cd /news/ai-safety/microsoft-ai-watermarks-in-paint-and… · home topics ai-safety article
[ARTICLE · art-109535] src=machinebrief.com ↗ pub= topic=ai-safety verified=true sentiment=· neutral

Microsoft AI watermarks in Paint and Photos are linked to user IDs, researcher finds

Microsoft embeds a server-issued GUID as an invisible watermark in AI-generated images from Paint and Photos, linking the image to the user's prompt, according to an analysis by software developer Xusheng Li of Vector 35. The watermark, a 16-byte integer, is encoded into pixels after the prompt is sent to Microsoft for moderation, and successive requests are linked via lastPromptGenerationId, potentially allowing Microsoft to identify users. Microsoft has not commented, while Meta and OpenAI are pursuing similar watermarking approaches.

read3 min views1 publishedAug 25, 2026
Microsoft AI watermarks in Paint and Photos are linked to user IDs, researcher finds
Image: Machinebrief (auto-discovered)

Source:

The RegisterPrivacy? Not if you use hosted AI services When

Anthropicdisclosed earlier this month that it would be applying a statistical word-choice watermark to itsClaudetext output, the company noted that at least 190 AI providers have agreed to abide by Europe's AI transparency rules. One such company is Microsoft, which has been applying its own form of watermarking to images created with the assistance of AI in its Paint and Photos applications for Windows. The EU's Code of Practice on Transparency of AI-generated Content requires that signatories mark content created with the help of AI in a machine-readable format and that associated metadata indicates at least whether content has been manipulated by AI, or entirely created by it. The regulation creates an obligation but does not specify the method of compliance, so signatories can employ whatever technology best achieves the goals [PDF] of "effectiveness, interoperability, robustness, and reliability." Microsoft has gone beyond minimum requirements in an effort to addressAI safetyconcerns. The EU rules encourage, but do not demand, the inclusion of metadata that does more than answer whether creators used AI to produce content. Redmond, as one of the founders of the Coalition for Content Provenance and Authenticity (C2PA), has chosen to embed AI-assisted images in Paint and Photos with a globally unique identifier (GUID) linked to the prompt that created the image. Xusheng Li, a software developer at Vector 35, recently published an analysis of Microsoft's approach, which the Windows biz previously disclosed in the Paint and Photos documentation but did not detail. "Microsoft Paint and Photos embed a server-issued GUID as an invisible watermark in locally generated AI images," Li explained in a LinkedIn post. "Your prompt is sent to Microsoft for moderation, and the returned GUID is encoded into the pixels." Li notes that the invisible GUID watermark – a 16-byte integer – is distinct from the visible watermark option that Microsoft provides to users of its Paint software and Microsoft 365 AI features. If Microsoft associates each prompt with the user who sent it, then the company could in theory identify users by referring to the watermark in an image. Long ago, manufacturers of laser printers implemented this sort of tracking and the practice alarmed privacy advocates when it came to light. "Microsoft receives and moderates the prompt, then issues the unique GUID that Paint embeds into the locally generated image," Li said. "Paint also sends the previous promptGenerationId as lastPromptGenerationId with its next moderation request, allowing successive requests to be linked explicitly." Li argues that while Microsoft has disclosed its AI safety measures, it hasn't sufficiently clarified that its C2PA manifest contains a GUID linked to users' AI image prompts. Microsoft did not immediately respond to a request for comment. Other companies are thinking along similar lines. Meta last month said it is working on its own watermarking technology called Content Seal. And OpenAI has been applying GoogleDeepMind's SynthID and C2PA metadata to its images. Those seeking to avoid having a tracking number embedded in their AI-generated images may want to explore running an open weight model likeStable Diffusionand running on-device open-source tools. ®Get AI news in your inbox

Daily digest of what matters in AI.

Key Terms Explained #

AI Safety

The broad field studying how to build AI systems that are safe, reliable, and beneficial.

Anthropic

An AI safety company founded in 2021 by former OpenAI researchers, including Dario and Daniela Amodei.

Claude

Anthropic's family of AI assistants, including Claude Haiku, Sonnet, and Opus.

DeepMind

A leading AI research lab, now part of Google.

── more in #ai-safety 4 stories · sorted by recency
── more on @microsoft 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/microsoft-ai-waterma…] indexed:0 read:3min 2026-08-25 ·