Microsoft AI watermarks in Paint and Photos are linked to user IDs, researcher finds

← Back to the feed

Microsoft AI watermarks in Paint and Photos are linked to user IDs, researcher finds

The Register · 6 hours ago

Microsoft has been embedding a hidden, server-issued unique identifier into images generated with AI assistance in its Paint and Photos apps for Windows, according to research by Vector 35 developer Xusheng Li. This goes beyond the requirements of the EU's Code of Practice on Transparency of AI-generated Content, which mandates machine-readable disclosure of AI-generated content but does not specify that identifiers be traceable back to individual users or prompts, raising fresh privacy concerns about how far tech firms are going in the name of compliance and AI safety.

Li found that Paint and Photos send user prompts to Microsoft for moderation, and the returned 16-byte GUID is invisibly encoded into the pixels of the resulting image, distinct from the optional visible watermark Microsoft also offers. Because successive requests reference the prior identifier, Microsoft could theoretically link a chain of prompts and images back to a specific user, echoing older controversies over hidden tracking codes in laser-printed documents. Microsoft, a C2PA founding member, had disclosed the practice in documentation but not detailed it, and did not respond to a request for comment; other firms including Meta (Content Seal) and OpenAI (using Google DeepMind's SynthID) are pursuing similar watermarking schemes, with open-source, on-device tools like Stable Diffusion offered as an alternative for those wanting to avoid embedded tracking.

  • Microsoft Paint/Photos embed hidden GUIDs linking AI images to user prompts
  • Goes beyond EU transparency rules; raises privacy tracking concerns
  • Similar watermarking planned or used by Meta and OpenAI

New here? Start with this

Microsoft's Paint and Photos apps for Windows let users create or edit images with built-in AI tools. A researcher has found that these apps quietly embed a hidden, unique code into AI-generated images, separate from the visible "AI-made" watermark some users may already know about. This hidden code is issued by Microsoft's servers and, according to the research, could potentially be traced back to the specific user who made the request.

The wider context is a set of rules from the European Union requiring tech companies to clearly mark content that has been generated or altered by AI, so people can tell what is real and what is not. Microsoft is a member of a coalition of companies working on standards for this kind of labelling, alongside firms like Meta and OpenAI, which are developing similar watermarking systems of their own. The concern raised here is that identifying content as AI-made is one thing, but linking that content to an individual's identity goes further than what the rules ask for.

This matters because it touches on how much personal data is collected when people use everyday creative tools, often without their knowledge. It also raises broader questions about the balance between making AI content traceable for safety and transparency reasons, and protecting the privacy of the people who use these tools.

Both sides, in good faith

The strongest fair case each way — we don't pick a winner.

The case for

Advocates of embedding traceable identifiers argue that as AI image generation becomes trivial to misuse for disinformation, fraud, non-consensual imagery and child safety violations, platforms have a responsibility to build in mechanisms that let bad actors be traced and held accountable. They point out that visible watermarks alone are easily cropped or edited out, so a resilient, server-linked identifier is a necessary backstop for content authenticity efforts like C2PA, and that moderation logging of prompts is standard practice to prevent harmful generations in the first place, with the added traceability a reasonable trade-off for a safer, more trustworthy AI ecosystem.

The case against

Privacy-minded critics argue that quietly linking every AI-assisted image a person creates to a persistent, chainable identifier goes well beyond what transparency rules require and beyond what users could reasonably expect, since disclosing that an image is AI-generated does not require knowing who made it. They contend that undocumented, invisible tracking embedded in ordinary creative tools like Paint sets a troubling precedent for surveillance by default, echoing past controversies over hidden printer tracking codes, and that users deserve clear, upfront disclosure and meaningful choice rather than discovering the practice only through independent security research.

AI Technology

Read the full article at the source →