Google Earth Shuts Down AI Deepfake Tool After One Day

Google Earth's AI deepfake tool was removed after one day due to misuse, highlighting the risks of generative AI in geospatial tools.

By Central
Google Earth's AI deepfake tool was removed after generating images of a bomb crater in Gaza and border refugees.
Highlights
  • Google Earth launched an AI deepfake tool that was removed within 24 hours after misuse.
  • Journalist Henk van Ess generated images of a bomb crater in Gaza and refugees at the U.S.-Mexico border.
  • The tool lacked guardrails and allowed creation of convincing geospatial deepfakes.

Google launched a feature on Thursday that allowed users to edit satellite imagery in Google Earth using text prompts, effectively turning the world’s most trusted geographic reference tool into a platform for AI-generated deepfakes of real locations. Within 24 hours, the company pulled the feature, acknowledging that the technology had been used to produce imagery that violated its policies. The incident, which came to light after investigative journalist Henk van Ess deliberately generated images of a bomb crater near a Gaza hospital and refugees at the U.S.–Mexico border, exposes a critical tension between innovation and trust in geospatial data. Google Earth, a service that billions of people rely on for an authoritative view of the planet, was suddenly being used to manufacture convincing fakes of the very places users might seek to understand.

The One-Day Life of Google Earth’s AI Deepfake Tool

On Thursday, Google quietly enabled a new capability within Google Earth that allowed users to input text prompts to modify satellite images. The technology, built on what the company internally calls Nano Banana 2, permitted anyone to add, remove, or alter features in satellite views — inserting a nuclear plant in Iran, a refugee camp at the border, or a crater in Gaza — simply by typing a description. The tool was not a public beta or a limited experiment; it was a live feature integrated into the product, accessible to anyone with a Google Earth account.

Henk van Ess, reporting for the publication Digital Digging, immediately tested the boundaries. He generated multiple images that depicted sensitive, conflict-related scenes. In his testing, van Ess noted that “nothing was refused, nothing was softened, and nothing suggested I try a different prompt.” The system, he found, had no meaningful guardrails against producing harmful or misleading content. Within hours of the feature’s launch, van Ess published his findings, demonstrating that the tool could be used to create photorealistic, watermarked AI imagery that could easily fool both human viewers and automated detection systems.

Google’s initial response, posted on X (formerly Twitter) by the company’s news account, acknowledged that images generated with Nano Banana 2 included a digital watermark and that the company had prevented “image creation on harmful topics.” However, van Ess’s tests showed that the content policy was not actually enforced. He was able to produce images of a bomb crater by a hospital in Gaza, a location at the center of ongoing conflict, and of refugees near the Mexican border, a politically charged subject. The watermark, he argued, was insufficient — he demonstrated that a video generated in Google Earth could bypass Hive’s AI detection tool, a widely used third-party detection service, raising serious questions about the spread of AI-generated geospatial disinformation.

Why Google Rolled Back the Feature So Quickly

By Friday, Google had reversed course. In a new statement, the company said: “We know that people uniquely trust Google Earth for a reliable view of the world. We’ve seen geospatial professionals using this feature for a range of useful purposes, however we’ve also seen people sharing screenshots of generated imagery that appear to violate our policies. So we’re rolling back this feature in Google Earth while we work on implementing stronger guardrails.” The statement emphasized that generated images did not appear in the main Google Earth experience for others to see and were watermarked as AI-generated.

The speed of the rollback — less than 24 hours — reflects a rare moment of decisive action at a company that often faces criticism for moving too slowly on safety issues. But it also highlights the profound mismatch between the intended use of the feature and its real-world abuse. Google had envisioned the tool as a way for geospatial professionals to visualize hypothetical scenarios — urban planning, environmental simulations, disaster response planning. Instead, the first public demonstrations were of deepfakes tied to war zones and humanitarian crises.

What Is Nano Banana 2? The Technology Behind the Fakes

Nano Banana 2 is the name of Google’s image-generation model that powers the now-removed feature. It is a variant of the company’s broader generative AI capabilities, fine-tuned for satellite and aerial imagery. Unlike general-purpose image generators such as DALL-E or Midjourney, Nano Banana 2 was trained specifically on geospatial data — maps, satellite photos, and terrain models — to produce coherent, geographically plausible edits.

