Google DeepMind Podcast

Pushmeet Kohli & Jeremy Ratcliffe on watermarking proteins, function intact

Pushmeet Kohli & Jeremy Ratcliffe· VP of Science & Research Scientist at Google DeepMind at Google DeepMind
·~38 min·English·Google DeepMind
AI SafetyMultimodalAI CompanyOpen Source
TL;DR

Google DeepMind's SynthID hides a key-driven signal inside AI output — text, images, and, as a proof of concept, AI-designed proteins — so its AI origin can be detected by anyone holding the key.

01Core Mental Model

Provenance, not a logo

A watermark is not a label stuck on top — it is a signal woven into the content itself, so you can still ask whether something came from a human or an AI model after the file has been edited.

A watermark, not the blocky logo you see on a stock photo, something far more subtle, something mathematical.

— Professor Hannah Fry, Google DeepMind Podcast
Key Insight
Framing provenance as an intrinsic property, not an attachment, is what lets the same idea later survive crops and re-encodes — and eventually attempt the jump from pixels to physical molecules.

02The Design Spec

Three tests a watermark must pass

A usable watermark has to be imperceptible, robust, and scalable all at once — drop any one and people stop using it or attackers strip it out.

We need three properties. One, it should not degrade the quality otherwise basically the whole point is lost. People will not use it.

— Pushmeet Kohli, Google DeepMind Podcast
Key Insight
The team built its watermarks to meet all three requirements at once — not degrading quality, resisting transformations, and staying easy to embed and detect — rather than trading one off against another.

03Why Now

From catching fakes to signing originals

Trained detectors get worse as models get better, because the tells they relied on disappear — so the field shifted from spotting fakes after the fact to signing content at the moment it is generated.

the classifier's accuracy goes down over time as the generative AI models become better

— Pushmeet Kohli, Google DeepMind Podcast
Key Insight
This reframes the usual arms race. Instead of an ever-smarter detector chasing an ever-smarter generator, the generator cooperates by leaving a deliberate signal — moving the hard problem from detection toward key management and adoption.

04Mechanism: Text

Hide a key in the choice of words

When a model has several equally-good next words, a secret key tilts which ones it picks, and a detector holding that key later spots the pattern — even telling which model wrote the text.

if different AI models are using different keys we can sort of check whether this was generated by this model or this other model

— Pushmeet Kohli, Google DeepMind Podcast
Key Insight
Because the signal lives in the pattern of choices rather than in any specific word, there has to be enough text to carry it — so a short factual answer is unwatermarkable, and a public detector can be queried enough times to learn how to evade it.

05Mechanism: Images

Robustness, trained against an attacker

For images the mark is injected by one network and read by another, with an attacker in the middle cropping and distorting the image — all trained together so the signal is harder to shake off.

The watermark generator injects a very small signal which is imperceptible.

— Pushmeet Kohli, Google DeepMind Podcast
Key Insight
Building the attacker into training turns robustness into an explicit objective rather than a hope — the system is optimized against the crops, rotations and noise an adversary would use, though that is not the same as immunity to every future attack.

06The Leap to Biology

The same trick jumps to proteins

Because a protein-design model (ProteinMPNN) generates sequences much like a text model generates words, SynthID's text watermark adapts almost directly to protein sequences, while a separate method marks 3D structures by nudging atom positions.

you can introduce watermarks through the selections of individual amino acids that are likely to have both maintain the same structure and therefore have similar function

— Jeremy Ratcliffe, Google DeepMind Podcast
Key Insight
Reusing the open-source text-watermarking code — instead of inventing a bespoke bio method — is what let a tool built against misinformation reach biosecurity so quickly; the unfinished part is getting model makers and DNA-synthesis firms to share keys and settings.

07The Threat It Addresses

The biosecurity hole it could plug

An AI can design a sequence that looks nothing like any known pathogen yet might fold into a dangerous protein, slipping past the databases DNA-synthesis firms screen against — so a watermark could add a second check: was this order AI-made?

you can make something that in sequence space is very different than something that's present in that pathogen database but might fold into the thing that is of concern

— Jeremy Ratcliffe, Google DeepMind Podcast
Key Insight
Today's screening matches on sequence similarity, which AI design can be built to evade. A watermark changes what is being checked — not "does this look hazardous?" but "did a capable AI system make this?" — which could give screeners a reason to look harder.

08Proof It's Real

They actually made the proteins

The watermarked proteins were built and tested in a lab, not just simulated — the binders bound at near-identical rates whether or not they carried the mark.

we made protein binders. So we made the things that stick.

— Jeremy Ratcliffe, Google DeepMind Podcast
Key Insight
Measuring function preservation in the wet lab — not just in simulation — is what lets the team claim a first for biology; turning a proof of concept into a standard still needs engineering headroom and industry coordination.