Microsoft Paint Is Signing Your Pixels
Paint is the most local-looking app on Windows. You draw a line, fill a color, hit save, and the file feels like yours. If Microsoft can later read a tracking ID out of those pixels, that feeling is the product, not the reality.
The ID is in the pixels, not the filename
This is not a filename trick. It is not a tag in the Properties pane. A GUID is being written into the pixel values of the saved image. A GUID is a 128-bit identifier designed not to collide. Open the doodle and it still looks like yesterday’s scribble.
Paint is not the only path. Photos can apply edits and write the file back, so the blast radius is not “AI art from a generator.” It is “a picture Windows saved.” After Copilot+ PCs became the sales pitch, both apps grew generate-and-edit features that sit there like defaults.
The ID is not decoration. If the same value shows up across files, separately uploaded images can be tied to one source. Public docs do not cleanly say whether that source is an account, a device, or a session. It is still a key. Whoever holds the extractor can match it later.
“On-device” does not mean unsigned
The on-device AI pitch is short. Data stays on the machine. Nothing goes to the cloud. Therefore it is safer.
A pixel watermark does not argue with that sentence. It walks around it. The original never has to leave the PC. The model can finish on an NPU. The app still signs the output. The moment that image hits the open web, the ID can be read again. Local creation and later attribution are not opposites. They travel together.
Microsoft is not inventing this pressure from nowhere. Deepfakes, election content, and ad fraud have made provenance a policy problem in Washington and Brussels. The EU’s AI Act wants people to know when they are looking at synthetic media. C2PA tries to do that in the open. Metadata is easy to strip, which is why hiding a signal in the pixels is more tempting.
The consent language users actually see is closer to “this runs on your device.” It is not “we will write a birth record into your doodle.” Skipping an upload is not the same as leaving the output unnamed.
Stripping EXIF does not touch this
EXIF and XMP are fragile. Open the file in a viewer, convert the format, run a metadata cleaner, and most of it is gone. Social networks often strip it on upload. That is why “delete properties, stay anonymous” became a habit.
Pixel watermarks are built for that habit. The signal lives in tiny color patterns the eye cannot pick out. Re-saving as JPEG or nudging the resolution is not a clean wipe. The design goal is persistence, not immortality. It can still be damaged. It is just a different class of problem from deleting tags.
That is why Paint matters more than a Midjourney download. People already distrust images from a generator. Nobody inspects a Paint sketch. The lower the suspicion, the farther the signature travels.
Over the last month this has not blown up on Hacker News or Reddit. There is no giant thread, no pile-on, no policy post from Redmond that matches the technical claim. That is the awkward part. The behavior is already in the apps. The conversation is not.
A watermark is a ledger only one side can read
Invisible AI watermarks get sold as anti-disinfo, creator protection, and “let’s label the source.” The goal is not automatically wrong. The question is who can read the label.
You almost never see the ID in the picture. The party that embedded it has the extractor. That looks like transparency. It is closer to a private ledger. Call it information asymmetry.
Google’s SynthID sits in the same family: a signal in the pixels of generated images. Adobe’s Content Credentials lean on attached metadata. Stamping a GUID into the raster is more stubborn. Drop that layer into Paint, and the watchlist is no longer “model output.” It is whatever a built-in Windows app happened to save.
On-device is an easy word to misread. Where the math runs is not the same as who controls the file. A model can stay on the NPU while the app still chooses the signature. The bytes that never left the machine may be the original. What the ID means can still be interpreted on a server later.
If you plan to post something sensitive, do not stop at stripping properties. Treat a fresh save from Paint or Photos as a signed object until proven otherwise. Re-encoding hard in another editor is the workaround people mention. It is not a guarantee.
Read the policy copy the same way. On-device. Local. Not uploaded to the cloud. Those phrases can be true and still say nothing about identifiers in the output.
The local doodle and the signed pixel now have to live in the same sentence. When you pick on-device AI, are you only asking where the model stops? Or are you also asking whose name gets written on the result?
Comments
Loading comments...