Paint and Photos: a server identifier in every AI image

Le brief IA que les pros lisent chaque soir
Les 7 actus IA du jour, décryptées en 5 min. Gratuit.
Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.
Choisis ton rythme
Gratuit · Pas de spam · Désabonnement en 1 clic
Images generated in Paint and Photos carry a unique identifier assigned by Microsoft servers, hidden within the pixels and recorded in metadata. These identifiers are also transmitted from one request to another, forming a chain throughout a session. European law currently requires detectable marking of synthetic origin, not traceability, and a code of good practices recommends avoiding sensitive data. No authority has been contacted, and Microsoft has not explained the purpose of this number.
The law mandates marking, not nominative traceability
Article 50 of the European AI regulation has been in effect since August 2, 2026. It mandates a machine-readable and detectable marking, focused on the synthetic origin of the content rather than on identifying its creator. A simple indicator that an image comes from an AI meets this requirement, and most current devices adhere to this level.
The European AI Office published a code of good practices on June 10, 2026, recommending that any provenance metadata exclude sensitive information related to privacy. This code is voluntary and carries no penalties at this stage, but it guides practices. An identifier linked to an individual request falls precisely within the area that this document suggests avoiding.
In terms of data protection, the GDPR includes online identifiers in the definition of personal data, and the CNIL highlights indirect identification through cross-referencing. An identifier generated by a server, associated with a request and possibly with an account, meets several criteria of this classification, while remaining a subjective assessment. To date, no authority has been approached, no legal qualification has been established, and there is no indication that Microsoft uses these identifiers to identify users. The technical possibility exists, but its concrete application has not been observed.
Identifiers transmitted from one request to another in Paint
Paint relays the identifier from the previous generation during the next moderation request. This transmission creates an explicit link between successive requests. In practice, images produced during a session are not treated as isolated files but as an ordered sequence tied to the same path.
InvisMark in the pixels and C2PA manifest in the file
The marking system relies on a unique global identifier, consisting of a 16-byte integer that the server assigns upon creation. This identifier is embedded in the pixels using Microsoft InvisMark, remains imperceptible to the naked eye, and has been designed to withstand compression. Concurrently, the file contains a provenance manifest compliant with the open standard C2PA, supported by an alliance including Adobe, Microsoft, Google, OpenAI, and Meta.
This manifest includes a cryptographically signed statement by Microsoft, which explicitly names InvisMark and records the identifier carried in the pixels. Thus, both layers belong to the same system, a point that was not clearly presented in the public documentation. Alongside this mechanism, Microsoft maintains a visible watermark, documented for Microsoft 365 and Bing Image Creator, which the user can see.
A discovery through reverse engineering, Microsoft silent on the purpose
The operation was uncovered through reverse engineering of Paint and Photos conducted by researcher Xusheng Li. According to his analyses, each generated image embeds a unique identifier in the pixels, linked to the original request. Microsoft did not immediately respond to a request from The Register and has, for now, provided no explanation regarding the intended use of this number.
The researcher notes that describing this function as "content identification information" is accurate without making the existence of an identifier explicit to a Windows user. One rationale put forward for such a choice would be the fight against malicious uses, with an identifier per generation facilitating tracing back to the source of problematic content compared to a generic marking. However, in technical discussions, some comments equate any identifier with a surveillance tool, a stance more extreme than what the available facts allow.
Other players push their own invisible markings
The sector does not adopt a common model. Google implemented SynthID starting in 2024 and announces tens of billions of marked contents. Meta unveiled Content Seal, an invisible watermark that is not compatible with two rival standards. OpenAI, for its part, uses SynthID on its images and also adds C2PA metadata. Each company develops its own provenance solution and chooses the data it integrates, content that users often learn about through academic research rather than through official documentation.
Brief IA — L'actualité IA en français
L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.