Brief IA

Paint and Photos: a server identifier in every AI image

🤖 Models & LLM·Tom Levy·

Paint and Photos: a server identifier in every AI image

Paint and Photos: a server identifier in every AI image
Key Takeaways
1A unique 16-byte identifier, issued server-side, is embedded in the pixels (InvisMark) and in a C2PA manifest for each image generated in Paint and Photos.
2Paint transmits the identifier from the previous generation to the next request, explicitly chaining the requests of a session.
3European law requires a simple detectable origin marking, and a code of good practices recommends avoiding sensitive data in metadata; no authority has been contacted, and Microsoft has not explained the purpose.
💡Why it mattersThe practice goes beyond the required "AI flag" set by European rules and touches on data protection, an area where the EU advises caution.
Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

Images generated in Paint and Photos carry a unique identifier assigned by Microsoft servers, hidden within the pixels and recorded in metadata. These identifiers are also transmitted from one request to another, forming a chain throughout a session. European law currently requires detectable marking of synthetic origin, not traceability, and a code of good practices recommends avoiding sensitive data. No authority has been contacted, and Microsoft has not explained the purpose of this number.

The law mandates marking, not nominative traceability

Article 50 of the European AI regulation has been in effect since August 2, 2026. It mandates a machine-readable and detectable marking, focused on the synthetic origin of the content rather than on identifying its creator. A simple indicator that an image comes from an AI meets this requirement, and most current devices adhere to this level.

The European AI Office published a code of good practices on June 10, 2026, recommending that any provenance metadata exclude sensitive information related to privacy. This code is voluntary and carries no penalties at this stage, but it guides practices. An identifier linked to an individual request falls precisely within the area that this document suggests avoiding.

In terms of data protection, the GDPR includes online identifiers in the definition of personal data, and the CNIL highlights indirect identification through cross-referencing. An identifier generated by a server, associated with a request and possibly with an account, meets several criteria of this classification, while remaining a subjective assessment. To date, no authority has been approached, no legal qualification has been established, and there is no indication that Microsoft uses these identifiers to identify users. The technical possibility exists, but its concrete application has not been observed.

Identifiers transmitted from one request to another in Paint

Paint relays the identifier from the previous generation during the next moderation request. This transmission creates an explicit link between successive requests. In practice, images produced during a session are not treated as isolated files but as an ordered sequence tied to the same path.

InvisMark in the pixels and C2PA manifest in the file

The marking system relies on a unique global identifier, consisting of a 16-byte integer that the server assigns upon creation. This identifier is embedded in the pixels using Microsoft InvisMark, remains imperceptible to the naked eye, and has been designed to withstand compression. Concurrently, the file contains a provenance manifest compliant with the open standard C2PA, supported by an alliance including Adobe, Microsoft, Google, OpenAI, and Meta.

This manifest includes a cryptographically signed statement by Microsoft, which explicitly names InvisMark and records the identifier carried in the pixels. Thus, both layers belong to the same system, a point that was not clearly presented in the public documentation. Alongside this mechanism, Microsoft maintains a visible watermark, documented for Microsoft 365 and Bing Image Creator, which the user can see.

A discovery through reverse engineering, Microsoft silent on the purpose

The operation was uncovered through reverse engineering of Paint and Photos conducted by researcher Xusheng Li. According to his analyses, each generated image embeds a unique identifier in the pixels, linked to the original request. Microsoft did not immediately respond to a request from The Register and has, for now, provided no explanation regarding the intended use of this number.

The researcher notes that describing this function as "content identification information" is accurate without making the existence of an identifier explicit to a Windows user. One rationale put forward for such a choice would be the fight against malicious uses, with an identifier per generation facilitating tracing back to the source of problematic content compared to a generic marking. However, in technical discussions, some comments equate any identifier with a surveillance tool, a stance more extreme than what the available facts allow.

Other players push their own invisible markings

The sector does not adopt a common model. Google implemented SynthID starting in 2024 and announces tens of billions of marked contents. Meta unveiled Content Seal, an invisible watermark that is not compatible with two rival standards. OpenAI, for its part, uses SynthID on its images and also adds C2PA metadata. Each company develops its own provenance solution and chooses the data it integrates, content that users often learn about through academic research rather than through official documentation.

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.