A developer reverse engineered invisible GUID watermarks embedded in AI-generated images made with Microsoft Paint and Photos, according to Tom's Hardware. The discovery shows Microsoft is quietly tagging synthetic images inside its own apps. Anyone using AI tools to create images should know their output may carry hidden tracking data.
What actually happened
Tom's Hardware reported that a developer found previously unknown GUID watermarking functionality inside Microsoft Paint and Photos. A GUID, or globally unique identifier, is a code string used to label digital files. The report does not name the developer or state when the functionality was added. It does not specify which Windows versions or app builds include the watermark, or whether it applies to every AI-generated image the apps produce. Microsoft has not issued a public statement addressing the finding, based on available reporting. The exact data stored inside the GUID, and how it is read or verified, remains undisclosed in the source material.
How we got here
Invisible watermarking has become a common tool for tracking AI-generated content, as image generators spread across mainstream software. Microsoft has built AI image tools directly into consumer apps, making Paint and Photos a natural place to embed provenance data. The source material does not detail when Microsoft added this watermarking or whether it was disclosed anywhere before this discovery. It also does not say whether the GUID method resembles other watermarking standards used elsewhere in the industry. What is clear from Tom's Hardware is that the functionality existed without public documentation until a developer found it independently.
Why this matters for you
For users, this means images created with Paint or Photos AI tools may already carry hidden identifiers, whether or not they realize it. For builders working on AI content verification or provenance tools, watermark detection inside mainstream apps adds a new data point to track. For the broader Web3 and digital identity space, this shows large platforms are moving toward embedded content authentication without waiting for open standards. Anyone sharing AI-generated images from these apps should consider that metadata or hidden markers could reveal their origin, even after edits or format changes, depending on how the watermark survives processing.
The bigger question
If invisible watermarks can identify AI-generated images without user knowledge, who should control that hidden data: the platform that embeds it, the user who creates the image, or an independent standard? The answer could shape how trust in digital images works for years. As more everyday software adds silent tracking to creative output, the question of consent and disclosure becomes harder to avoid, especially as AI-generated content spreads across messaging, social platforms, and the wearable devices people use to capture and share images.
What to watch
No official Microsoft response or documentation update has been reported yet. Watch for whether Microsoft confirms, explains, or expands this watermarking across other apps. Further reverse engineering work from the developer community could reveal more about how the GUID data is structured. As AR and smart glasses push more AI-generated visuals into daily use, invisible provenance tools like this one may become standard well beyond desktop apps.



