cd /news/artificial-intelligence/microsofts-ai-image-watermarks-may-i… · home topics artificial-intelligence article
[ARTICLE · art-110292] src=forgeeks.net ↗ pub= topic=artificial-intelligence verified=true sentiment=· neutral

Microsoft’s AI image watermarks may identify users

Microsoft Paint and Photos embed a server-issued 16-byte GUID into AI-generated images, which may be linkable to the user who created them, according to a reverse-engineering analysis by software developer Xusheng Li at Vector 35. The GUID is encoded into the image pixels regardless of the visible watermark setting and is associated with the C2PA provenance record, raising privacy concerns because it could provide a durable handle for identifying the source of an image if Microsoft links it to user accounts.

read4 min views2 publishedAug 25, 2026
Microsoft’s AI image watermarks may identify users
Image: Forgeeks (auto-discovered)

Privacy • Updated • 4 min read

A researcher found Microsoft Paint and Photos embed server-issued GUIDs tied to AI prompts in image pixels, raising privacy concerns.

Source: The Register Microsoft Paint and Photos embed a server-issued 16-byte GUID into images created with AI assistance. The identifier may be linkable to the user who generated the image. Anyone who extracts it could, in theory, connect an image to its creation request.

The mechanism was documented in a reverse-engineering analysis by Xusheng Li, a software developer at Vector 35. Microsoft’s apps send the user’s prompt to Microsoft for moderation. The server returns a globally unique identifier, which Paint then encodes into the image’s pixels.

“Microsoft Paint and Photos embed a server-issued GUID as an invisible watermark in locally generated AI images.”

The identifier is separate from Microsoft’s optional visible watermark. Users can choose to display a visible mark on content produced through Paint and Microsoft 365 AI features, but the GUID is embedded regardless of that setting, according to the analysis. It also differs from ordinary metadata: the value is carried inside the image data as an invisible watermark and is associated with the C2PA provenance record.

Recommended reading

Flock’s police AI can track drivers by behavior

Sergey Kuznetsov • • 4 min read

Li’s analysis says Microsoft’s moderation request includes the prompt, while a later request includes the prior promptGenerationId

as lastPromptGenerationId

. That lets Microsoft associate successive image-generation requests instead of treating each prompt as an unrelated transaction.

“Your prompt is sent to Microsoft for moderation, and the returned GUID is encoded into the pixels.”

That doesn’t prove that every GUID is publicly resolvable to a named Microsoft account. The privacy risk is conditional: if Microsoft associates the prompt or identifier with the account that submitted it, the GUID could provide a durable handle for identifying the source of an image. The researcher’s point is that Microsoft’s documentation describes the safety and provenance system without clearly explaining that the C2PA manifest contains an identifier connected to users' AI image prompts.

Microsoft did not immediately respond to a request for comment.

The watermark exceeds EU compliance requirements #

Microsoft is among at least 190 AI providers that have agreed to follow Europe’s Code of Practice on Transparency of AI-Generated Content, according to the source report. The code calls for AI-generated or AI-manipulated content to carry machine-readable marking and for associated metadata to indicate whether AI helped create or modify it. It doesn’t prescribe a particular implementation, instead emphasizing effectiveness, interoperability, robustness and reliability.

A simple provenance flag could satisfy the basic disclosure requirement. Microsoft, a founding member of the Coalition for Content Provenance and Authenticity, has gone further by tying the image to a unique server-issued value and the prompt that produced it. That may improve traceability, but it also creates a record that users cannot inspect or remove through the visible-watermark control.

The distinction matters because provenance markers aren’t all equivalent. Google’s SynthID and C2PA markers in Gemini-generated media can remain present even when a visible watermark is hidden, while Anthropic’s Claude watermarking uses statistical word choices rather than a pixel-level identifier. Microsoft’s approach adds an identity-linked element to image provenance, at least in the scenario described by Li.

More companies are using persistent markers #

Microsoft isn’t the only company working on persistent markers. Meta said in July 2026 that it was developing a watermarking system called Content Seal, while OpenAI has applied Google DeepMind’s SynthID and C2PA metadata to its images. The source material does not establish whether those systems encode user-linked identifiers in the same way.

For people who want to avoid a server-issued tracking value in generated images, Li points to open-weight models such as Stable Diffusion and on-device open-source tools. That option changes the trust model because prompt moderation and identifier issuance need not pass through a hosted provider, but it also means the resulting images may not carry the same provenance information. The issue for Microsoft users is not whether Paint and Photos mark AI-assisted images; the analysis indicates that they do. It is whether Microsoft clearly tells users that the invisible marker contains a GUID tied to the prompt—and what Microsoft can recover from that GUID later.

Sophia Reynolds Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @microsoft 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/microsofts-ai-image-…] indexed:0 read:4min 2026-08-25 ·