University and Arc Institute, DeepMind integrated SynthID Bio into Evo 2, a genomic model, to watermark the genome of an Evo 2-designed bacteriophage, a virus that infects bacteria. Early lab testing in bacteria cultures confirmed the watermarked phages are functional. DeepMind says a technical manuscript will follow.\nDeepMind is publishing the methods paper, open-sourcing the code and in vitro data, and releasing the weights to the research community.","confidence":0.9,"diagnostics_url":"/api/diagnose?url=https%3A//www.helpnetsecurity.com/2026/10/01/synthid-bio-watermark/","quality_bucket":"high","failure_kind":"none","retryable":false,"quality_reason":"High confidence: full text extraction produced 3451 characters.","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 3451 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":3451,"summary_length":382,"usable_text_length":3451,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":3451,"summary_length":382}},"tags":[]},"fallback_formats":["markdown","json","html"],"actions":{"read":"/item/93952","export_markdown":"/api/items/93952/export?format=markdown","export_json":"/api/items/93952/export?format=json","diagnose":"/api/diagnose?url=https%3A//www.helpnetsecurity.com/2026/10/01/synthid-bio-watermark/"},"formats":{"full":{"id":93952,"title":"Google’s SynthID Bio can watermark AI-designed protein binders without breaking them - helpnetsecurity.com","url":"https://www.helpnetsecurity.com/2026/10/01/synthid-bio-watermark/","source":"helpnetsecurity.com","author":null,"published_at":"2026-10-01T03:31:14+00:00","locale":"en","topic":"ai","tags":[],"excerpt":"Google’s SynthID Bio can watermark AI-designed protein binders without breaking them\nGoogle DeepMind has built SynthID Bio, a watermark for AI-designed proteins, and shown in wet-lab tests on protein binders that it leaves their function intact. The method hides a signature in the amino acid sequence of a designed protein and in the atomic coordinates of a predicted 3D structure.","full_text":"Google’s SynthID Bio can watermark AI-designed protein binders without breaking them\nGoogle DeepMind has built SynthID Bio, a watermark for AI-designed proteins, and shown in wet-lab tests on protein binders that it leaves their function intact. The method hides a signature in the amino acid sequence of a designed protein and in the atomic coordinates of a predicted 3D structure. DeepMind says the signature can be checked on the physical protein after synthesis.\nDeepMind aims the watermark at DNA synthesis screening. Providers who turn digital protein designs into physical molecules check each order against databases of known threats. AI can now produce sequences with little resemblance to known hazards, so screeners can no longer assume an unfamiliar sequence comes from an undiscovered natural organism. Verifying an unfamiliar order by hand can stall research. A watermark would give screeners an automated signal that an order came from a trusted model, one with safeguards built in.\nLab tests\nDeepMind tested protein binders, molecules designed to grab a particular target protein. It paired its AlphaProteo design method with a SynthID Bio version of ProteinMPNN, a commonly used sequence generator, and ran wet-lab tests on three targets: VEGF-A, the receptor-binding domain of the SARS-CoV-2 spike protein, and PD-L1. On all three, watermarked designs matched unwatermarked versions on hit rate, binding affinity and natural sequence diversity. Hit rate is the share of designs that bind their target, so a match means the watermark did not cost researchers working binders on these three targets.\nFor structure prediction, DeepMind fine-tuned a small part of AlphaFold 3’s diffusion network, which builds the watermark into the model’s weights. Anyone who runs the model gets predicted coordinates that carry the signature. AlphaFold 3 keeps its prediction accuracy, and the signal holds up against digital noise and minor coordinate changes. DeepMind calls detectability near-perfect without citing a rate in its blog post.\nDatabases get a second use\nDeepMind also points the watermark at public databases such as the Protein Data Bank, UniProt and GenBank. Many accept public submissions, and mislabeled entries can have an outsized negative effect on biosecurity decisions. At submission, the watermark could help flag synthetic entries for labeling or review.\nWhat it cannot do yet\nDeepMind lists resistance to deliberate tampering as a challenge still to be met. It suggests pairing the watermark with provenance metadata or central repositories of AI-generated biological data, and describes SynthID Bio as one layer next to model-level mitigations and customer vetting, each with potential gaps.\nJames Diggans, VP of policy and biosecurity at Twist Bioscience, gave early feedback on the paper. He calls watermarking “a promising new addition to the biosecurity toolbox that could strengthen screening.”\nEarly phage results\nIn ongoing work with the Hie lab at Stanford University and Arc Institute, DeepMind integrated SynthID Bio into Evo 2, a genomic model, to watermark the genome of an Evo 2-designed bacteriophage, a virus that infects bacteria. Early lab testing in bacteria cultures confirmed the watermarked phages are functional. DeepMind says a technical manuscript will follow.\nDeepMind is publishing the methods paper, open-sourcing the code and in vitro data, and releasing the weights to the research community.","reading_time_min":3,"extraction":{"state":"ok","confidence":0.9,"error":null,"explanation":"High confidence: full text extraction produced 3451 characters.","diagnostics_url":"/api/diagnose?url=https%3A//www.helpnetsecurity.com/2026/10/01/synthid-bio-watermark/","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 3451 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":3451,"summary_length":382,"usable_text_length":3451,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":3451,"summary_length":382}}},"quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 3451 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":3451,"summary_length":382,"usable_text_length":3451,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":3451,"summary_length":382}},"actions":{"read":"/item/93952","export_markdown":"/api/items/93952/export?format=markdown","export_json":"/api/items/93952/export?format=json","diagnose":"/api/diagnose?url=https%3A//www.helpnetsecurity.com/2026/10/01/synthid-bio-watermark/"}},"digest":{"id":93952,"title":"Google’s