Provenance marks on AI images are usually a good thing. They let a viewer tell a generated picture from a photograph, which is exactly what regulators have started to demand. A finding published this week complicates that tidy story. Microsoft's Paint and Photos apps, a researcher discovered, do not just mark an image as AI-made. They stamp it with a unique serial number that could point back to the individual who created it.

The researcher, Xusheng Li, reverse-engineered the apps and described the results in a report covered by The Register. When you generate an image, Microsoft embeds an invisible 16-byte identifier, a GUID, into the pixels themselves. This is separate from the optional visible watermark the apps offer. The identifier is issued by a Microsoft server, and it is baked into the picture whether or not you ever choose to label the image as AI-generated.

Two details make privacy researchers uneasy. First, your prompt is sent to Microsoft for moderation even when the picture is produced by a model running locally on your own machine, so the company sees what you asked for regardless. Second, when you generate a series of images, the app passes the previous picture's identifier along with the next request. That means a sequence of images can be linked together explicitly, and if Microsoft keeps a record of which account each GUID was issued to, an image found in the wild could in principle be traced to its maker.

Intent versus effect

None of this proves Microsoft is tracking anyone. The likeliest purpose is exactly what the company would say it is, content moderation and a tamper-evident provenance record built on the C2PA standard, the industry framework for labelling media. The gap is one of disclosure. Microsoft has not clearly explained that a per-image identifier is fetched from its servers during local generation, nor that the provenance data contains a GUID capable of singling out one picture from every other.

The timing is not accidental. Article 50 of the EU AI Act, whose transparency rules took effect on August 2, requires AI-generated content to carry a detectable, machine-readable mark. It does not ask for a prompt-specific serial number tied to a user, and that is the line this watermark appears to cross. A rule meant to tell people when they are looking at synthetic media has, in this implementation, quietly become a way to tell who made it. Users who assumed a locally generated image stayed on their own machine may want to reconsider that assumption.

Sources

  1. i. www.theregister.com
  2. ii. xusheng.dev
  3. iii. news.ycombinator.com

Commentarii · 0

Add · a · Comment