Technology
Hacker News

MS Paint and Photos inivisibly watermark even locally generated output with GUID

Source Entity

Hacker News

August 24, 2026
MS Paint and Photos inivisibly watermark even locally generated output with GUID

Microsoft has implemented invisible GUID watermarking for AI-generated images in Paint and Photos. Even when generation occurs locally on Copilot+ PCs, the system relies on remote servers for prompt moderation and metadata injection.

The Mechanics of Microsoft's Invisible Watermarking

Recent technical analysis has uncovered a sophisticated tracking mechanism integrated into Microsoft Paint and Photos. When users generate images using the integrated AI capabilities, the software embeds a Globally Unique Identifier (GUID) directly into the pixel data of the output. This process occurs even when the image generation is performed locally on the hardware, highlighting a complex interplay between local processing and cloud-based oversight.

The Role of Remote Moderation

While Copilot+ PCs allow for local AI image generation, the system maintains a persistent connection to Microsoft’s servers for prompt moderation. When a user inputs a prompt, it is transmitted to a remote server for validation. The server then returns a GUID alongside the moderated prompt, which is subsequently encoded into the image file. This architecture ensures that even locally created content is tethered to a centralized moderation system, effectively creating a digital trail for AI-generated assets.

Transparency and C2PA Standards

Microsoft has publicly disclosed that these applications utilize C2PA (Coalition for Content Provenance and Authenticity) metadata to label AI-generated images. This is a critical move toward establishing industry standards for content provenance. By embedding this metadata into formats such as PNG, JPEG, GIF, and the proprietary .paint format, Microsoft aims to provide a reliable way for platforms and users to identify AI-altered or generated media, thereby curbing the spread of misinformation.

Privacy and User Control Implications

A significant finding from the reverse engineering of these apps is that the invisible GUID watermark functions independently of the visible-watermark settings available to users. This means that users cannot opt out of the invisible tracking, even if they disable visible labels. This design choice underscores Microsoft's commitment to maintaining a persistent audit trail for AI content, though it raises questions regarding user autonomy and transparency in how local data is handled.

Broader Industry Trends

This implementation reflects a broader trend among major tech companies to bake digital provenance into the foundational layers of their software. As generative AI becomes ubiquitous, the industry is moving toward 'content credentials' to distinguish human-made from machine-made content. Microsoft's approach—combining remote moderation with local pixel-level watermarking—serves as a blueprint for how future operating systems may manage the provenance of synthetic media at scale.

Conclusion

The integration of invisible GUID watermarking in Microsoft Paint and Photos represents a significant step in the governance of synthetic media. While the reliance on remote servers for prompt moderation may challenge the definition of 'local' processing, it provides a necessary mechanism for content tracking. As the digital landscape continues to grapple with the proliferation of AI-generated content, such technical safeguards will likely become standard features across all creative software suites.

Verification Required?

Read the full report from the primary source

Go to Hacker News