뉴스로 돌아가기
제품AI Understanding 브리핑

Tom's Hardware는 Microsoft Paint 및 Photos AI 이미지에서 보이지 않는 GUID 워터마크를 보고합니다.

Tom's Hardware는 Microsoft Paint 및 Photos가 C2PA 자격 증명과 함께 눈에 보이지 않는 서버에서 발행한 GUID 데이터를 AI 생성 이미지에 포함한다고 보고했습니다. 이 결과는 개발자 Xusheng Li의 리버스 엔지니어링에서 나온 것이며 Microsoft에서 독립적으로 확인하지 않았습니다.

5 min readRead the original reporting
Source-provided image accompanying Tom’s Hardware reports invisible GUID watermarks in Microsoft Paint and Photos AI images
기여 보고녹음된 소스
출판사
tomshardware.com
소스 링크
tomshardware.comhttps://www.tomshardware.com/tech-industry/artificial-intelligence/microsoft-paint-and-photos-apps-add-invisible-watermark-to-ai-generated-content-developer-reverse-engineers-guid-embedding
소스 유형
자사 문서가 아닌 뉴스 매체를 통한 보도입니다.

자체적으로는 확인할 수 없었던 내용: 이 소유권 주장은 해당 매장에 귀속됩니다. 당사는 자사 문서와 비교하여 이를 확인하지 않았습니다. (tomshardware.com)

맥락60초 안에 이해하세요

여기서 시작하세요

주요 용어

API(애플리케이션 프로그래밍 인터페이스)
한 소프트웨어 시스템이 다른 시스템에 요청을 보내고 응답을 받는 구조화된 방식입니다.
워터마킹
AI가 생성한 텍스트나 미디어에 감지 가능한 신호를 삽입하여 나중에 기계가 생성한 것으로 식별할 수 있습니다.
임베딩
텍스트, 이미지 또는 기타 데이터의 의미론적 의미를 포착하는 숫자 벡터 표현입니다.
자신을 테스트해 보세요AI 윤리 퀴즈

무슨 일이 일어났나요?

Tom’s Hardware reports that developer Xusheng Li discovered previously undocumented behavior in Microsoft Paint and Photos when their AI image-generation features are used. The report says the apps apply both visible Copilot branding in some cases and an invisible watermark intended to identify or verify that AI participated in creating an image.

Tom’s Hardware reports that developer Xusheng Li investigated the AI features in Microsoft Paint on Windows 11 after finding that the app could call a remote image-generation API. The report says Li also found four apparent model files in the application path for local processing: one file resembling an ONNX model and three encrypted ONNX-like files. The article presents this discovery as the starting point for examining how Microsoft’s AI image features mark generated content.

According to Tom’s Hardware, Li found a file named watermarker.dll while probing the application. The report says Li initially believed the file handled only visible , including a Copilot logo placed in the lower-right corner of an image. The article says further analysis, assisted by an AI tool, identified a separate function called WmkWriteWatermark for invisible watermarking, in addition to the visible-watermark function AddPerceptibleWatermark.

Tom’s Hardware reports that the invisible process mixes a server-issued globally unique identifier, or GUID, into image pixels. The report also says Paint attaches C2PA Content Credentials to saved files, with code associated with ProvenanceHelper.dll and provenancesdk.dll. The source does not establish what the GUID specifically identifies, whether it maps to a prompt, account, session or other event, or whether Microsoft retains a corresponding record.

The article reports different failure behavior in Paint and Photos. In Paint, Tom’s Hardware says the watermark is mandatory for Stable Diffusion image-generation output and that image generation fails if WmkWriteWatermark cannot be written. In Photos, the report says the app still returns the image but logs an error when the process has a problem. Tom’s Hardware also reports that prompts from local image-generation workflows are sent to Microsoft servers for moderation. The article speculates that the processing may relate to Article 50 of the EU AI Act, whose transparency rules the report says took effect on August 2, 2026, while noting that the rules do not specifically call for a prompt-specific GUID. Microsoft’s response, if any, is not included in the supplied report.

소스 세부정보: tomshardware.com ↗

왜 중요한가요?

