You bought a Copilot+ PC partly because the AI runs on your hardware. No cloud bills, no rate limits, no prompts leaving the machine. You open Paint, type a prompt into Cocreator, and the NPU generates the image locally. It feels offline.

It is not offline. And the image you save carries something you cannot see: a 16-byte globally unique identifier, issued by a Microsoft server, embedded into the pixels themselves.

That is the conclusion of a detailed reverse engineering writeup published last week by a security researcher, and it climbed to the top of Hacker News over the weekend with over 500 points and 200+ comments. I do not own a Copilot+ PC, so I have not reproduced this myself. Full disclosure: everything below comes from the researcher's published analysis, Microsoft's own support documentation, and discussion in the original thread. I verified each claim against those sources, and I will link all of them.

What makes this story worth 15 minutes of your time is not outrage. It is the engineering. This is one of the clearest public examples of how "local AI" and "private AI" have quietly become two different things, and the design decisions Microsoft made here teach you a lot about how provenance systems are being built across the industry.