ai and ml
Freeeedom! Copyright (c) 2026 New Africa/Shutterstock. No use without permission.
Privacy? Not if you use hosted AI services
When Anthropic disclosed earlier this month that it would be applying a statistical word-choice watermark to its Claude text output, the company noted that at least 190 AI providers have agreed to abide by Europe's AI transparency rules.
One such company is Microsoft, which has been applying its own form of watermarking to images created with the assistance of AI in its Paint and Photos applications for Windows.
The EU's Code of Practice on Transparency of AI-generated Content requires that signatories mark content created with the help of AI in a machine-readable format and that associated metadata indicates at least whether content has been manipulated by AI, or entirely created by it.
The regulation creates an obligation but does not specify the method of compliance, so signatories can employ whatever technology best achieves the goals [PDF] of "effectiveness, interoperability, robustness, and reliability."
Microsoft has gone beyond minimum requirements in an effort to address AI safety concerns. The EU rules encourage, but do not demand, the inclusion of metadata that does more than answer whether creators used AI to produce content. Redmond, as one of the founders of the Coalition for Content Provenance and Authenticity (C2PA), has chosen to embed AI-assisted images in Paint and Photos with a globally unique identifier (GUID) linked to the prompt that created the image.
Xusheng Li, a software developer at Vector 35, recently published an analysis of Microsoft's approach, which the Windows biz previously disclosed in the Paint and Photos documentation but did not detail.
"Microsoft Paint and Photos embed a server-issued GUID as an invisible watermark in locally generated AI images," Li explained in a LinkedIn post. "Your prompt is sent to Microsoft for moderation, and the returned GUID is encoded into the pixels."
Li notes that the invisible GUID watermark – a 16-byte integer – is distinct from the visible watermark option that Microsoft provides to users of its Paint software and Microsoft 365 AI features.
If Microsoft associates each prompt with the user who sent it, then the company could in theory identify users by referring to the watermark in an image. Long ago, manufacturers of laser printers implemented this sort of tracking and the practice alarmed privacy advocates when it came to light.
"Microsoft receives and moderates the prompt, then issues the unique GUID that Paint embeds into the locally generated image," Li said. "Paint also sends the previous promptGenerationId as lastPromptGenerationId with its next moderation request, allowing successive requests to be linked explicitly."
Li argues that while Microsoft has disclosed its AI safety measures, it hasn't sufficiently clarified that its C2PA manifest contains a GUID linked to users' AI image prompts.
Microsoft did not immediately respond to a request for comment.
Other companies are thinking along similar lines. Meta last month said it is working on its own watermarking technology called Content Seal. And OpenAI has been applying Google DeepMind's SynthID and C2PA metadata to its images.
Those seeking to avoid having a tracking number embedded in their AI-generated images may want to explore running an open weight model like Stable Diffusion and running on-device open-source tools. ®

5 hours ago
11








English (US) ·