Home›Blog›Google Earth Now Lets Anyone Generate Fake Satellite Images

Google Earth Now Lets Anyone Generate Fake Satellite Images

Illustration of a map grid with a fabricated structure being drawn onto genuine terrain, over a caption about inherited credibility
Generated imagery is built on top of Google's real satellite and aerial imagery of the same coordinates, which is what gives the result its plausibility. (Illustrative)

On 30 July 2026 Google added AI image generation to Google Earth on the web, using its Nano Banana 2 model, available globally on the day. You zoom to any coordinates, click create image, and describe what you want there. The model uses Google's own satellite, aerial and 3D imagery of that exact spot as its starting point. Within hours, open-source intelligence researchers had used it to place a nuclear plant in Iran, refugees near the Mexican border and a bomb crater in Gaza. Google says every generated image carries a detectable watermark and that harmful topics are blocked. Both of those things can be true and the problem still stands.

Update, 2 August 2026: Google withdrew this feature on 31 July, about a day after launch, saying it had seen people sharing generated imagery that appeared to breach its policies and that it was rolling the feature back while it works on stronger guardrails. That is a pause, not a cancellation. As of 2 August, Google's launch post remains live and unamended, still inviting readers to zoom in and type whatever they want to see. Everything described below happened inside that one-day window.

This piece reflects reporting as of 31 July 2026. The feature launched on 30 July and Google has said its protections are being updated, so the behaviour described here may change.

What Google shipped

Google's announcement, written by a Google Earth product manager, frames the feature around visualisation. It suggests rendering the Pompeii ruins as they looked in 78 AD for a classroom, generating an infographic about the Statue of Liberty, showing a client what an empty Tokyo lot could become, previewing a lakeside cabin, and turning the Google campus into a sci-fi city. The instruction to the user is "type whatever you want to see".

The post contains no safety section. It does not mention watermarking, restricted subjects or any limit on what can be generated. Google's description of the model is that it creates concepts grounded in the real world, which is an accurate description of both the intended use and the problem.

What researchers did with it the same day

Henk van Ess, an open-source investigation specialist, published his tests hours after launch: refugees placed near the Mexican border, a nuclear plant in Iran, a fatal crash on an Amsterdam street, and a hospital and bomb crater in Gaza. All of them drawn on Google's genuine imagery of those real locations.

404 Media ran its own tests and reported adding skyscrapers to a rural area, a homeless encampment to a part of Los Angeles where homelessness is a live political fight, and a bomb blast and crater to another Los Angeles location. A third specialist, the OSINT professional Ben Heubl, described what the tool does if you type your own workplace address and prompt it for a drone attack, and said the result would make verification work "much more difficult".


Diagram contrasting the older multi-step method of faking a satellite image with the new one-sentence method
Faking a satellite image previously meant screenshotting, uploading, prompting, downloading and cropping. It now takes one prompt inside the map itself. (Illustrative)

These are not sophisticated attacks. They are the first thing people with relevant expertise tried, and they worked.

Why a mapping tool is the wrong place for this

The reason this lands differently from any other image generator is what Google Earth had become.

When a photograph appears online claiming to show a bombed hospital or a burning refinery, someone has to decide whether it is real before it is republished. The way that is done is comparison: put the claim next to a picture of the same place that everyone agrees is genuine, and look at the difference. Google spent two decades building that reference, and crucially every frame of it is dated, so you can establish when something appeared.

The clearest demonstration came in July 2014, when the Russian Ministry of Defence presented satellite images at a press conference four days after the downing of flight MH17. Bellingcat found the vegetation and field patterns did not match the mid-July dates claimed, placing the images in June instead, and concluded the ministry had presented them falsely. Note what Bellingcat's follow-up guide actually does, though: it checks Google Earth's own dates against a second provider's image previews, because the accuracy of Google's dates had itself been questioned. The dated archive was where the check started, not the last word.

The fabrication is now generated on top of that archive, at the correct coordinates, in the same light and at the same angle as the real imagery beside it. It does not have to be convincing on its own. It borrows the credibility of the map it was made on.

The precedent already exists

Someone did the laborious version of this months ago. A Google Earth pass dated 10 February 2025 photographed a car park at a US naval base in Manama, Bahrain. A year later a photograph circulated showing the same base apparently destroyed by an Iranian drone strike, posted by the state-linked Tehran Times as a before-and-after of American radar equipment in Qatar. It was not Qatar, and the giveaway was that the cars in the car park had not moved – same vehicles, same rows, same spaces. DW's fact-check team put the post at more than 950,000 views, and AFP reported the image spreading further across platforms in several languages. Awkwardly, Iran did strike that base: independently verified imagery from Planet Labs and Airbus shows real damage there. The fake was a fabricated version of something that actually happened.

