Google researchers have adapted SynthID watermarking to proteins created with AI, embedding a statistical signal in the amino-acid sequence without deliberately changing the protein’s intended shape. The goal is to help DNA suppliers distinguish designs from trusted institutions when ordinary threat screens encounter an unfamiliar sequence.

SynthID Bio works with ProteinMPNN, a tool that chooses amino acids for a predefined protein backbone. At positions where several chemically suitable amino acids could work, the watermark system uses a secret key and earlier choices to favor one carrying its signal. ProteinMPNN can reject a suggestion that would not fit the functional design.

The signal is distributed across the protein and detected by scanning the full sequence with the correct key. In laboratory tests, watermarked proteins still bound their intended natural targets. Binding is a narrower test than enzyme catalysis, so the result demonstrates a proof of concept rather than universal preservation of every biological function.

The system does not declare an unmarked protein dangerous. It could instead help screeners focus attention on novel designs lacking a trusted watermark. Very short proteins may not contain enough signal, adding unrelated sequence could dilute detection, and other design methods may not integrate easily. Secure distribution of watermark keys and the statistical threshold for false positives and negatives are additional deployment challenges.