// AI NEWS · PLATFORM

Microsoft Paint and Photos Quietly Embed Invisible GUID Watermarks in AI Images — Even Ones Generated Locally

Reverse-engineering research published August 20, 2026 found that Paint's Cocreator and the Windows Photos app hide a server-issued identifier inside the pixels of every AI image they make, and that the "local" generation path still phones home to Microsoft to get that identifier.

2026-08-24 · by Moe Ameen

What happened

A reverse-engineering write-up published on August 20, 2026 by researcher Xusheng Li documented behavior Microsoft had not made obvious to Windows users: the Paint app's Cocreator feature and the Windows Photos app (Image Creator / Restyle Image) embed an invisible, pixel-level watermark into every AI image they generate. The payload is a server-issued GUID — a 16-byte identifier — expanded into roughly 144 bits and written across the image using a content-adaptive, block-domain embedding method Microsoft calls InvisMark. It is imperceptible to a viewer but recoverable by a matching detector, and the same GUID is recorded in a signed C2PA (Content Credentials) provenance manifest attached to the file.

The detail that drew the most attention is where the identifier comes from. Even when image generation runs on-device — for example, on a Copilot+ PC's NPU — the prompt is still sent to a Microsoft moderation endpoint, and that server returns both a revised prompt and the watermark GUID that gets baked into the finished picture. In other words, "local" generation is not offline: the completed image goes through online provenance signing, and the embedded ID is minted by Microsoft's servers rather than generated on your machine. The analysis found a large share of pixels altered to carry the mark in a test image, consistent with a watermark designed to persist rather than a fragile tag.

This is separate from the opt-in visible watermark Microsoft added to Paint and Photos in 2026, which is off by default and lets you choose "Never," "Always," or a prompt each time you save. The invisible GUID watermark and the C2PA manifest are applied to AI generations regardless of that visible-mark setting. Microsoft has attached C2PA provenance metadata to its AI image output since 2023; what the new research surfaces is the invisible in-pixel GUID and the fact that it traces back to a Microsoft-issued identifier tied to the generation request.

The move fits a broader regulatory push. The EU AI Act's Article 50 transparency rules took effect on August 2, 2026 and press providers of generative AI to make synthetic output carry a detectable, machine-readable mark — the same driver behind Anthropic watermarking Claude's output and Google's SynthID across Gemini media. Microsoft has not published detailed public documentation of the invisible-watermark behavior in Paint, so treat implementation specifics as findings from independent reverse engineering rather than an official spec.

Why it matters for creators

  • Provenance is now baked into consumer tools, not just pro suites. A free Windows app writes an invisible, traceable ID into AI images — "no one will know it's AI" is no longer a safe assumption for anything made in Paint or Photos.
  • The identifier is server-issued and tied to your request. Because the GUID is minted by Microsoft and linked to the prompt, an image can in principle be traced back to the generation that made it — a privacy consideration for anyone generating quietly.
  • "Local" did not mean offline. The prompt leaves your machine for moderation and provenance signing even on on-device generation, which matters if you assumed a Copilot+ PC kept your prompts private.
  • The invisible mark ignores the visible-watermark toggle. Turning the visible Copilot watermark to "Never" does not stop the hidden GUID or the C2PA manifest from being embedded.
  • This is the direction of travel everywhere. With the EU AI Act live and Anthropic, Google, and Suno all marking output, invisible provenance is becoming standard — build your workflow around clean disclosure, not around avoiding a mark.

How to act on this with Kompozy

The practical read for image-first creators: provenance now rides along with almost anything an AI tool makes, so the edge is not a watermark-free image — it is a distinctive, on-brand, actually-published one. That is the gap [Kompozy](/) closes. Where Paint makes a single loose image you then have to place, size, and post by hand, Kompozy generates images through OpenAI's gpt-image and Google Gemini and composites them into brand-exact [Carousel Posts](/glossary/output-buckets), quote cards, and [Persona Photos](/glossary/persona-shorts) via [HyperFrames](/glossary/hyperframes) — then fans that one source into a blog, a newsletter, captioned video, and native posts across the eight social platforms plus blog and email, behind a per-post review gate where a consistent AI-disclosure line goes in once and rides every asset.

One honest, useful specific, because provenance is the whole story here: if you drop a Paint- or Photos-generated image into Kompozy as a source asset, Microsoft's invisible GUID and C2PA manifest travel with that file — Kompozy does not strip or launder it, and you should not expect it to. Kompozy's own generated images come from gpt-image and Gemini, not Paint, so they carry those providers' provenance rather than Microsoft's. The point is not to dodge any mark; it is to run a disclosed pipeline where you know exactly which tool touched which asset, and where the output is finished and scheduled instead of a lone PNG in a downloads folder.

Quick takeaways

  • Published August 20, 2026, reverse-engineering research found Paint (Cocreator) and Photos embed an invisible, server-issued GUID watermark plus a signed C2PA manifest in AI images they generate.
  • The watermark uses Microsoft's InvisMark method — a 16-byte GUID spread across the image as ~144 bits — and the GUID is recorded in a C2PA soft-binding assertion.
  • Even on-device generation sends the prompt to a Microsoft moderation server, which returns the GUID; "local" is not offline.
  • This is distinct from the opt-in visible watermark added in 2026 (off by default). The invisible GUID and C2PA data are applied regardless of that setting.
  • The context is the EU AI Act's Article 50 transparency rules, effective August 2, 2026, alongside similar moves from Anthropic, Google, and Suno.

Frequently asked questions

Does Microsoft Paint really watermark AI images invisibly?

According to reverse-engineering research published August 20, 2026, yes. Paint's Cocreator and the Windows Photos app embed an invisible, pixel-level watermark carrying a server-issued GUID, and record that GUID in a signed C2PA provenance manifest attached to the file. It is separate from the opt-in visible watermark, and applies whether or not the visible mark is turned on.

Is the image generated locally or on Microsoft's servers?

The image can be generated on-device — for example on a Copilot+ PC's NPU — but the prompt is still sent to a Microsoft moderation endpoint that returns a revised prompt and the watermark GUID. So the finished picture goes through online provenance signing and the identifier is issued by Microsoft, meaning "local" generation is not fully offline.

Can I turn the invisible watermark off?

The reported behavior is that the invisible GUID and C2PA manifest are applied to AI generations regardless of the visible-watermark setting, which has options for "Never," "Always," or a prompt each time. Microsoft has not published detailed public documentation of the invisible mark, so there is no confirmed user toggle for it. Assume anything you generate in Paint or Photos carries provenance.

Why is Microsoft doing this?

It fits the industry-wide move to label synthetic media, driven in large part by the EU AI Act's Article 50 transparency rules that took effect on August 2, 2026 and require AI-generated content to carry a detectable, machine-readable mark. Anthropic, Google, and Suno have made comparable moves for text, image, and audio.

Related news

← All AI news · Get started →