Secret watermark labels proteins as ‘made by AI’

Wait 5 sec.

NEWS30 September 2026An innovative safeguard could help to flag proteins devised by artificial-intelligence tools such as AlphaFold, but the digital marker can be erased.ByElie Dolgin0Elie DolginElie Dolgin is a science journalist in Somerville, Massachusetts.View author publicationsSearch author on: PubMed  Google ScholarSave articleView saved researchProteins (artist’s illustration) designed by AI tools can now incorporate a hidden digital tag revealing their origins. Credit: Christoph Burgstedt/SPLProteins designed by artificial intelligence could soon carry a hidden signature of their machine-generated origins, thanks to a watermarking system described today in Nature1.The technology, developed by researchers at Google DeepMind in London, borrows a trick that is already used to identify AI-made content across images, video, audio and text. It involves weaving a faint statistical tell into both the amino-acid sequence and 3D shape of computer-designed proteins — without noticeably compromising their function.Known as SynthIDBio, the approach could distinguish AI-generated proteins in biological repositories from their natural counterparts, helping to preserve the integrity of databases that underpin both scientific research and biosecurity screening.Five protein-design questions that still challenge AISteph Guerra, a biosecurity scholar at the non-profit research organization RAND in Washington DC, sees value in an approach that aligns interests across the life-sciences community. Watermarking can support innovation and scientific reproducibility, she says, “and, at the same time, have a security benefit”.The catch is that this molecular stamp can be scrubbed away. Someone who wants to erase the ‘made by AI’ tag can, in many cases, run a watermarked protein through another design tool and generate a new sequence that retains the protein’s structure and function but obscures its synthetic origins.It is therefore best viewed as one more tool in a layered framework for guarding against biological threats, says Tessa Alexanian, a biosecurity researcher formerly at the International Biosecurity and Biosafety Initiative for Science, a non-profit organization in Geneva, Switzerland. “We’re in a wild new world,” she says.Blind spots in biosecurityAmong the potential users of the watermarking system are companies that make DNA sequences to order. Customers then use this DNA to produce their desired proteins.Such companies routinely check whether a customer’s DNA sequence encodes known toxins, proteins made by pathogens and other concerning molecules. But they could miss a design dreamt up by AI with a protein sequence that bears little or no resemblance to anything in their reference databases, even if the resulting protein performs much the same function once produced and put into a cell.AI can design viruses, toxins and other bioweapons. How worried should we be?One solution, outlined by Alexanian and her colleagues, involves screening not only for sequence matches but also for the biological function that a DNA seqeuence might encode.2,3,4 That still requires working out what the resulting protein might do, however.SynthIDBio offers a simpler alternative: it inserts a hidden clue into any AI-designed protein — encoded both at the sequence level, by subtly changing the pattern of amino acid building blocks that comprise the protein, and in the protein’s 3D shape, through tiny changes in the way its atoms are arranged.The watermark would automatically be added to proteins designed by AI tools such as AlphaFold and RFdiffusion. It could be spotted by anyone who held a secret detection key, which would be shared only with trusted partners such as DNA sequence makers.The watermark could still be useful even though it reveals nothing except that a protein was made using an AI tool. “The synthesis providers I’ve talked to have been kind of like, ‘Any information you can give us to make sense of these orders is good’,” Alexanian says.Marking without manglingBut that utility is undermined if the watermark interferes with what a protein is designed to do. So, computer scientist Pushmeet Kohli and his team at DeepMind “stress-tested the approach on a number of challenging problems”, he says. They found that the watermarked proteins were able to bind to a range targets — including those involved in viral infection, blood-vessel formation and immune regulation — as efficiently as unwatermarked ones.doi: https://doi.org/10.1038/d41586-026-03033-yReferencesStutz, D. et al. Nature https://doi.org/10.1038/s41586-026-10965-y (2026).Article  Google Scholar Wittmann, B. J. et al. Science 390, 82–87 (2025).Article  PubMed  Google Scholar Abel, G. R. Jr. et al. Front. Bioeng. Biotechnol. 14, 1832724 (2026).Article  PubMed  Google Scholar Wittmann, B. J. et al. Front. Bioeng. Biotechnol. 14, 1858951 (2026).Article  PubMed  Google Scholar Zhang, Z. et al. Preprint at bioRxiv https://doi.org/10.1101/2024.10.23.619960 (2026).Zhang, Z. et al. Preprint at arXiv https://doi.org/10.48550/arXiv.2510.15975 (2025).Download referencesRelated Articles Can Anthropic’s invisible watermarks curb ‘AI slop’? Researchers remain sceptical AI co-scientists are revolutionizing how research is done AlphaFold database hits ‘next level’: the AI system now includes protein pairing Beyond AlphaFold: how AI is decoding the grammar of the genome AI has dreamt up a blizzard of new proteins. Do any of them actually work?SubjectsMachine learningComputer scienceStructural biologyLatest on:Machine learningComputer scienceStructural biologyJobs AI ScientistJoin the Casale Group at Human Technopole in Milan to build AI systems that turn human genetics and biomedical data into disease discoveries.Milan (IT)Human Technopole