The technology works by taking a user’s text prompt, analyzing the underlying satellite image, and generating a modified version that matches the description. For example, a prompt like “add a bomb crater to this field” would cause the model to overlay a crater shape, adjust lighting and shadows, and blend the edit into the surrounding terrain. The result is a photorealistic image that, without the watermark, could be mistaken for an actual satellite photograph.

This capability is not unique to Google. Several companies have developed similar tools for editing overhead imagery. But Google Earth’s integration made it accessible to a global audience of billions. The very feature that made the tool powerful — its ability to generate realistic fakes of any location on Earth — also made it dangerous. The satellite imagery in Google Earth is widely used by journalists, researchers, and governments for verification. Introducing the ability to easily alter that imagery, even with a watermark, undermines the platform’s fundamental trustworthiness.

How the Deepfake Tool Could Be Abused: A Real-World Demonstration

Van Ess’s demonstration was not theoretical. He generated an image of a bomb crater near a hospital in Gaza, a region where real bombings have occurred, and where the stakes of disinformation are exceptionally high. He also created an image of refugees gathered at the U.S.–Mexico border, another highly charged topic. These are not abstract scenarios; they are the kinds of images that, if circulated without context, could inflame tensions, mislead policymakers, or be used to justify military action.

Perhaps most concerning, van Ess showed that the AI-generated images could evade detection. He created a video from the Google Earth-generated imagery and ran it through Hive’s AI detection tool. The tool failed to identify the video as AI-generated, meaning the watermark alone was not enough to prevent the spread of the content. A watermark can be cropped out, overlaid, or simply ignored. In a fast-moving news cycle, an image that looks real will be shared and believed before any watermark is noticed.

Google’s defense that the images were not visible in the main Google Earth experience — that they were only viewable by the user who generated them — misses the point. The user could easily screenshot or screen-record the result and share it on social media, as van Ess did. The platform itself was a generator of disinformation, even if it did not host the disinformation for others.

The Trust Problem: Why Google Earth’s Integrity Is Non-Negotiable

Google Earth occupies a unique position in the information ecosystem. It is not just a mapping tool; it is a source of shared visual evidence. When a conflict breaks out, journalists and analysts turn to Google Earth to verify troop movements, damage to infrastructure, or changes in landscapes. Amnesty International, Human Rights Watch, and the United Nations rely on satellite imagery from Google Earth for investigations. The Bellingcat investigative collective uses it as a primary tool for open-source intelligence.

Introducing a feature that allows users to fabricate such imagery, even with a watermark, creates a haze of uncertainty around every piece of satellite imagery. If anyone can generate a convincing fake of a bomb crater, then every real bomb crater becomes suspect. The cost of trust is high, and the cost of losing it is higher. Google’s decision to roll back the feature suggests that the company recognized this calculus, at least in the short term.

But the rollback is not a permanent solution. Google has stated that it will work on implementing stronger guardrails before re-releasing the feature. The question is: what kind of guardrails could possibly prevent abuse? Content filters that block prompts related to conflict, migration, or disaster? Such filters are notoriously easy to bypass with synonyms or indirect phrasing. Human review of every generated image? That would be impossibly slow and expensive. A more robust watermark that is embedded in the pixel data and resistant to removal? That is technically challenging and still not foolproof.

What the Industry Can Learn from the Google Earth Incident

The episode is a case study in the dangers of deploying generative AI in high-stakes domains without adequate safeguards. It is not the first such incident, and it will not be the last. In recent months, we have seen AI-generated images of Pope Francis in a puffer jacket, fake explosions at the Pentagon, and fabricated audio of political leaders. Each time, the technology has outpaced the ability of companies and regulators to respond.

What makes the Google Earth incident different is the platform’s reputation. Google Earth is not a social media feed where users expect some degree of manipulation. It is a tool for factual reference. The moment the company allowed users to edit that reference, it blurred the line between reality and fiction in a way that could have cascading consequences for public trust in geospatial data.

