\n\n\n\n Your Local AI Art Phones Home Anyway - AgntBox Your Local AI Art Phones Home Anyway - AgntBox \n

Your Local AI Art Phones Home Anyway

📖 4 min read•694 words•Updated Aug 25, 2026

Remember when Microsoft announced invisible watermarks for images generated with DALL-E on the Azure OpenAI service? At the time, it read as a reasonable enterprise move — cloud service, cloud rules, and a hidden marker so downstream viewers could tell machine-made pictures from human ones. Then in April 2026, Microsoft published its plan for bringing watermarks to AI-generated content across Microsoft 365, framing it as part of transparency and responsible use. Fine. Expected, even. But the story has now landed somewhere I didn’t expect: on your own hard drive.

According to reverse engineering work reported by Zeli, Microsoft Paint and Photos on Copilot+ PCs — apps that generate and edit images locally, on your silicon, with your electricity — send your prompts to a remote moderation server. That server returns a GUID, a globally unique identifier, which gets invisibly embedded into the resulting image. The watermark applies to AI-manipulated images even when generation happens entirely on-device. And there’s no toggle. It cannot be disabled.

Local Generation With an Asterisk

I review AI toolkits for a living, and the entire pitch of on-device generation has always rested on two promises: it works offline-ish, and it stays private. That’s the trade you make when you accept a smaller local model instead of a giant cloud one. You give up some quality; you get back control.

This setup quietly breaks half of that bargain. If the app is shipping your prompt to a moderation endpoint before stamping the output, then “local generation” describes where the pixels get computed, not where your creative intent travels. Your prompt — the thing that often reveals more about you than the image does — takes a round trip to Microsoft’s servers so a unique identifier can come back and hide inside your file.

And a GUID is not a generic “made with AI” stamp. Unique identifiers are unique. That’s the whole point of them. A blanket watermark says “this image was AI-assisted.” A per-image GUID issued by a server creates, at minimum, the technical possibility of linking a specific image back to a specific generation event. Microsoft frames all of this as provenance tracking under its broader AI transparency efforts, and provenance is a legitimate goal. But provenance for whom, tracked by whom, revocable by whom? Those questions matter a lot more when the marker is invisible and mandatory.

What Works

Let me be fair, because honest reviewing cuts both ways. AI transparency is a real problem, and invisible watermarking is one of the few technical approaches that scales. If a doctored photo shows up somewhere it shouldn’t, a provenance trail helps establish what happened. Microsoft committing to this across Paint, Photos, Microsoft 365, and Azure OpenAI is consistent, and consistency is more than most vendors manage. A watermark that users could switch off would be close to useless for its stated purpose — the people you most want to catch would be the first to flip the switch.

So I understand the design. I even think parts of it are defensible.

What Doesn’t

What I can’t defend is the disclosure. This came to light through reverse engineering, not through a settings page, a first-run notice, or a plainly worded support document. When a “local” feature quietly depends on a remote server, users deserve to know before a researcher pulls the binary apart. Transparency tooling that isn’t itself transparent about how it operates undermines its own mission.

The no-off-switch decision also lands differently on consumer machines than in enterprise clouds. Azure customers sign contracts and read compliance docs. Someone doodling in Paint on a laptop they bought at a big-box store has made no such agreement in any meaningful sense. Bundling mandatory, server-issued identifiers into the most casual image editor in computing history — an app people have trusted since before the web existed — is a significant shift, and it deserved a louder announcement than it got.

The Toolkit Takeaway

If you’re evaluating Copilot+ PCs or the built-in creative apps for privacy-sensitive work, adjust your mental model: Paint and Photos AI features are hybrid tools, not local ones, regardless of where inference runs. Your prompts leave the machine, and your outputs carry a unique, invisible, permanent identifier you cannot remove through

🕒 Published:

🧰
Written by Jake Chen

Software reviewer and AI tool expert. Independently tests and benchmarks AI products. No sponsored reviews — ever.

Learn more →
Browse Topics: AI & Automation | Comparisons | Dev Tools | Infrastructure | Security & Monitoring
Scroll to Top