Microsoft Paint and Photos May Be Tagging Your AI Images Without Telling You


paint photos ai watermark
Image credit: Microsoft

Microsoft Paint and Photos may embed invisible identifiers into AI-generated images, potentially allowing generated content to carry a unique server-issued ID, according to security researcher Xusheng Li.

Li found that Microsoft uses a GUID, or Globally Unique Identifier, as an invisible watermark inside AI-generated images. A GUID is a 128-bit value designed to uniquely identify data.

Paint reportedly adds server-issued IDs to local AI images

According to Li’s analysis, the identifier appears even when Copilot generates the actual image locally on the user’s device.

The process still involves Microsoft’s servers. Paint reportedly sends the user’s prompt to Microsoft, where the service returns a revised prompt alongside a separate watermark identifier.

Paint then uses that identifier when generating and saving the image locally.

During his research, Li discovered a component called Watermarker.dll inside Paint’s AI features. The DLL appears responsible for adding the invisible identifier to generated images.

Microsoft also includes C2PA Content Credentials, which provide information about an image’s origin and editing history.

Li found that the same watermarkId also appears inside the C2PA metadata as a soft-binding value, linking the invisible pixel-level watermark to the image’s provenance metadata.

Microsoft Photos appears to use the same watermarking system

The system does not appear limited to Paint.

Microsoft Photos also includes Watermarker.dll, with AI features such as Image Creator and Restyle Image apparently embedding GUIDs into generated images as well.

Microsoft has previously disclosed its use of C2PA Content Credentials. The company has also acknowledged that prompts can reach Microsoft servers for moderation, even when an AI model runs locally.

However, Microsoft does not appear to have publicly disclosed that those prompts can receive a server-issued GUID that later becomes embedded in the resulting image.

Researcher raises privacy concerns

Li argues that the identifier could create privacy concerns depending on what Microsoft stores alongside it.

If Microsoft links these GUIDs to Microsoft accounts, devices, or other identifying information, someone with access to that data could potentially trace an AI-generated image back to its creator.

The issue has similarities to the recent GDID controversy, which raised questions about persistent identifiers assigned to Windows installations.

Microsoft has not yet officially responded to Li’s findings.

Microsoft is not alone in adopting hidden watermarking technologies. Claude will add hidden watermarks to AI-generated text for users in the European Union.

Via Neowin

More about the topics: AI, microsoft, Microsoft Paint, photos app

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages