Microsoft Paint may embed a hidden identifier into AI-generated images, even when a Copilot+ Windows PC creates the image locally. Researcher Xusheng Li says the identifier could allow Microsoft to connect an image to records related to an account, device, IP address or prompt.

The Microsoft AI image watermark is not visible to users. It also appears to remain in the image even when users disable Paint’s visible Copilot watermark.

Li has not shown that Microsoft uses the identifier to track individual users. However, he argues that Microsoft does not clearly disclose how the hidden stamp works or what information the company may connect to it.

Paint checks prompts before local generation

Li, a software developer at reverse-engineering firm Vector 35, examined how Microsoft Paint handles AI image generation.

His research indicates that Paint sends a user’s prompt to Microsoft for a safety review before the device generates the image. The company then returns a unique watermark ID, which Paint inserts into the image pixels.

The process reportedly takes place even when the device handles image generation locally on a Copilot+ PC.

The identifier uses a GUID, or Globally Unique Identifier. It does not directly include a name, but Microsoft could potentially associate it with records that identify the source of an AI generation.

Hidden ID remains when the visible logo is disabled

Paint offers a visible Copilot logo on AI-generated images and lets users turn it off. Li found that disabling the logo does not remove the hidden identifier.

He discovered the watermark while reviewing a 1.67 MB file connected to the visible watermark function. The file appeared unusually large for a simple on-screen logo, prompting further analysis.

Li identified a 16-byte GUID payload that Paint appears to embed within the generated image. He says Paint may refuse to return an image if it cannot add the invisible watermark successfully.

Microsoft Photos includes similar technology, although Li found that Photos may continue processing if the watermarking step fails.

C2PA disclosure leaves questions

Microsoft has said that Paint uses the Coalition for Content Provenance and Authenticity, or C2PA, standard to help establish an image’s origin and support content verification.

However, Li says he found no clear disclosure explaining the server-issued GUID, its connection to prompt moderation or its presence in image pixels. Those details raise privacy questions because the value could potentially link a widely shared image to internal Microsoft records.

The Microsoft AI image watermark does not appear to work like Windows’ Global Device Identifier, which can persistently identify a device. Instead, Li’s findings suggest the Paint identifier relates to a specific AI image generation.

Still, both systems illustrate the same privacy concern: a random identifier can become personally meaningful when a company holds the records that link it to an individual.

AI watermarking expands across platforms

Microsoft is not the only company exploring provenance tools for AI-generated content. Technology companies increasingly use visible labels, metadata and machine-readable watermarking to identify synthetic images and other media.

These measures can support authenticity checks and copyright-related verification. At the same time, developers and users need clear information about what identifiers are embedded, whether they survive edits or sharing, and what data companies can associate with them.


0 responses to “Microsoft AI Image Watermark May Identify Copilot+ Users”