Microsoft AI Watermarks in Paint, Photos Link Images to User IDs

3 min readSources: The Register

Study finds Microsoft Paint and Photos embed user-linked watermarks in AI-generated images.

Why it matters: Legal and tech professionals must scrutinize privacy and data protection risks from AI watermarking in popular applications. Understanding these risks is essential for compliance and safeguarding user data.

  • Microsoft Paint and Photos embed an invisible, server-issued Globally Unique Identifier (GUID) as a watermark in AI images.
  • The GUID watermark is linked to the prompt sent to Microsoft for moderation before embedding.
  • Metadata may include AI model details, generating app, and image creation time.
  • Watermarking occurs even for AI content generated locally, raising privacy questions.

A recent study reveals that Microsoft's Paint and Photos applications embed invisible watermarks in AI-generated images.

The watermark is a server-issued Globally Unique Identifier (GUID) linked to the user's prompt, which is sent to Microsoft for moderation. Upon moderation, Microsoft returns the GUID which is then encoded into the image's pixels—even when the image is generated locally on the device.

This mechanism of embedding metadata aligns with Microsoft's documentation stating that AI-generated content watermarks can include details such as the AI model used, the application generating the content, and the time of creation, as outlined here.

Software developer Xusheng Li explained, "Microsoft Paint and Photos embed a server-issued GUID as an invisible watermark in locally generated AI images. Your prompt is sent to Microsoft for moderation, and the returned GUID is encoded into the pixels." This reveals a direct link between the user's identity and the AI-generated image.

While this watermarking strategy supports transparency and AI content authenticity, it also raises critical privacy concerns. The linkage between GUIDs and user identities could expose personal data without clear user consent or opt-out options. Additionally, the exact process Microsoft uses to associate GUIDs with identities remains undisclosed.

Legal professionals and IT teams evaluating AI tools must consider these implications to navigate compliance with data protection laws and safeguard user privacy effectively.

By the numbers:

  • 1 GUID — Invisible server-issued watermark embedded in each AI-generated image in Paint and Photos
  • 3 metadata elements — AI model used, generating application, and time of generation may be included in watermark metadata
  • 0 opt-out details — No clear information on user control over watermark embedding

Yes, but: While watermarking enhances AI-generated content traceability, lack of transparency and user control may undermine privacy protections.

What's next: Regulators and privacy advocates may increase scrutiny of AI watermarking practices; Microsoft could clarify user consent and data management policies soon.