25/08/2026
A small discovery that South Africans should pay attention to.
A researcher recently took apart how Microsoft Paint and Photos generate AI images on Windows, and found something worth talking about. Every image created with these tools carries an invisible watermark tied to a unique ID issued by Microsoft's servers each time a prompt is submitted, and successive prompts can be linked to one another. Microsoft had disclosed that it filters and moderates prompts, and adds C2PA content credentials, but had not made clear, in plain terms, that this metadata ties an image back to the person who requested it.
Why should this matter to someone who has never opened Paint in their life?
Because this is exactly the kind of quiet, behind-the-scenes data collection POPIA was written to deal with. A user ID linked to a prompt, and by extension to a Microsoft account, is personal information. Under our Act, a lawful basis is required to process it, the purpose must be clear, and people should reasonably be able to understand what is being collected and why. A watermark buried in pixel data, explained only in documentation most people will never read, sits uncomfortably against that standard.
There is a history here worth remembering. Decades ago, laser printer manufacturers embedded near-invisible tracking dots into printed pages, a practice that only came to light through independent research. We may be watching a similar pattern with AI image generation, just at greater scale, given how much of ourselves goes into a simple prompt.
To be fair to Microsoft, the intention is largely legitimate. Watermarking AI content helps combat misinformation, protects artists, and supports standards such as the EU's Code of Practice on transparency. The concern is not that provenance tracking exists, but whether people know, in language they understand, that their activity is tied to an identifier and retained somewhere.
For businesses, this is a good moment to check your own house. If your organisation issues Windows devices or uses Copilot features, ask your IT or security partner two things: what data is actually generated and transmitted when these AI features are used, and whether that activity is reflected in your data protection impact assessments and your Information Officer's records of processing.
For everyone else, the lesson is simpler. Convenience often comes with a quiet trade-off, and it is worth asking, now and then, what a tool is doing in the background while it does the thing you asked it to do.
I would be glad to hear how others, in security, legal, compliance or simply as concerned users, are reading this.
Privacy? Not if you use hosted AI services