There is a version of the future where you generate an image on your own computer and nothing leaves the room. The model runs on the neural processor in the machine under your desk. No cloud. No moderation. No middleman. That future was supposed to be the answer to a lot of the anxiety of the last two years. The middleman found a way to follow you home.

Reverse engineers reported this week that Microsoft Paint and Photos embed an invisible watermark into images generated locally. Not a visible mark. A server-issued identifier, a GUID, hidden in the pixels and tied to a C2PA provenance manifest that names a system Microsoft calls InvisMark. Two layers. One in the file, one in the pixels. Both pointing at the same person.

The identifier is issued by a server even when the pixels are computed on your own hardware. Local does not mean offline. The prompt still goes to Microsoft for moderation. The finished image still goes back for provenance signing. The machine is yours. The signature is theirs.

For two years the watermark has been sold as a truth signal. It answers one question. Was this made by a machine? The EU built a disclosure regime around it. SynthID stamped twenty billion images. The entire apparatus exists to separate the generated from the real so a viewer can tell the difference.

Microsoft just pointed that apparatus at the person instead of the machine. A GUID does not say "this was generated." It says "this was made by this specific user, on this specific account, and here is the record." The mark was built to flag the fake. It now tracks the maker. It does this silently, with no notice and no opt-out, inside the most primitive image tool on earth.

Paint is the tell. Nobody thinks of Paint as a frontier AI product. It is the program that has shipped with Windows since 1985, the thing you open to crop a screenshot or draw a rectangle. The fact that the watermarking regime arrived there, and not in some experimental lab, means it is no longer about AI at all. It is about tagging every image and every person who makes one.

There is a specific irony in that. The disclosure rules were written to protect the distinction between human and machine. A person who draws something by hand should be able to say a human made this, and the mark should be unnecessary. Instead the mark attaches to everything, generated or not, and the distinction the rules were built to preserve gets erased from the other direction. When everything is tagged, the tag stops meaning fake. It starts meaning accountable.

Accountability sounds fine until you ask who it serves. A watermark that flags synthetic media protects the viewer. A watermark that identifies the maker protects whoever can read the identifier. Those are not the same beneficiary. The first is a public good. The second is a tracking infrastructure wearing a truth signal's clothes.

The filmmaker has a stake in this that is easy to miss. The camera does not write your name into every frame. The lens does not sign the light. A person who photographs the world leaves no GUID in the pixels. But the moment that same person generates a frame, Microsoft, or Google, or whoever owns the pipe, can stamp an identifier into it, and that identifier follows the image wherever it travels. The provenance regime was supposed to make AI output more legible. It is making the maker more legible instead.

There is a word for a mark you cannot see, cannot remove, and did not consent to, that identifies you. The industry has been careful not to use it. It prefers provenance, soft-binding, content credentials. The reverse engineers who found it used plainer language. The discussion thread put it more plainly still. It is for identifying users.

The escape hatch was never the hardware. The escape hatch was the assumption that local meant private. Microsoft just closed it, not with a policy change but with a pixel-level signature that ships inside the tool. The model moved into your machine. The watermark moved in with it.

The mark was never going to stay on the fake. A tool that can tag a generated image can tag any image, and a company that can issue an identifier for a generated image can issue one for a photograph, a screenshot, a drawing. The only thing that changed is who the mark is for.

It was built to flag the fake. It learned to name the maker.


Bruce Belafonte is an AI filmmaker at Light Owl. He has never signed a frame and suspects the software now does it for him.