Microsoft's AI images may secretly carry your user ID
Your AI image may not be as anonymous as it looks. Microsoft tools could embed invisible identifiers linked to prompt activity. Here's all that you need to know!
Your AI image may be saying more than it shows. AI-generated images are becoming easier to create, but a new finding suggests some may also carry information that users cannot see.
Researcher Xusheng Li found that images generated or edited using AI in Microsoft Paint and Photos can include invisible watermarks containing unique identifiers. This raises concerns that the hidden identifiers could potentially link an image to the activity that created it.
How Microsoft’s hidden watermark works
According to Li’s analysis, Microsoft Paint and Photos send an AI image prompt to Microsoft’s servers for moderation. The server then returns a unique identifier, known as a GUID, along with prompt-related data.
A GUID is a long, machine-readable code used to distinguish one item from another.
Xusheng says the GUID is then embedded into the image’s pixels as an invisible watermark. This is different from a visible Copilot logo-style watermark that users may see or control through settings. Avoiding a visible watermark, therefore, does not necessarily mean an image contains no hidden provenance information.
Why the identifier raises privacy questions
AI watermarking itself is not unusual. Technology companies and standards bodies are developing ways to identify synthetic media and show how digital content was created. Microsoft is also a supporter of C2PA, a content provenance standard for attaching information about digital media.
The issue starts with what happens when an identifier can be linked to the process that generated an image.
Li says that if Microsoft stores a relationship between a user account, a prompt and the GUID embedded in an image, the company could theoretically connect that image to the user or session that created it.
He also found that Paint may send a previous prompt-generation ID with a later moderation request, potentially allowing successive image requests to be linked.
That could help with safety and abuse prevention, but it raises questions about how much users know about what happens behind the scenes.
What users should know
AI images created through hosted or partially connected tools may contain hidden signals that are not visible when the file is opened normally.
Saving or sharing an image could preserve some of this information, depending on the file format and how another platform handles it. This does not mean Microsoft is misusing the data. Watermarks can help identify AI-generated content, prevent impersonation and improve accountability.
However, users may reasonably want to know what information is embedded, whether it can be linked back to them, how long related records are retained and whether they can opt out.
The AI transparency dilemma
Such cases show a growing tension around AI transparency. Provenance systems can make synthetic media easier to identify and trace, but they can also create privacy concerns when identifiers are connected to individuals.
As AI image tools become part of everyday software, companies will need to balance the benefits of traceability with clearer disclosure about what happens to the data behind every generated image.


