Tools
AI Minute Newsroom
2026-08-25
Your 'local' AI image asks a Microsoft server for permission first — and comes back stamped with an ID only that server can read
A reverse-engineering write-up published on 20 August, and widely picked over by developers this week, traces what happens when Paint's Cocreator or Photos' Image Creator generate a picture on a Copilot+ PC. The prompt goes first to a remote Microsoft moderation endpoint, which returns a revised prompt, a generation ID and a 16-byte GUID. The NPU then makes the image locally, and Watermarker.dll embeds that GUID invisibly into the pixels using a content-adaptive block technique. The same identifier is written into the file's C2PA Content Credentials as a soft binding. It applies only to AI-generated output — images you merely edit are untouched.
Why it mattersThe pixel watermark survives things metadata does not: screenshots, re-encoding, stripping the file's headers. That is the point of soft binding, and for tracing deepfakes it is a feature. The part worth knowing is the other half: the identifier is issued by a server that saw your prompt, so every image carries a token linking it back to that session. 'Generated locally on your device' turns out to describe where the compute happened, not where the record lives.
✓ Verified · 2 sources
▶ Related video: What Is C2PA Metadata? The Future of AI Image Verification & Content Authenticity
Read in the app — free, in 9 languages
Related stories
One message can run code as root on an unpatched LLM cache server.
2026-10-09Google's new office agent also runs on rival Anthropic's Claude.
2026-10-09Microsoft's new laptop runs a 120-billion-parameter model offline.
2026-10-08Google opened its AI watermark detector to everyone worldwide.
2026-10-08Hackers broke OpenAI's coding agent on day one of a contest.
2026-10-08