Microsoft AI watermarks in Paint and Photos are linked to user IDs, researcher finds

Privacy? Not if you use hosted AI services

By The Register

Microsoft’s Paint and Photos apps are being used to embed an invisible watermark in locally generated AI images, and a researcher says that watermark can be tied to a user’s identity in some cases.

The Register reports that Microsoft sends prompts to its servers for moderation, then returns a globally unique identifier that is encoded into the image pixels. According to the report, researcher Kai‑Chen Li said the watermark is a server-issued GUID and that successive requests can be linked because Paint also sends the previous promptGenerationId with later moderation requests.

The article says the invisible watermark is separate from Microsoft’s visible watermark option in Paint and Microsoft 365 AI features. It also says Microsoft is one of the founders of the Coalition for Content Provenance and Authenticity, which is why the finding has raised privacy concerns.

Li was quoted in a LinkedIn post saying Microsoft Paint and Photos embed a server-issued GUID as an invisible watermark in locally generated AI images. The Register says that, if Microsoft associates each prompt with the user who sent it, the company could theoretically identify users by referring to the watermark in an image.

No police, council, residents or customers are mentioned in the report.

Open article on Cheshire Today