← AI watermark database
Microsoft

Copilot watermark

Not markedC2PA on images, nothing for text · last verified

Microsoft attaches C2PA Content Credentials to Copilot images and can mark generated audio and video in Microsoft 365. Copilot text carries no documented watermark.

What the evidence says

No text watermark is documented for Microsoft Copilot, and the absence is structural rather than an oversight. Microsoft’s transparency documents treat text as a modality and give it only an interface notice — a warning that AI-generated content may contain errors — while describing provenance for images. Microsoft has not stated that it does not mark text, so this entry records missing documentation, not a denial.

Microsoft is explicit about where text provenance would come from. Its Foundry documentation says text provenance support varies by model, and that where it exists the underlying model provides the watermarking, which Microsoft then surfaces. Copilot’s answers are produced by OpenAI GPT models and Anthropic Claude models, so whether a given response carries a mark depends on that model’s provider rather than on Copilot itself.

Images are the one case where provenance is systematic. Content Credentials, Microsoft’s implementation of the C2PA standard, record which AI model was used, which application generated the content and when. Separately, a visible watermark can be switched on by the user in their account settings; it is off by default, and the metadata is attached either way.

Audio and video are marked only on request. A Microsoft 365 Cloud Policy lets an administrator add a fixed mark — spoken audio states that the audio is generated by AI — which is disabled unless configured, cannot be reworded or repositioned, and does not apply to images. Provenance metadata for audio and video has not shipped: Microsoft states the information is currently added only to image metadata, with no time frame for the rest.

Metadata provenance is worth understanding for its fragility. Microsoft warns that provenance information might not survive all transformations, listing re-saving in applications that do not preserve it, cropping, resizing, filters, format conversion, transcoding and compression; C2PA’s own guidance adds screenshots and re-exports. Credentials are good evidence when present and prove nothing when absent, and Microsoft cautions that they do not establish whether content is accurate, truthful or trustworthy.

A common misreading

Content Credentials on a Copilot image are often described as a watermark on everything Copilot produces. They are signed metadata travelling with a media file, they are lost by ordinary editing and re-encoding, and they say nothing at all about a paragraph of text.

Sources

  1. Add watermarks to content generated or altered by using AI in Microsoft 365Microsoft Learn · · Provider documentation
  2. Content provenance in Microsoft FoundryMicrosoft Learn · · Provider documentation
  3. Application card: Microsoft Copilot for organizationsMicrosoft Learn · · Provider documentation
  4. Content Credentials Deployment Guidance 1.0C2PA · · Provider documentation

Frequently asked questions

Does Copilot mark the text it writes?

No text watermark is documented. Microsoft’s published provenance work covers images, audio and video. It has not said that text is unmarked, so this is an absence of documentation rather than a denial.

What are Content Credentials?

Signed C2PA metadata attached to a generated image, recording the model, the application and the date. They are fragile: cropping, re-encoding, screenshots and editing in tools that do not preserve them all strip the credentials.

Is Copilot text traceable at all?

Only as far as the underlying model marks it. Microsoft says text provenance varies by model and comes from the model provider, and Copilot runs on OpenAI and Anthropic models.

Working on your own draft?

GenPolish rewrites text you already have, showing every change before you accept it. It does not add or remove provenance signals, and it makes no claim about detectors.

Open GenPolish