A reverse-engineering write-up shows Microsoft Paint and Photos stamp AI images with an invisible, server-issued GUID watermark, even when the image itself is rendered entirely on-device, because the prompt still travels to a Microsoft moderation server first.

Read the full story: Microsoft Paint Secretly Watermarks Even Local AI Images →

Transcript

Microsoft Paint can generate AI images locally, right on a Copilot plus PC's own chip. But a new reverse engineering report shows that render still isn't fully private. Before anything gets drawn, your prompt travels to a Microsoft server for moderation. That server sends back an ID, and Paint's watermark tool hides that ID across nearly three quarters of the image's pixels, invisible to the eye. The same ID also gets written into the file's visible metadata, linking the two together. Microsoft's own support pages mention content filtering and image labeling, but never say the identifier is tied to your specific prompt. Nothing here is illegal. But local doesn't mean private, and this research proves it.