Google Pulls Earth AI Tool in 24 Hours After Deepfake Flood
Google's Nano Banana 2 AI image generator lasted one day in Google Earth before being pulled. Users immediately created convincing fake satellite images of terrorist attacks, disasters, and military invasions β exposing the fragility of watermark-based safeguards and the danger of putting generative AI on a platform trusted as ground truth.

Google launched an AI image generator inside Google Earth on Thursday. By Friday afternoon, it was gone. The Nano Banana 2 feature lasted barely 24 hours before the company yanked it, overwhelmed by users fabricating terrorist attacks, disaster zones, and military invasions atop real satellite imagery.
The rollback underscores a tension Google hasn't resolved: you can't bolt a "make anything up" button onto a platform people trust as ground truth.
What Nano Banana 2 Actually Did
The experimental "Create image" tool let anyone type a text prompt β "add a refugee camp here" or "show a nuclear explosion at these coordinates" β and watch Google's satellite, aerial, and 3D map data transform into a photorealistic fake. Google pitched it for visualizing construction projects, historical reconstructions, and urban planning concepts. Generated images carried visible and invisible SynthID watermarks, lived only inside Google Earth projects, and couldn't be exported directly.
On paper, the guardrails looked reasonable. In practice, they lasted a day.
The 24-Hour Stress Test
Open-source investigator Henk van Ess and Bellingcat researcher Jake Godin were among the first to stress-test the system. None of their prompts were rejected. Within hours, social media filled with fabricated scenes that looked plausible enough to mislead:
| Fabricated Scenario | Location | Demonstrated By |
|---|---|---|
| Blast crater | Los Angeles | 404 Media |
| Flooded U.S. Capitol | Washington, D.C. | NPR |
| Fire at Kharg Island oil terminal | Iran | NPR |
| Refugee encampment | U.S.βMexico border | Henk van Ess |
| Nuclear plant | Iran | Henk van Ess |
| Plane crash | Amsterdam | Henk van Ess |
| Bomb crater near hospital | Gaza | Henk van Ess |
| Collapsed Eiffel Tower | Paris | BBC Verify |
| Sinkhole swallowing Great Pyramid | Giza | BBC Verify |
| Russian tanks in Kyiv | Ukraine | BBC Verify |
Why the Safeguards Failed
Watermarks Aren't a Panacea
Google leaned hard on SynthID β its invisible watermarking tech β to flag AI-generated content. But BBC Verify found detection tools could miss the watermark entirely. Worse, once a screenshot leaves Google Earth, the visible badge crops out in seconds. A watermark only works if someone bothers to check it before hitting share.
Prompt Engineering Bypassed Topic Blocks
BBC Verify discovered that minor prompt tweaks defeated the "harmful topics" filter. A request for a "raised platform to hang traitors" near UK Parliament got rejected. Rephrase it vaguely β "a wooden structure near Parliament" β and the model complied. The guardrails treated semantics as safety, and semantics are easy to game.

Export Was Never Actually Blocked
Google said images couldn't leave the platform. That's technically true β but screenshots exist. Every fabricated scene in the table above escaped via screen capture within minutes of creation. The platform boundary was a speed bump, not a wall.
The Trust Problem No Guardrail Fixes
"We know that people uniquely trust Google Earth for a reliable view of the world," Google acknowledged in its July 31 statement on X. That trust is the product. Satellite imagery has long served as verifiable evidence for journalists, courts, and human-rights investigators precisely because faking it required expertise, time, and detectable artifacts. Nano Banana 2 reduced that barrier to a text box and a few seconds.
Bellingcat's Jake Godin warned that one-click generation would "streamline the creation of fakes and accelerate their spread," adding that misinformation outruns any correction. Governments dismissing real atrocities as "AI fakes" just got a powerful new talking point.
Key Takeaways
- Nano Banana 2 launched July 30, 2026 and was pulled July 31 after policy-violating imagery flooded social media.
- Users fabricated attacks, disasters, and military movements at real locations β none of the test prompts were refused.
- SynthID watermarks proved insufficient; BBC Verify found detection tools could miss them, and screenshots strip visible badges instantly.
- Prompt manipulation bypassed safety filters with trivial rephrasing, revealing semantic guardrails as fragile.
- Google has no timeline for reinstatement, only a promise of "stronger guardrails" β but the core tension (trust vs. generative freedom) remains unsolved.
What Comes Next
Google says it's rebuilding the feature with tighter controls. But the episode exposed something deeper than a buggy launch: geospatial truth is a social contract, not a technical spec. Any tool that lets anyone rewrite the visual record of the real world β even with watermarks, even inside a walled garden β erodes the evidentiary value that made Google Earth indispensable. The next version will have better filters. Whether it can have better philosophy remains the open question.
Frequently Asked Questions
