Illustration for: Microsoft's AI Watermarks in Paint, Photos Tied to User IDs

Microsoft's AI Watermarks in Paint, Photos Tied to User IDs

A security researcher found Microsoft Paint and Photos embed an invisible, server-issued watermark tied to a user's account into locally generated AI images.

By the Numbers

Xusheng Li
Researcher
invisible pixel GUID
Watermark type
Microsoft InvisMark
Named system
AI Act Art. 50 (Aug 2, 2026)
Related EU rule
TC
By the Markets Desk
Edited by Trace Cohen · Early-stage VC & angel · Founder, New York Venture Partners
2 min read
ShareXLinkedInEmail

THE RUNDOWN

1

A researcher found that Microsoft Paint and Photos embed an invisible, server-issued watermark GUID linked to a user's account into locally generated AI images, [The Register reported](https://www.theregister.com/ai-and-ml/2026/08/25/microsoft-ai-watermarks-in-paint-and-photos-are-linked-to-user-ids-researcher-finds/5292034)

2

The mechanism sends a user's prompt to Microsoft for moderation and returns a GUID that gets encoded directly into the image's pixels, a layer of provenance tracking beyond the C2PA metadata Microsoft does disclose

3

The finding lands three weeks after the EU AI Act's Article 50 transparency rules took effect, requiring disclosure of AI-generated content and its provenance

4

The gap between disclosed provenance metadata and an undisclosed, individually identifying pixel watermark is exactly the kind of distinction regulators enforcing new AI transparency rules are likely to focus on

TC

The VC Read · Trace's Take

Trace Cohen

Any startup embedding provenance or watermarking into AI-generated content should get ahead of this now: write down exactly what's embedded, whether it's user-identifying, and disclose it in plain language before a researcher finds it for you. The gap between 'we disclose C2PA metadata' and 'we embed a user-linked GUID in the pixels' is the kind of distinction that turns a routine feature into a regulatory incident once Article 50 enforcement actually starts picking targets.

Analysis

Researcher Xusheng Li found that Microsoft Paint and Photos embed a server-issued GUID as an invisible pixel-level watermark in AI images generated locally within the apps, The Register reported. According to the research, a user's prompt is sent to Microsoft for content moderation even when the image generation itself happens locally, and the GUID Microsoft's server returns as part of that moderation check gets encoded directly into the pixels of the resulting image.

Microsoft does disclose the existence of C2PA metadata -- an industry-standard content-provenance format -- attached to AI-generated images. What Li's research says was not disclosed is the separate, deeper pixel-level watermark: a c2pa.soft-binding assertion names 'Microsoft InvisMark' and records the same identifier carried in the invisible pixel watermark, meaning the file-level metadata and the pixel-level watermark are two layers of the same underlying provenance system, one visible in the file properties and one invisible and much harder for an end user to detect or strip.

The distinction matters because file-level metadata can be stripped by re-saving or re-compressing an image, while a pixel-embedded watermark is designed to survive exactly that kind of manipulation -- which is the entire point of the technique from a provenance-tracking standpoint, but also means a user has functionally no way to know or control that an identifier tied to their account is embedded in an image they believed was generated and processed locally.

Microsoft does disclose the existence of C2PA metadata -- an industry-standard content-provenance format -- attached to AI-generated images.

  • Microsoft -- operator of the InvisMark watermarking system embedded in Paint and Photos
  • Xusheng Li -- the independent researcher who documented and reverse-engineered the watermarking behavior
  • EU regulators -- enforcing Article 50 of the AI Act, whose transparency requirements took effect August 2, 2026, shortly before this research was published

The timing is what elevates this from a technical curiosity to a live compliance question. Article 50 requires disclosure of AI-generated content and, depending on interpretation, meaningful transparency around how that content is tracked and identified. A watermarking system that ties generated images back to an individual user's account, without disclosure of that specific linkage beyond a general C2PA reference, is precisely the kind of gap between technical disclosure and genuine user understanding that new EU transparency rules were designed to close.

The counterweight is that watermarking AI-generated content for provenance and misuse-detection purposes is a legitimate and increasingly expected practice across the industry -- OpenAI, Google and others embed similar provenance signals in their own generated images, and there is a reasonable argument that user-account linkage helps trace abuse (like generating harmful content) back to a responsible party. The core issue is disclosure specificity, not the practice of watermarking itself.

What to watch is whether Microsoft updates its disclosure language to explicitly describe the user-ID linkage, and whether EU regulators treat this as a live Article 50 test case now that the rule has been in effect for three weeks.

ShareXLinkedInEmail

Key Sources

2 sources

THE WIRE in your inbox— Tech, startup & VC news with Trace's take. Free, no spam.