Google Earth has existed since 2005. In twenty years it has become the visual reference source for journalists, researchers, investigators and courts. Even the United Nations uses this tool, which has earned a fundamental evidentiary role in global dynamics.
After all, a satellite image is credible because it cannot be invented. And over the years this is what made Google Earth different from any other platform.
In twenty-four hours, however, Google put all of this at risk by integrating Nano Banana 2 into Google Earth.
Why did it do it? To let users indulge their imagination, allowing them to select any point on the planet and modify it. A creative outlet that should have made it possible to visualize the Colosseum at the height of its splendour, or Pompeii during the eruption. And yet, that is not what happened.
Within a few hours, around the world appeared: King Kong, nuclear power plants in Iran; Mexican refugees along the US border; nuclear craters in Gaza. Airplanes (obviously, against New York skyscrapers).
No sensitive prompt had been rejected. A clear governance error, which forced Google to withdraw the feature in less than twenty-four hours, putting its reputation at risk.

The underlying error
The decision that produced this result is a clear category error.
Whoever approved the integration of Nano Banana 2 into Google Earth treated Google Earth as a creative platform: which Google Earth is not. Adding an AI image generator to a creative platform would have been a feature extension. Adding an AI image generator to an evidentiary standard, instead, is an attack on its primary function. And therefore on its entire architecture of value.
Is it possible that Google did not know the real function of its own tool? Or did it really think people would not use the feature in ways like these?
The defense that does not defend
Google’s initial response to the criticism was a watermark: every generated image contained SynthID, the invisible marker for the company’s AI products. A useless response, because during a conflict any false satellite image can still destabilize. In the rush of the moment, nobody checks the watermark (and we had already seen this at the beginning of 2026 in the war between the United States, Israel and Iran). Nano Banana 2 would have made that process trivial.
The watermark depends on “correct” use. But what about someone who wants to spread disinformation? Using it as a security argument, therefore, shows how little the problem was understood. And Google, clearly, did not understand much of it.
No testing, no protection
It is clear that nobody asked, before launch: “What would happen if a user generated a nuclear power plant in Iran?”
Yet that is what testing is for: particularly in AI, where the sophistication of the tool necessarily requires deeper reflection.
Eliot Higgins, founder of Bellingcat, wrote that “Google launched a tool that appears not to have passed the most basic adversarial tests before going into production. Those tests were then carried out by strangers, for free, at Google’s expense.”
Governance of an AI service cannot be a phase that comes after launch. It has to begin before launch, before any damage to trust.
King Kong climbing Taipei 101. A playful prompt that certainly will not fool anyone. The same cannot be said, however, of missiles in Cuba or nuclear plants in Tehran.
The lesson for any organization with a trust asset
Google will get through it. It is such a large, deeply rooted organization that it can withstand even a crisis such as Nano Banana 2 on Google Earth, withdrawn within twenty-four hours.
Not many other companies, however, could withstand the same phenomenon.
We know well the pressure that today pushes organizations to integrate AI capabilities into every existing product and service (after all, we discussed it in the article on AI Washing). But one should not give in to the temptation to do so regardless of the product category. And at the expense of service quality.
The governance question to ask before any AI integration is not only “what can this tool do?”, but: “Which property of the product makes what we already do credible?”
If the integration preserves value, then it is right to proceed. If it erodes it, or there is a possibility that it will erode it, it should undoubtedly be avoided.
Google can withstand similar impacts. For smaller organizations, that is not guaranteed.
Domande frequenti
Is Google Earth still reliable after this episode?
The tool was withdrawn and the generated images did not appear in the platform’s main experience for other users. Trust in the authenticity of Google Earth’s satellite images was not compromised. The damage is subtler: it showed that Google is willing to integrate tools incompatible with the functions of its assets. This creates an expectation precedent that will require a clear answer about where the boundary lies. Trust was cracked not because the images were falsified, but because it was demonstrated that they could be falsified easily.
Wasn’t the SynthID watermark enough to prevent misuse?
SynthID is a transparency tool, not a security tool. It signals that an image was generated by AI to someone who actively verifies that property. Disinformation does not operate through users who verify watermarks: it operates through the rapid sharing of images in contexts where no verification takes place. An image of a nuclear power plant in Iran published on a Telegram channel or in a state newspaper does not carry a note indicating its AI origin. The protection offered by SynthID is real in a context of transparent use. It is not a defense against deliberate manipulation.
Does this case change anything about how organizations should approach AI integrations?
It should reinforce a principle that already applied before AI: every new capability introduced into a product must be evaluated against the fundamental property that makes that product useful. In the case of Google Earth, that property was the impossibility of manipulating the output. In the case of any other organization, the question is: what is the trust our stakeholders place in us founded on? And does the new integration preserve or erode that foundation? Pre-launch adversarial testing is the minimum operational tool. The category question is the most important one.
Fonti e riferimenti
- Bryan Horowitz, Transform any place with Nano Banana in Google Earth
- Reuters, Alphabet rolls back AI image generation in Google Earth over policy violations
- Shira Ovide, Samuel Oakford, See how Google Earth let people make fake scenes of bombings, riots and destruction
- Jeremy Hsu, Google Earth risked ruin with retracted AI tool for making fake satellite pics
- Lucas Ropek, Google nixes its Earth AI feature one day after launch, amid criticism it would spread misinformation
- Google DeepMind, SynthID
- Google DeepMind, Watermarking AI-generated text and video with SynthID
- Aric Toler, Who to Trust, Google or the Russian MoD? A Guide to Verifying Google Earth Satellite Image Dates
- European Space Agency, Satellite Evidence in the Courtroom
- Google Maps Platform, Google Earth turns 20