SynthID Bio can watermark AI-designed protein binders without breaking them - helpnetsecurity.com","url":"https://www.helpnetsecurity.com/2026/10/01/synthid-bio-watermark/","source":"helpnetsecurity.com","topic":"ai","published_at":"2026-10-01T03:31:14+00:00","excerpt":"Google’s SynthID Bio can watermark AI-designed protein binders without breaking them Google DeepMind has built SynthID Bio, a watermark for AI-designed proteins, and shown in wet-lab tests on protein binders that it leaves their function intact. The method hides a signature in…","quality_bucket":"high","quality_reason":"High confidence: full text extraction produced 3451 characters.","reading_time_min":3,"cluster_id":null},"card":{"display_title":"Google’s SynthID Bio can watermark AI-designed protein binders without breaking them - helpnetsecurity.com","subtitle":"helpnetsecurity.com · 2026-10-01","summary":"Google’s SynthID Bio can watermark AI-designed protein binders without breaking them Google DeepMind has built SynthID Bio, a watermark for AI-designed proteins, and shown in wet-lab tests on protein binders that it…","badges":["quality:high"],"links":{"read":"/item/93952","original":"https://www.helpnetsecurity.com/2026/10/01/synthid-bio-watermark/","diagnose":"/api/diagnose?url=https%3A//www.helpnetsecurity.com/2026/10/01/synthid-bio-watermark/"},"quality_warning":null},"export":{"title":"Google’s SynthID Bio can watermark AI-designed protein binders without breaking them - helpnetsecurity.com","url":"https://www.helpnetsecurity.com/2026/10/01/synthid-bio-watermark/","summary":"Google’s SynthID Bio can watermark AI-designed protein binders without breaking them\nGoogle DeepMind has built SynthID Bio, a watermark for AI-designed proteins, and shown in wet-lab tests on protein binders that it leaves their function intact. The method hides a signature in the amino acid sequence of a designed protein and in the atomic coordinates of a predicted 3D structure.","source":"helpnetsecurity.com","date":"2026-10-01T03:31:14+00:00","content":"Google’s SynthID Bio can watermark AI-designed protein binders without breaking them\nGoogle DeepMind has built SynthID Bio, a watermark for AI-designed proteins, and shown in wet-lab tests on protein binders that it leaves their function intact. The method hides a signature in the amino acid sequence of a designed protein and in the atomic coordinates of a predicted 3D structure. DeepMind says the signature can be checked on the physical protein after synthesis.\nDeepMind aims the watermark at DNA synthesis screening. Providers who turn digital protein designs into physical molecules check each order against databases of known threats. AI can now produce sequences with little resemblance to known hazards, so screeners can no longer assume an unfamiliar sequence comes from an undiscovered natural organism. Verifying an unfamiliar order by hand can stall research. A watermark would give screeners an automated signal that an order came from a trusted model, one with safeguards built in.\nLab tests\nDeepMind tested protein binders, molecules designed to grab a particular target protein. It paired its AlphaProteo design method with a SynthID Bio version of ProteinMPNN, a commonly used sequence generator, and ran wet-lab tests on three targets: VEGF-A, the receptor-binding domain of the SARS-CoV-2 spike protein, and PD-L1. On all three, watermarked designs matched unwatermarked versions on hit rate, binding affinity and natural sequence diversity. Hit rate is the share of designs that bind their target, so a match means the watermark did not cost researchers working binders on these three targets.\nFor structure prediction, DeepMind fine-tuned a small part of AlphaFold 3’s diffusion network, which builds the watermark into the model’s weights. Anyone who runs the model gets predicted coordinates that carry the signature. AlphaFold 3 keeps its prediction accuracy, and the signal holds up against digital noise and minor coordinate changes. DeepMind calls detectability near-perfect without citing a rate in its blog post.\nDatabases get a second use\nDeepMind also points the watermark at public databases such as the Protein Data Bank, UniProt and GenBank. Many accept public submissions, and mislabeled entries can have an outsized negative effect on biosecurity decisions. At submission, the watermark could help flag synthetic entries for labeling or review.\nWhat it cannot do yet\nDeepMind lists resistance to deliberate tampering as a challenge still to be met. It suggests pairing the watermark with provenance metadata or central repositories of AI-generated biological data, and describes SynthID Bio as one layer next to model-level mitigations and customer vetting, each with potential gaps.\nJames Diggans, VP of policy and biosecurity at Twist Bioscience, gave early feedback on the paper. He calls watermarking “a promising new addition to the biosecurity toolbox that could strengthen screening.”\nEarly phage results\nIn ongoing work with the Hie lab at Stanford University and Arc Institute, DeepMind integrated SynthID Bio into Evo 2, a genomic model, to watermark the genome of an Evo 2-designed bacteriophage, a virus that infects bacteria. Early lab testing in bacteria cultures confirmed the watermarked phages are functional. DeepMind says a technical manuscript will follow.\nDeepMind is publishing the methods paper, open-sourcing the code and in vitro data, and releasing the weights to the research community.","confidence":0.9,"diagnostics_url":"/api/diagnose?url=https%3A//www.helpnetsecurity.com/2026/10/01/synthid-bio-watermark/","quality_bucket":"high","failure_kind":"none","retryable":false,"quality_reason":"High confidence: full text extraction produced 3451 characters.","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 3451 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":3451,"summary_length":382,"usable_text_length":3451,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":3451,"summary_length":382}},"tags":[],"format_contract_version":"news_item_formats.v1"}}}