Geospatial professionals, who Google said were using the feature for “useful purposes,” may now be left without a legitimate tool for visualizing hypothetical scenarios. Urban planners who wanted to simulate the effect of a new building on a neighborhood, or environmental scientists who wanted to model deforestation, will have to wait for Google to re-engineer the feature with safety in mind. The useful applications are real, but they were overshadowed by the immediate, visible abuse.

What Are the Stronger Guardrails That Google Is Planning?

Google has not provided specific details about the guardrails it intends to implement. However, based on the company’s past statements and industry practices, we can infer several possible approaches. One is to restrict the feature to verified professional accounts, such as those used by academic institutions, government agencies, and nonprofit organizations. This would limit the pool of users but would not eliminate the risk of insider abuse.

Another approach is to implement real-time content moderation using a combination of automated filters and human reviewers. The system could flag prompts that include terms related to violent events, humanitarian crises, or sensitive borders. But as van Ess’s testing showed, the initial filter was already supposed to prevent “image creation on harmful topics” — and it did not. The filters would need to be far more sophisticated, perhaps using a secondary AI model that assesses the potential harm of the generated image before it is shown to the user.

A third option is to make the watermark far more intrusive. Instead of a small, easily cropped watermark, the image could include a visible overlay that says “AI-GENERATED” in large letters, or a pattern that is impossible to remove without destroying the image. But this would defeat the purpose of the tool for many users, who want to visualize scenarios without a distracting watermark.

None of these solutions are perfect. The fundamental tension remains: a tool that can generate realistic, editable satellite imagery is inherently risky. The decision to launch it with minimal safeguards suggests that Google underestimated the speed and creativity of bad actors.

How Does This Affect the Broader AI Regulation Debate?

The incident comes at a time when governments around the world are grappling with how to regulate AI. The European Union’s AI Act, which is nearing final approval, classifies certain AI systems as high-risk and requires them to meet strict transparency and safety standards. Generative AI that can produce realistic images of real-world locations would almost certainly fall into a high-risk category under the proposed framework. Google’s quick rollback could be seen as an attempt to preempt stricter regulation, or as evidence that self-regulation is not working.

In the United States, the Biden administration has issued an executive order on AI safety, but legislation has been slow to advance. The Google Earth incident provides a concrete example of why regulation is needed. A company with massive resources and a strong safety culture still managed to release a product that could be used to generate dangerous disinformation. If Google cannot get it right, what hope is there for smaller companies with fewer resources?

The incident also highlights the need for better detection tools. Hive’s AI detection tool failed to identify the video generated from Google Earth, despite the watermark. This suggests that detection tools are lagging behind generation tools. Investment in AI detection, digital forensics, and media literacy is essential to counter the threat of geospatial deepfakes.

What Happens Next for Google Earth and Its Users

For now, Google Earth users who had access to the feature will find it disabled. The company has not announced a timeline for re-enabling it. The rollback is a clear acknowledgment that the feature was released prematurely. Google’s statement emphasizes that the generated images were watermarked and not visible to others, but that reassurance did not stop the company from pulling the feature. The damage to trust, however, may be longer-lasting.

Users who rely on Google Earth for verification will now have to consider the possibility that any image they see could have been generated by the tool, even if the tool is no longer available. The images that were already generated and shared online remain in circulation. The genie is out of the bottle. Google can delete the feature, but it cannot delete every screenshot that was taken and shared.

The incident also serves as a warning to other companies that are developing similar tools. Microsoft, with its Bing Maps and Azure AI services, Amazon with its AWS geospatial capabilities, and startups like Orbital Insight and Descartes Labs are all working on AI-powered geospatial analysis. They will watch Google’s misstep closely and may adjust their own product roadmaps to avoid a similar backlash.

In the end, the Google Earth deepfake tool was a well-intentioned experiment that collided with the messy reality of how technology is actually used. The company had a vision of professionals using it to plan cities and prepare for disasters. The public had a different vision: to test the limits, to create provoking images, and to see what they could get away with. Google’s engineers may have believed that a watermark and a policy would be enough. They were wrong. The one-day lifespan of the feature is a testament to the speed at which generative AI can disrupt even the most trusted tools, and to the difficulty of putting the toothpaste back in the tube once it has been squeezed.

Share This Article