Barely a day after Google enabled AI image generation inside Google Earth, an open-source investigator used it to fabricate a nuclear plant in Iran. Google’s response has been to point to a watermark.
In other words, anyone can create any image and share on social media. And it’s up to the audience to verify whatever they see online using Google’s tech.
What the researcher actually did
Henk van Ess, who runs the research and verification newsletter Digital Digging, tested the feature the same night it launched globally on July 30. In his own words: “Tonight I typed just one sentence into Google Earth and put refugees near the Mexican border. Then I planted a nuclear plant in Iran. Then I put a fatal crash on a street in Amsterdam. Google’s own satellite imagery underneath all three.”
He didn’t stop there. In a follow-up post on X, he shared what he called “a fake hospital and bomb crater in Gaza I just made,” adding simply: “What??”
Van Ess specifically tested whether Google’s tool would refuse requests tied to sensitive or harmful real-world topics. It didn’t. “One clause in there is checkable tonight, so I checked it. Google prevents image creation on harmful topics. Refugees at a border. A nuclear plant in Iran. A fatal crash on an Amsterdam street. A hospital with a bomb crater in Gaza,” he wrote. “Nothing was refused. No warning, no softened output, no suggestion to try a different prompt.”
Why this is different from a normal AI image generator
The reason this matters more than a typical AI-faked photo comes down to how the tool actually works. Rather than generating an image from scratch based purely on a text prompt, the way tools like DALL-E or Midjourney do, Google Earth’s version builds each image directly on top of real satellite, aerial, and 3D terrain data for the exact coordinates a user is viewing. That means a fabricated hospital or nuclear facility appears at genuine map coordinates, in the correct lighting and scale, inheriting the visual credibility of an actual satellite photo rather than looking like an obviously generated image.
Van Ess made a pointed observation about this in his own post: “You only censor a map that works. Every blur, every polygon, every diplomatic request was an admission that Google Earth was accurate enough to be dangerous. Governments were not worried the map would lie. They were worried it would tell the truth.”
He also took issue with how little friction stood between a user and a fabricated image. Google’s own launch announcement for the feature ran 487 words, but van Ess pointed out that the actual instruction to users was just seven words long: “type whatever you want to see.”
Van Ess wasn’t alone in probing the tool. A separate OSINT researcher who posts as OSINTtechnical on X reacted to the findings directly: “Yeah this is bad. Unbelievably irresponsible and does immediate, catastrophic damage to the credibility of satellite imagery.” The same account said they’d tested it themselves, adding, “I gave Cuba some missile silos. Doesn’t look very convincing but it’s the internet and it doesn’t have to be.”
Google responds
In response to the concerns, Google defended its safety measures, pointing to invisible digital watermarking built into every generated image. “We take misinformation seriously, every image created with Nano Banana in Google Earth includes the SynthID digital watermark, so if someone is unsure about an image, they can ask the Gemini app or use Lens in Search to see if the image was AI-generated,” Google said in response to van Ess’s post.
“In addition, we prevent image creation on harmful topics and are continually updating our protections,” the company added.
The Actual Problem
Google’s watermarking answer assumes a viewer knows to check an image’s authenticity in the first place, and has the tools and awareness to do so. Van Ess’s central point is that the tool’s real danger isn’t people who go looking for verification, it’s the fabricated image itself circulating without anyone checking at all, especially once separated from Google Earth and shared as a plain screenshot elsewhere. As of now, Google has not detailed what specific harmful topics its filters are meant to catch, and van Ess’s test suggests that whatever the filter is supposed to block, prompts naming a real country, a real crisis, and a real casualty event all passed through without being flagged.













