Why This Matters
This investigation uncovers that Microsoft Paint and Photos embed invisible GUID watermarks into locally generated AI images, linking them to remote moderation servers. This hidden tracking mechanism highlights ongoing concerns about user privacy and data provenance in AI-powered tools, even when processing occurs locally. Understanding these embedded identifiers is crucial for consumers and developers aiming to safeguard digital rights and transparency in AI-generated content.
Key Takeaways
- Paint and Photos embed invisible GUID watermarks into locally generated AI images.
- The GUIDs are linked to remote moderation servers, raising privacy considerations.
- Microsoft adds C2PA metadata to AI images in supported formats for provenance tracking.
Reverse engineering reveals how Paint and Photos embed a server-issued GUID into the pixels of locally generated AI images.
TL;DR
Microsoft Paint supports both local and cloud image generation
Paint and Photos also ship local AI models
The two apps send the prompt to a remote server for moderation
The server returns a GUID along with the moderated prompt
The GUID is embedded into the locally generated image as an invisible watermark
A separate visible-watermark setting does not control this invisible watermark
On Copilot+ PCs, image generation is local but prompt moderation remains remote
Microsoft discloses that Paint adds C2PA metadata to AI-generated images
... continue reading