The reported behavior could give users, platforms and investigators another way to identify AI-assisted images, but it also raises unanswered questions about what information is embedded, how it is linked to a user or request, and how long related data may be retained. The source does not independently confirm Microsoft’s implementation or explain its privacy safeguards.

If the report is accurate, Microsoft’s consumer-facing image tools are treating provenance as part of the generation pipeline rather than as an optional post-processing feature. That matters because an image can look ordinary to a viewer while carrying machine-readable information indicating that AI participated in its creation. C2PA credentials and pixel-level serve different technical roles, but the source does not provide enough detail to assess how they interact or how reliable either mechanism is in practice.

The reported distinction between visible and invisible marks is important for public understanding. A visible Copilot logo can signal AI involvement to a person looking at the image, while an invisible mark may be useful to software that processes large numbers of files. Tom’s Hardware does not report tests showing whether the hidden mark survives resizing, cropping, recompression, screenshots, format conversion or deliberate removal. Without those tests, the practical detection value remains uncertain.

The reported use of a server-issued GUID also creates a privacy question that the article does not resolve. A GUID could be designed only to support provenance verification, but its implications depend on what Microsoft associates with it and who can query or interpret that association. The source does not say whether the identifier is unique to a prompt, image, account, device, moderation request or generation event. It also does not report retention periods, access rules, user disclosures, or whether the identifier can be disconnected from personal information.

The story is therefore consequential mainly as a report about product behavior and accountability, not as proof that Microsoft has created a comprehensive tracking system. Tom’s Hardware attributes the technical findings to Li’s reverse engineering, and the supplied source contains no independent replication, Microsoft documentation, or Microsoft statement confirming the implementation. The report also does not establish that the mechanism is legally required, that it applies to every AI feature in Paint and Photos, or that it provides a dependable answer about an image’s origin.

Interactive Mechanism

대화형 메커니즘: 실제로 작동하는 방식

이 개발의 이면에 있는 기본 기술을 대화식으로 살펴보세요.

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
대화형 개념 확인+10 Points
AI Ethics Quiz

Why can ethical evaluation not be reduced to one model score?

다음에 무엇을 볼 것인가

The key next steps are Microsoft’s response, technical documentation, and clarification of which Paint and Photos versions are affected. Further scrutiny should establish whether the reported watermark survives common edits, what the server-issued GUID represents, how C2PA credentials are handled, and whether users receive meaningful notice or control.

Microsoft’s public response would help establish whether the reported functions are intentional, what versions of Paint and Photos contain them, and whether the behavior varies by region, account type or generation model. Documentation should clarify the relationship among the visible watermark, pixel-level GUID and C2PA credentials. It should also explain what information the GUID encodes and whether Microsoft maintains a lookup service or associated logs.

Independent technical testing is needed to determine the watermark’s real-world durability. Researchers should examine images produced through local and remote workflows and test ordinary editing operations, including cropping, resizing, compression and file-format changes. They should also compare Paint’s abort-on-failure behavior with Photos’ error-logging behavior to see whether both applications use the same implementation and whether failures are visible to users.

Privacy and user-control questions deserve particular attention. Users need clear notice when a supposedly local workflow sends a prompt to Microsoft servers for moderation, as reported by Tom’s Hardware. They also need to know whether saved files can be stripped of credentials, whether removing them affects functionality, and whether organizations can manage or audit the process. None of those controls or policies is described in the supplied source.

The legal and standards context remains unsettled. Tom’s Hardware links the behavior tentatively to Article 50 of the EU AI Act but explicitly notes that a prompt-specific GUID is not what the article says the rule requires. Future reporting should distinguish between legal compliance, voluntary provenance engineering and product-specific design choices. Until Microsoft or independent researchers provide more evidence, the scope, durability, identifiability and effectiveness of the reported should be treated as meaningful unknowns.

관련 가이드 및 퀴즈

AI 윤리AI 모델 설명ChatGPT와 LLM알고 있는 내용을 테스트해 보세요. 무료 AI 퀴즈를 시도해 보세요.용어집에서 AI 용어를 찾아보세요.AI 모델 출시 추적기를 따르세요.
이것이 유용하다고 생각하시나요?