Security researchers have uncovered that Microsoft’s Windows 11 Paint and Photos applications may be embedding a Global Device Identifier (GDID) into AI-generated images. This hidden identifier, a 128-bit value occupying 16 bytes, is reportedly inserted by Microsoft servers when users generate images using AI features within these applications.
Unveiling the Hidden Identifier
The discovery was made by security researcher Xusheng Li, who, through reverse analysis, found evidence of this embedded GDID. This identifier is not new; it was previously reported in July in relation to a federal indictment, where Microsoft acknowledged its presence in Windows 11 without a complete opt-out option.
The GDID serves as a persistent, device-level identifier for a Windows installation. It can link to physical devices or virtual machines and acts as a unified key across various Microsoft services. Its typical uses include device registry, cross-device service coordination, update distribution, and enterprise status reporting.
According to Li’s analysis of the Paint application’s AI capabilities, a component named Watermarker.dll is involved. While Paint offers a visible watermark option displaying a small Copilot logo, Li identified a separate, hidden watermarking function operating independently.
The research indicates that Microsoft is also incorporating C2PA Content Credentials into AI-generated images. Li found that the same watermarkId appears within the C2PA metadata, acting as a “soft binding” to link the hidden image pixel watermark with the metadata indicating the image’s origin.
Microsoft Photos Also Involved
The Watermarker.dll component is also present in the Microsoft Photos application. Li’s investigation revealed that the local Image Creator and Restyle Image features within Photos appear to embed the GDID into the generated images in a similar fashion.
This discovery raises potential privacy concerns, as the GDID can be a persistent identifier linked to a specific Windows installation. While Microsoft utilizes these identifiers for various service-related functions, the non-obvious embedding within AI-generated content may lead to questions about user awareness and data traceability.
Previous reports have highlighted the persistence of the GDID, with tools like deGDID being developed to attempt to block Microsoft from tracking users on Windows 10 and 11. The involvement of this identifier in AI image generation adds another layer to the ongoing discussions surrounding data privacy and device identification within the Windows ecosystem.
The technical details suggest a coordinated effort by Microsoft to integrate device-specific identifiers into content created via its AI tools, potentially for tracking, analytics, or service improvement purposes. Users seeking to understand or control such identifiers may need to consult advanced technical resources or third-party tools, as options for disabling them completely are reportedly limited.