That is the shape of the problem. Detection did eventually work on that wave of fakes. AFP reported finding a SynthID watermark on one fabricated satellite image from the same conflict, and DW spotted a Gemini watermark sitting in the corner of another. In both cases the finding arrived after the image had travelled, which is roughly the point at which it stopped mattering.

By van Ess's reconstruction, building the Bahrain fake took six separate steps and enough patience to see them through. It now takes a sentence typed into the map.

What Google says

Asked for comment, Google pointed 404 Media to a company post stating that every image created with Nano Banana in Google Earth includes the SynthID digital watermark, that anyone unsure about an image can check it via the Gemini app or Lens in Search, that image creation is prevented on harmful topics, and that protections are continually updated.

The watermark claim is credible and worth knowing about. The harmful-topics claim is harder to reconcile with the published record, given that a bomb crater and a nuclear facility were both generated on day one by researchers who then wrote about it. It is possible the filter blocks some prompts and not others, and neither Google nor anyone else has published where the line sits. What can be said accurately: a filter exists, and two independent sets of researchers produced conflict imagery on the first day without apparent difficulty.

There is also a harm that does not require anyone to be deceived. Once a tool like this is known to exist, an official confronted with a genuine photograph of a genuine atrocity has a ready-made response available. They do not need to use the tool. They need everyone to know it exists.


Diagram showing a verification workflow that cross-checks a claimed image against a second independent satellite source and published orbital data
Verification specialists recommend adjudicating off Google entirely, using a second independent sensor and checking whether any satellite was actually overhead. (Illustrative)

How verification specialists say to handle it

The practical advice from the OSINT community has shifted, and it is mostly about not relying on a single source.

  • Adjudicate off Google entirely. Sentinel-2 is free and revisits every five or six days. Landsat, Planet, Airbus and others give you a sensor with a known orbit, a collection time and a resolution you can check.
  • Take two collects. For any image that matters, get a duplicate from an independent source. This is long-standing geospatial practice, not a new response to AI.
  • Check the orbit. If an image claims a specific satellite at a specific hour, published orbital data will tell you whether anything was overhead. It is the dullest check available and the only one a model cannot fake, because it is not about the pixels.
  • Run it through the detector, but do not stop there. Google says uploading a suspicious image to Gemini will flag content its own models generated. It will not catch a fake made elsewhere, and it will not catch anything before it spreads.

FAQ

Does this change what I see when I normally use Google Earth?

No. The underlying satellite and aerial imagery is unchanged. Generation is something a user does in their own session, and the result is an image they can screenshot and share. The risk is entirely downstream, in what circulates afterwards.

Can I tell a generated image from a real one?

If it came from this feature, Google says its SynthID watermark will be present and can be checked through the Gemini app or Lens in Search. That is a real capability. It requires you to suspect the image enough to check it, which is the step most people skip.

Is Google doing anything wrong here legally?

Nothing has been alleged, and the timing is worth being precise about. The EU AI Act requires providers of systems generating synthetic image content to mark those outputs in a machine-readable format so they can be detected as AI-generated, and the SynthID watermark is the kind of measure intended to satisfy that. But Article 50 only applies from 2 August 2026, three days after this feature launched, and the marking and detection duty carries a limited grace period to 2 December 2026 for systems already on the market. Whether marking alone is sufficient is precisely what is being argued about.

Why not just remove the feature from conflict zones?

Geographic restriction is possible in principle and Google has not indicated it is planning it. It would also be leaky: the misuse in the examples above includes a fabricated homeless encampment in Los Angeles and a car crash in Amsterdam, neither of which is in a conflict zone.

Should I stop trusting satellite imagery?

No, but the standard has moved. A single satellite screenshot from any source was already weak evidence for anything contested. What is new is that the archive people used to check those screenshots against is now also a place fakes can be made.

The takeaway

For twenty years the argument about Google Earth was that it might reveal something true. Governments negotiated blurred air bases and censored palaces on exactly that basis, which was itself an admission that the map was accurate enough to be dangerous. There were procedures for that: a ministry, a condition on an overflight permit, a legal process. The failure mode now runs the other way – a map showing something that was never there – and there is no equivalent procedure for it, only a watermark that catches the fake after it has travelled. Google has built a genuinely useful visualisation tool. It has also put a generator inside the reference archive, and it published the announcement without addressing that at all.

Sources

Enjoyed this? Get the weekly roundup:
← Back to blog