Risky Business

Innovation Enables Responsibility: Watermarking to Strengthen DNA Synthesis Screening

In a world where motivated actors can use biological AI tools to evade DNA synthesis screening, how can DNA providers be more confident that the sequences they assemble and ship are safe? Google DeepMind’s biosecurity and provenance teams have developed SynthID Bio, a technical proof-of-concept for watermarking AI-generated protein sequences and structures without degrading their function.

Watermarking is commonly used to authenticate currency. While the exact methods vary based on the medium, it generally involves marking a design with a unique and identifiable pattern that is imperceptible to the casual observer but can be detected by someone with the appropriate tools.

In the case of sequence-watermarking with SynthID Bio, a watermark is created directly within a protein sequence by manipulating specific amino acids using an algorithm. When the watermarked sequence is sent to a DNA service provider for synthesis, the provider could use a key to verify that the watermark is both present and corresponds to the information provided by the customer.

Importantly, SynthID Bio does all of this without impacting the intended end-use of a sequence. This is vital, because even a minor disruption in a sequence could have significant implications for the way it is translated, for example, into a protein necessary for therapeutic drug discovery.

By carefully calibrating their watermarking process to preserve intended function, Google DeepMind has signaled their commitment to advancing scientific inquiry and reducing the barriers to safeguard adoption.

While a watermark by itself does not prevent the deliberate misuse of a biological AI tool, its inclusion in the biosecurity ecosystem offers important benefits. DNA service providers are increasingly confronted with sequences designed by AI-enabled tools that they can’t confirm are safe to synthesize. By embedding SynthID Bio within biological design tools that are known to have other operational safeguards against misuse, the presence of a watermark can act as a signal of assurance that the sequence is likely to be safe.

SynthID Bio is designed to be complementary to existing, widely used screening protocols like IBBIS’ Common Mechanism. It could also be linked to emerging safeguards such as the Biodesign Metadata Security Standard being developed by NTI | bio and Lattice Automation, and the BioTrust model for know-your-customer screening being incubated by Sentinel Bio.

Together, each of these safeguards reinforces the others and creates a layered defense that resists DNA synthesis screening evasion more effectively than any single safeguard could on its own.

September 2026 is proving to be a major flashpoint in discussions around AI safety. Multiple high-profile whistleblower events and publications have led to increased calls for stronger built-in safeguards—such as biosecurity-relevant classifiers—as well as more stringent access controls. At the same time, there are those who reject these calls and argue that safeguards would harm innovation and risk falling behind in a so-called “AI arms race”.

The development of SynthID Bio by a major frontier AI lab is an important reminder that responsible development and cutting-edge progress are not mutually exclusive.

AI developers can and should implement reasonable safeguards against misuse, and in fact, strengthening a critical control point like DNA synthesis has the potential to support faster, more effective beneficial use. After all, you can drive a lot faster if you know your brakes work.

Through their biosecurity work, Google DeepMind has demonstrated a model for the industry not just of responsible development, but also creative solutions to rapidly emerging challenges.

As AIxBio capabilities continue to accelerate, and the realm of possible risks continues to expand, we will need equally expansive and creative solutions, like SynthID Bio, if we hope to ensure the safe and secure use of AI.

Stay Informed

Sign up for our newsletter to get the latest on nuclear and biological threats.

Sign Up


Why Responsible AIxBio Innovation Must Be on New Delhi’s Agenda

Risky Business

Why Responsible AIxBio Innovation Must Be on New Delhi’s Agenda

Some of the world’s largest AI companies—Google DeepMind, OpenAI, and Anthropic—have warned that their models could be misused to cause harm with biology. The India AI Impact Summit is a critical moment for policymakers, scientists, developers, and biosecurity experts to work together on responsible governance that reduces AIxBio risks.


Congress Must Act to Secure U.S. Biotechnology

Risky Business

Congress Must Act to Secure U.S. Biotechnology

Innovation requires security, and security requires innovation. Congress needs to act decisively to ensure U.S. leadership in biotechnology is paired with governance that keeps its development secure.


See All

Close

My Resources

Subscribe to NTI

Sign up for regular updates on innovative, real-world solutions to existential threats.

Get Updates