Analysis
Researcher Xusheng Li found that Microsoft Paint and Photos embed a server-issued GUID as an invisible pixel-level watermark in AI images generated locally within the apps, The Register reported. According to the research, a user's prompt is sent to Microsoft for content moderation even when the image generation itself happens locally, and the GUID Microsoft's server returns as part of that moderation check gets encoded directly into the pixels of the resulting image.
Microsoft does disclose the existence of C2PA metadata -- an industry-standard content-provenance format -- attached to AI-generated images. What Li's research says was not disclosed is the separate, deeper pixel-level watermark: a c2pa.soft-binding assertion names 'Microsoft InvisMark' and records the same identifier carried in the invisible pixel watermark, meaning the file-level metadata and the pixel-level watermark are two layers of the same underlying provenance system, one visible in the file properties and one invisible and much harder for an end user to detect or strip.
The distinction matters because file-level metadata can be stripped by re-saving or re-compressing an image, while a pixel-embedded watermark is designed to survive exactly that kind of manipulation -- which is the entire point of the technique from a provenance-tracking standpoint, but also means a user has functionally no way to know or control that an identifier tied to their account is embedded in an image they believed was generated and processed locally.
โMicrosoft does disclose the existence of C2PA metadata -- an industry-standard content-provenance format -- attached to AI-generated images.โ
- Microsoft -- operator of the InvisMark watermarking system embedded in Paint and Photos
- Xusheng Li -- the independent researcher who documented and reverse-engineered the watermarking behavior
- EU regulators -- enforcing Article 50 of the AI Act, whose transparency requirements took effect August 2, 2026, shortly before this research was published
The timing is what elevates this from a technical curiosity to a live compliance question. Article 50 requires disclosure of AI-generated content and, depending on interpretation, meaningful transparency around how that content is tracked and identified. A watermarking system that ties generated images back to an individual user's account, without disclosure of that specific linkage beyond a general C2PA reference, is precisely the kind of gap between technical disclosure and genuine user understanding that new EU transparency rules were designed to close.
The counterweight is that watermarking AI-generated content for provenance and misuse-detection purposes is a legitimate and increasingly expected practice across the industry -- OpenAI, Google and others embed similar provenance signals in their own generated images, and there is a reasonable argument that user-account linkage helps trace abuse (like generating harmful content) back to a responsible party. The core issue is disclosure specificity, not the practice of watermarking itself.
Article 50's enforcement window opened three weeks ago, and EU regulators have 90 days from a documented complaint to open a formal inquiry -- Li's public writeup starts that clock, which means the first real test of how this rule gets enforced could land before Thanksgiving.